June 8, 2026
A SOC 2+ report is an expanded SOC 2 examination that combines the AICPA Trust Services Criteria with additional subject matter or control frameworks that matter to customers, regulators, or business partners. In practice, this allows an organization to use the familiar SOC 2 reporting structure while also addressing requirements from other frameworks that relate to its security, compliance, or governance objectives. Because SOC 2 reports are already widely recognized in the marketplace, a SOC 2+ approach can be a practical way to provide broader assurance in a single report.
At its core, SOC 2 is based on the AICPA’s Trust Services Criteria, with security required and additional categories such as availability, confidentiality, processing integrity, and privacy added as needed. A SOC 2+ report builds on that foundation by mapping and testing controls against one or more additional frameworks. Depending on the organization’s needs, those additional criteria may include areas such as HIPAA, ISO 27001, NIST Cybersecurity Framework 2.0, ISO 42001, or other relevant requirements. This makes SOC 2+ especially useful for organizations that want one attestation report to speak to multiple stakeholder expectations.
For many organizations, the biggest appeal of SOC 2+ is efficiency. Instead of treating every framework as a separate exercise, management can often organize evidence, testing, and reporting in a more integrated way. That can reduce duplication, support cross-framework readiness, and make it easier to communicate assurance to customers who increasingly ask about multiple standards at once.
A SOC 2+ report can be a strong option for organizations that want to build on the market recognition of SOC 2 while also addressing other control frameworks in a single reporting exercise. It offers flexibility, efficiency, and the potential to reduce duplicated compliance work. At the same time, organizations should understand that it is not a substitute for a formal certification where one is required, and it may demand more planning and coordination to execute well. When scoped thoughtfully, however, SOC 2+ can be an effective way to align assurance reporting with real customer and business expectations.
If you are interested in obtaining a SOC 2 + report, please contact the Larson SOC Team for details.
What is a SOC 2+ report?
A SOC 2+ report is an enhanced SOC 2 examination that combines the AICPA Trust Services Criteria with one or more additional compliance or security frameworks, such as HIPAA, ISO 27001, NIST CSF 2.0, or ISO 42001. It provides broader assurance within a single attestation report.
What are the benefits of a SOC 2+ report?
A SOC 2+ report can reduce compliance duplication, lower overall audit costs, accelerate reporting timelines, and provide customers and stakeholders with assurance across multiple frameworks through one comprehensive report.
Is a SOC 2+ report the same as a certification?
No. A SOC 2+ report is an independent attestation report issued by a qualified CPA firm. It does not replace formal certifications that may be required under certain frameworks, such as ISO 27001 certification issued by an authorized certification body.