Skip to content

Scoping the SOC 2 Examination

 

Learn about scoping the SOC 2 examination, system boundaries, sub-processors, carve-out methods, mid-audit scope changes, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization. 

Table of Contents

What does “in scope” mean in a SOC 2 examination? 

 

In a SOC 2 examination, “in scope” refers to the specific systems, services, data flows, infrastructure, and personnel that the auditor will examine and that the resulting report will cover. Controls outside the defined scope boundary are not tested and not represented in the report. Scope is not the entire organization, it is the portion that processes, stores, or transmits the customer data the examination is intended to provide assurance over. Defining scope too narrowly produces a report customers find insufficient; defining it too broadly adds cost and complexity without proportionate assurance value. 

 

How is the system boundary defined for a SOC 2 examination? 

 

The system boundary for a SOC 2 examination is defined by five components, infrastructure, software, people, procedures, and data, covering every element that touches customer data within the service delivery process. 

Infrastructure includes the servers, databases, network devices, and cloud services supporting the in-scope service. Software includes the applications, operating systems, and utilities that process customer data. People includes employees, contractors, and vendors with privileged access to in-scope systems. Procedures covers the automated and manual processes governing service delivery and maintenance. Data covers the customer, configuration, and operational data flowing through the system. 

Internal systems unrelated to customer data, HR platforms, finance tools, internal productivity software, are typically excluded. The boundary decision should be made with a readiness partner before engaging an auditor, because changing scope after an engagement is signed adds cost and timeline risk. 

 

What determines whether a sub-processor is in scope? 

 

A sub-processor is in scope when their services are part of delivering the in-scope service and when their controls affect the security, availability, processing integrity, confidentiality, or privacy of the customer data being examined. The two options for handling in-scope sub-processors are the carve-out method, exclude their controls and reference their own SOC 2 Report, and the inclusive method, incorporate their controls directly into the examination. Sub-processors whose failure would not affect customer data are excluded entirely. The scope decision for each significant sub-processor should be documented and reviewed with the auditor during the planning phase.

 

What happens to scope when a new product or service is added mid-examination? 

 

When a new product, service, or system component is added during an active Type 2 observation period, the organization must immediately disclose it to the auditor if it touches the in-scope customer data environment. The auditor determines whether it falls within the existing scope boundary or constitutes a material change. A material scope change mid-observation period may require extending the observation window, adjusting the audit plan, or in significant cases, restarting the observation period. The safest approach is to implement and stabilize major system changes before the observation period begins, and to communicate any unavoidable mid-period changes to the auditor immediately, not during fieldwork. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data
Sam-IT-Solutions Logo
SAM IT Solutions

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties