Schellman describes SOC examinations and readiness assessments. Evaluate the report type, service boundary, evidence process, assigned team, and responsibility for closing gaps before comparing an engagement.
Documented services
Schellman's SOC services page describes SOC 1, SOC 2, and SOC 3 examinations, readiness assessments, and Type 1 and Type 2 reporting. Ask which deliverable addresses your customer's request.
Engagement considerations
Provide the legal entity, service description, relevant systems, controls already operating, and known gaps. Ask the proposed team how it establishes the examination boundary and handles changes during the engagement. Discuss report delivery separately from the period under examination.
Request a sanitized evidence request and follow-up example. Inspect what your team must supply, how questions reach the engagement lead, and how corrections are documented. Establish who performs remediation and how any readiness work relates to the examination.
Questions to verify in a consultation
- Which issuing entity and assigned team appear in the engagement letter?
- Which report type, criteria, and reporting period are proposed?
- How are evidence requests and unresolved findings tracked?
- What access and platform arrangements are required?
- Which changes trigger additional fees or revised milestones?
Scope to confirm
Normalize proposals around systems, period, staffing, readiness work, examination, review, and delivery. Request current credential and peer-review information for the issuing firm. A firm's published service range does not establish that every service is included or that an assessment will produce a particular opinion.
Choose a SOC 2 auditor · Build an auditor selection brief · Plan compliance evidence
Buying content reviewed October 1, 2026. Public sources; no firsthand service evaluation.