News & Updates

Trust Through Ongoing Compliance

We’re proud to have completed our SOC 2® Type II examination. Our report, audited by Schneider Downs, covers controls related to Security for the period October 1, 2025 through March 31, 2026. It provides independent validation that our controls are designed appropriately and operated effectively over time. 

But what is SOC 2? 
SOC 2 is an independent attestation that evaluates how a service provider protects customer data and systems based on the AICPA Trust Services Criteria. A Type II report goes a step further by testing those controls over a defined period (typically 6–12 months), not just at a single point in time. 

Why does this matter? 
When you entrust a partner with sensitive employee, payroll, or system data, you can delegate the work — but not the responsibility. You still need assurance that your partner’s controls consistently safeguard your information. A current SOC 2 Type II report provides that assurance by confirming controls were tested and found effective throughout the review period. 

For you, this means: 

  • Greater confidence in how your data is secured and managed 
  • Support for your own compliance and audit efforts 
  • Reduced vendor risk through independently verified controls 

In short, a current SOC 2 Type II report is not just a logo — it reflects an ongoing commitment to data protection, transparency, and being a trusted partner you can rely on. 

Why SOC Compliance Matters — and Why a Current SOC 2 Should Be NonNegotiable 

When evaluating a service provider, organizations often focus on capabilities, experience, and cost. But there’s one question that directly impacts your risk, compliance posture, and peace of mind that should never be overlooked: 

Can this partner demonstrate that their controls are independently verified — and current? 

That’s where SOC compliance comes in. 

What Is SOC Compliance? 

SOC (System and Organization Controls) reports are independent attestation reports developed by the AICPA that evaluate how service providers manage and protect information. These reports are commonly requested during vendor risk assessments, audits, and compliance reviews because they provide third‑party validation that a provider’s controls are designed appropriately and operating effectively. 

Not all SOC reports are the same — and understanding the difference is critical. 

SOC 1 vs. SOC 2: What’s the Difference? 

SOC 1: Controls Related to Financial Reporting 

A SOC 1 report focuses on a service provider’s internal controls that impact a customer’s financial reporting. These reports are most relevant when a provider supports processes like payroll processing, benefits administration, or financial data handling that feed into a company’s financial statements. 

In simple terms: 

SOC 1 answers the question: 
“Can our auditors rely on this provider’s controls when reviewing our financials?” 

  • It helps streamline audits and reduces the need for duplicative testing 
  • A Type II SOC 1 confirms that controls were tested over a period of time, not just at a single point 

SOC 1 is important — but it doesn’t address the full picture of data protection. 

SOC 2: Controls That Protect Your Data 

A SOC 2 report evaluates a service provider’s controls based on the Trust Services Criteria, which may include: 

  • Security 
  • Availability 
  • Confidentiality 
  • Processing Integrity 
  • Privacy 

Most organizations rely on SOC 2 to understand how a provider safeguards sensitive data, systems, and access — especially when employee, payroll, or personal information is involved. 

A SOC 2 Type II report is the gold standard because it: 

  • Evaluates not just how controls are designed 
  • Confirms those controls operated effectively over a sustained review period (typically 6–12 months) 

This distinction matters. 

Why a Current SOC 2 Type II Matters So Much 

A SOC report is not timeless. 

Controls change. Systems evolve. Teams grow. Threats adapt. 

A current SOC 2 Type II report demonstrates that: 

  • Controls are actively maintained, not just documented once 
  • Security practices are regularly tested against real‑world operations 
  • Risk management is ongoing, not reactive 

If a SOC 2 report is outdated, it tells you very little about a provider’s present‑day security posture — and can create a false sense of confidence. 

When you work with a partner without a current SOC 2 Type II: 

  • You may inherit additional audit burden 
  • You take on increased vendor risk 
  • You may struggle to satisfy internal, regulatory, or customer compliance requirements 

In other words, you can outsource the work — but not the accountability. 

What This Means for You 

When your partner maintains a current SOC 2 Type II report, you gain: 

  • Confidence that your data is protected by tested, effective controls 
  • Reduced audit friction, as your auditors can rely on independent validation 
  • Transparency into how risk is managed behind the scenes 
  • Assurance that compliance is an ongoing commitment, not a one‑time activity 

A current SOC 2 is more than a checkbox — it’s a signal of operational maturity and trustworthiness. 

The Bottom Line 

SOC compliance isn’t about logos or certifications for show. 

It’s about trust. 

It’s about knowing that the partner you rely on to handle critical systems and sensitive data: 

  • Takes security seriously 
  • Submits to independent scrutiny 
  • Keeps their controls current, tested, and proven 

When evaluating vendors, don’t just ask if they have a SOC report. 
Ask which one, what type, and most importantly — how current it is. 

Because a trusted partner doesn’t just say they’re secure. 
They prove it — year after year. 

Top