When SOC 2 was drafted, its authors did not expect it to apply to companies under 100 employees. Today roughly 90 percent of the organizations going through a SOC 2 are under that threshold.
Part one of this series put the industry data on the table. Part two brings in the other side of the conversation. Nick Norton, co-founder of Geels-Norton (now a Smith & Howard firm) and now leading the cyber risk practice at Smith & Howard, has spent his career issuing SOC 2 reports for high-growth and public SaaS companies. He joins Ryan Patrick of HITRUST and AJ Yawn of Rippling and the GRC Engineering Club for a live, unscripted conversation about where SOC 2 breaks down in third-party risk management, what HITRUST is actually building, and what a workable path forward looks like for the TPRM teams stuck in the middle.
You will leave with a clear read on what a SOC 2 report gives a TPRM team and what it leaves out, how HITRUST positions itself as a third-party risk company, why one audit feeding many reports may be closer than you think, and what still has to change in contracts and procurement before any of it matters.