Frequently Asked Questions

Got questions? We’ve got answers.

1. Which SOC report do we need — SOC 1, SOC 2, or SOC 3?

SOC 1 applies when your services affect a client's internal control over financial reporting — payroll, outsourced accounting, transaction processing, and similar. SOC 2 reports against the AICPA Trust Services Criteria and is the report technology and SaaS companies are most often asked for, as a Type I (control design) or Type II (operating effectiveness over a period). SOC 3 is a general-use summary you can share publicly without an NDA. We help you confirm scope and report type before any engagement begins.

BFAG CPA advisors in discussion with a client

Explore common queries about working with BFAG CPA LLC. Still unsure?
Contact us — we’re happy to help.

Service-Specific FAQs

SOC 2

ISO/IEC 27001

SOC 2 vs ISO/IEC 27001

GDPR

HIPAA

GDPR & HIPAA Combined

NIST Cybersecurity Framework (CSF 2.0)