<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecurancePro — Field notes</title>
    <link>https://securancepro.com/blog</link>
    <description>Field notes on SOC 1 &amp; SOC 2 audits, compliance, accounting, and tax from SecurancePro.</description>
    <language>en-us</language>
    <atom:link href="https://securancepro.com/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>What a SOC 2 report actually tells your buyer</title>
      <link>https://securancepro.com/blog/what-soc-2-actually-tells-your-buyer</link>
      <guid isPermaLink="true">https://securancepro.com/blog/what-soc-2-actually-tells-your-buyer</guid>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
      <description>A short, honest field guide to what enterprise procurement teams look for when they flip to the independent auditor&apos;s opinion — and what they don&apos;t.</description>
      <category>Field Guide</category>
    </item>
    <item>
      <title>Data Processing Agreement: a founder&apos;s guide to the DPA</title>
      <link>https://securancepro.com/blog/data-processing-agreement-guide</link>
      <guid isPermaLink="true">https://securancepro.com/blog/data-processing-agreement-guide</guid>
      <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
      <description>What a data processing agreement does, the clauses GDPR requires, how sub-processors flow down, and how a DPA relates to a BAA, SOC 2, and ISO 27001.</description>
      <category>Operations</category>
    </item>
    <item>
      <title>SOC 2 bridge letter: what it is and who signs</title>
      <link>https://securancepro.com/blog/soc-2-bridge-letter</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-2-bridge-letter</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
      <description>A SOC 2 bridge letter covers the gap between your last Type II report and today. Here is what it says, who signs it, and how long it can run.</description>
      <category>Operations</category>
    </item>
    <item>
      <title>How to run a SOC 2 readiness assessment that actually works</title>
      <link>https://securancepro.com/blog/soc-2-readiness-assessment</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-2-readiness-assessment</guid>
      <pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate>
      <description>A SOC 2 readiness assessment is cheaper than remediation. How to scope it, build the gap list, run an evidence library, and pick Type I vs Type II.</description>
      <category>Operations</category>
    </item>
    <item>
      <title>SOC 2 vs ISO 27001: how to pick (and when to do both)</title>
      <link>https://securancepro.com/blog/soc-2-vs-iso-27001</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-2-vs-iso-27001</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <description>SOC 2 vs ISO 27001, compared by the people asking for them. Buyer geography, timelines, cost, control overlap, and the three sequences that actually work.</description>
      <category>Compare</category>
    </item>
    <item>
      <title>SOX 404(a) vs 404(b): management vs auditor attestation</title>
      <link>https://securancepro.com/blog/sox-404a-vs-404b</link>
      <guid isPermaLink="true">https://securancepro.com/blog/sox-404a-vs-404b</guid>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
      <description>SOX 404a vs 404b in plain English: 404(a) is management&apos;s ICFR assertion; 404(b) is the external auditor&apos;s attestation. Who files each, and when it kicks in.</description>
      <category>Compare</category>
    </item>
    <item>
      <title>CMMC 2.0 explained: levels, timeline, and who assesses you</title>
      <link>https://securancepro.com/blog/cmmc-2-explained</link>
      <guid isPermaLink="true">https://securancepro.com/blog/cmmc-2-explained</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <description>CMMC 2.0 primer for defense contractors: what CMMC stands for, Level 1, Level 2, and Level 3 requirements, what a C3PAO does, and the rollout timeline.</description>
      <category>Federal</category>
    </item>
    <item>
      <title>HIPAA compliance for SaaS: BAAs, safeguards, and the honest path</title>
      <link>https://securancepro.com/blog/hipaa-compliance-for-saas</link>
      <guid isPermaLink="true">https://securancepro.com/blog/hipaa-compliance-for-saas</guid>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <description>HIPAA compliance services for SaaS: what a BAA is, when you become a business associate, the minimum technical safeguards, and how SOC 2 maps to HIPAA.</description>
      <category>HIPAA/HITRUST</category>
    </item>
    <item>
      <title>ISO 27001 requirements: clauses 4–10 and Annex A</title>
      <link>https://securancepro.com/blog/iso-27001-requirements</link>
      <guid isPermaLink="true">https://securancepro.com/blog/iso-27001-requirements</guid>
      <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
      <description>ISO 27001 requirements explained clause by clause. What auditors expect for the ISMS, risk treatment, internal audit, management review, and Annex A evidence.</description>
      <category>ISO</category>
    </item>
    <item>
      <title>SOC 3 reports: the public-use version of your SOC 2</title>
      <link>https://securancepro.com/blog/soc-3-reports</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-3-reports</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <description>SOC 3 is the publicly distributable version of a SOC 2 Type II. Here is what it contains, how it is produced, and when it is worth adding to your audit.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>SOC 1 vs SOC 2: which report your buyer is actually asking for</title>
      <link>https://securancepro.com/blog/soc-1-vs-soc-2</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-1-vs-soc-2</guid>
      <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
      <description>SOC 1 vs SOC 2, plus a note on SOC 3: one covers ICFR for your customers&apos; auditors, the other covers vendor trust for their security teams. Here is how to pick.</description>
      <category>Compare</category>
    </item>
    <item>
      <title>SOC 1 Type 1 vs Type 2: which one your buyer is asking for</title>
      <link>https://securancepro.com/blog/soc-1-type-1-vs-type-2</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-1-type-1-vs-type-2</guid>
      <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
      <description>SOC 1 Type 1 vs Type 2 explained: point-in-time design versus operating effectiveness over 3 to 12 months, and which report a user auditor actually wants.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>The SOC 2 audit process, phase by phase</title>
      <link>https://securancepro.com/blog/soc-2-audit-process</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-2-audit-process</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <description>The SOC 2 audit process in real phases with honest timelines: scoping, readiness, observation window, fieldwork, draft, management review, issued report.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>SOC 2 Type I vs Type II: which one to run first</title>
      <link>https://securancepro.com/blog/soc-2-type-i-vs-type-ii</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-2-type-i-vs-type-ii</guid>
      <pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate>
      <description>A SOC 2 Type 2 audit tests operating effectiveness over months, not a single day. Here is when Type I is the right first step and when to skip it.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>SOC 2 compliance requirements: the practical checklist</title>
      <link>https://securancepro.com/blog/soc-2-compliance-requirements</link>
      <guid isPermaLink="true">https://securancepro.com/blog/soc-2-compliance-requirements</guid>
      <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
      <description>SOC 2 compliance requirements are not a fixed control list. The policies, controls, evidence, and observation-window mechanics auditors actually expect.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>What is ISO 27001? A plain-English primer</title>
      <link>https://securancepro.com/blog/what-is-iso-27001</link>
      <guid isPermaLink="true">https://securancepro.com/blog/what-is-iso-27001</guid>
      <pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate>
      <description>What is ISO 27001, what an ISMS actually is, and why the Statement of Applicability matters. A CPA firm&apos;s jargon-free primer for US SaaS founders.</description>
      <category>ISO</category>
    </item>
    <item>
      <title>Trust Services Criteria, explained for SOC 2 scoping</title>
      <link>https://securancepro.com/blog/trust-services-criteria-explained</link>
      <guid isPermaLink="true">https://securancepro.com/blog/trust-services-criteria-explained</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <description>The Trust Services Criteria are the AICPA categories a SOC 2 tests against. Here is what each one means and how to pick the right scope for your report.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>What is FedRAMP? A plain-English primer for SaaS founders</title>
      <link>https://securancepro.com/blog/what-is-fedramp</link>
      <guid isPermaLink="true">https://securancepro.com/blog/what-is-fedramp</guid>
      <pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate>
      <description>What is FedRAMP: the OMB-mandated program that authorizes cloud services for US federal use. Impact levels, JAB vs Agency paths, what a 3PAO does.</description>
      <category>Federal</category>
    </item>
    <item>
      <title>HITRUST certification explained: e1, i1, r2, and the honest cost</title>
      <link>https://securancepro.com/blog/hitrust-explained</link>
      <guid isPermaLink="true">https://securancepro.com/blog/hitrust-explained</guid>
      <pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate>
      <description>HITRUST certification primer for SaaS founders: what the CSF is, the e1/i1/r2 levels, who issues the certificate, and how it maps to HIPAA and SOC 2.</description>
      <category>HIPAA/HITRUST</category>
    </item>
    <item>
      <title>Who the HIPAA Security Rule applies to</title>
      <link>https://securancepro.com/blog/hipaa-security-rule</link>
      <guid isPermaLink="true">https://securancepro.com/blog/hipaa-security-rule</guid>
      <pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate>
      <description>The HIPAA Security Rule applies to covered entities and business associates that create, receive, maintain, or transmit ePHI. Here is exactly who that is.</description>
      <category>HIPAA/HITRUST</category>
    </item>
    <item>
      <title>ISO 27001 certification: how it actually works</title>
      <link>https://securancepro.com/blog/iso-27001-certification</link>
      <guid isPermaLink="true">https://securancepro.com/blog/iso-27001-certification</guid>
      <pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate>
      <description>A SaaS founder&apos;s guide to ISO 27001 certification: who issues it, stage 1 vs stage 2, the three-year cycle, timelines, and how it compares to SOC 2.</description>
      <category>ISO</category>
    </item>
    <item>
      <title>What Is a SOC 1 Report? ICFR, Examples, and Who Asks</title>
      <link>https://securancepro.com/blog/what-is-a-soc-1-report</link>
      <guid isPermaLink="true">https://securancepro.com/blog/what-is-a-soc-1-report</guid>
      <pubDate>Sun, 11 Jan 2026 00:00:00 GMT</pubDate>
      <description>A SOC 1 report is an auditor&apos;s attestation on a service organization&apos;s controls relevant to its customers&apos; financial reporting. Here is what&apos;s in one.</description>
      <category>SOC</category>
    </item>
    <item>
      <title>What is SOC 2 compliance? A founder&apos;s primer</title>
      <link>https://securancepro.com/blog/what-is-soc-2</link>
      <guid isPermaLink="true">https://securancepro.com/blog/what-is-soc-2</guid>
      <pubDate>Tue, 06 Jan 2026 00:00:00 GMT</pubDate>
      <description>What is SOC 2 compliance, who issues the report, why enterprise buyers ask for it, and how long it actually takes. A CPA firm&apos;s plain-English primer.</description>
      <category>SOC</category>
    </item>
  </channel>
</rss>