+ 001 0231 123 32



All demo content is for sample purposes only, intended to represent a live site. Please use the RocketLauncher to install an equivalent of the demo, all images will be replaced with sample images.

Trusted Advisors to Businesses throughout North America

6 minutes reading time (1109 words)

SOC 1 SSAE 18 and SOC 2 Compliance Auditors | Denver, Colorado | Fixed Fees

NDB is Denver’s leading provider of SSAE 18 SOC 1 compliance audits and SOC 2 assessments, providing highly efficient, fixed fee services for service organizations all throughout the Rockies. The growing regulatory compliance drumbeat just keeps getting louder and louder each year, ultimately forcing Colorado businesses to undertake annual compliance audits, such as SSAE 18 SOC 1, SOC 2, and SOC 3.

NDB has years of experience performing such audits, dating back to as far as 1992 with the now defunct SAS 70 auditing standard, and continuing on with the new AICPA SOC platform. To learn more about NDB’s Denver SOC 1 compliance services – or any other audit mandate – call and speak directly with Christopher Nickell, CPA, at 1-800-277-5415, ext. 706, or email him at This email address is being protected from spambots. You need JavaScript enabled to view it..

SOC 1 Compliance Auditors | Denver, Colorado | Fixed Fees

“So which audit do we need, a SOC 1 or a SOC 2” is a very common question fielded from Denver businesses, and rightfully so as there’s general confusion and misguidance on SOC 1 vs. SOC 2. For purposes of simplicity, SOC 1 assessments – which utilizes the SSAE 18 professional standard – are for companies that display a true nexus to the concept known as Internal Controls over Financial Reporting – ICFR – think banks, actuarial businesses, trust departments, and others.

Moreover, services performed by service organizations can often impact the financial reporting for their clients, thus furthering the need for SOC 1 reporting. As for SOC 2, it’s geared towards technology driven companies, such as managed services providers, ISPs, Software as a Service (SaaS) entities, and more. There’s clear differences between SOC 1 and SOC 2, and you need to be aware of them.

SOC 1 Compliance Auditors | Denver, Colorado | Readiness Assessment

Are you a service organization in the greater Denver, Colorado area new to SOC reporting and are being required to undertake an annual SSAE 18 SOC 1 assessment? If so, the very first move to make is performing a SOC 1 readiness assessment, a helpful and proactive initiative that properly identifies audit scope, policy and procedural gaps, and other items requiring remediation prior to commencing with an actual audit.

While some Denver service organizations can bypass a readiness assessment – if they’ve been doing annual SSAE 18 SOC 1 assessments for quite some time – companies new to SOC reporting are advised to not forgo such an important step in the overall auditing process. Here’s what Colorado service organizations receive when undertaking an NDB SSAE 18 SOC 1 readiness assessment:

Scope Evaluation: What businesses processes are to be assessed for the audit – the entire company or just a segmented or specific service – as this needs to be identified very early on for ensuring no “scope creep” occurs during the audit. Second, does the service organization perform any activities that impact their client’s financial statement reporting – a concept known as “Internal Controls over Financial Reporting”, or simply ICFR.

Remember that the SSAE 18 professional standard should “technically” include controls relating to ICFR – and we preface “technically” because there are a number of entities that have limited and/or no real ICFR relationship (i.e., data centers, etc.), but are still receiving SOC 1 reports, and not SOC 2 reports.

Control Objective Determination: Denver, Colorado service organizations will also need to assess, define, and ultimately agree upon which control objectives will be included within the scope of an SSAE 18 SOC 1 report. Working with a well-qualified CPA during a readiness assessment is an excellent time to conduct this activity, and it’s also an important component of the overall audit. Things to consider are the following: (1). Develop control objectives that include (a). Business process controls. (b). ICFR controls, if necessary, along with (c). information technology general controls, known as ITGC.

Where to Test: Many service organizations have multiple locations across the country or within a certain geographic area. Because of this, one of the goals of an SSAE 18 SOC 1 readiness assessment is to determine which locations are in scope, what activities are to be conducted for the audit, and how there can be efficiencies and cost savings built into the assessment for mitigating travel as much as possible, ultimately reducing costs.

Policy Materials: If you’ve been through an audit – any type of audit – then you are well aware of the importance of documentation – specifically – information security policies and procedures, and other supporting materials. What’s interesting to note is that often times the absence of adequate, current, and relevant security and operational policies are the biggest gaps identified during an SSAE 18 SOC 1 readiness assessment – that’s right. The solution is working with NDB, which provides Colorado businesses an extensive packet of SOC 1 policy documents for helping ease the compliance burden.

What is SOC 1 SSAE 18 and Why Policies are Important

Break the Compliance Mindset: One of the true rewards for Colorado service organizations undertaking an SSAE 18 SOC 1 readiness assessment with NDB is that we go way beyond the minimum compliance mandates when providing expert guidance. True security is about protecting your entire landscape regardless if you have to do an audit or not – it is – and it’s why NDB is a chosen provider of many businesses throughout the Denver area.

SOC 1 Compliance Auditors | Denver, Colorado | Readiness Assessment

When it comes to competitively priced, fixed-fee SSAE 18 SOC 1 and SOC 2 assessments for Denver, Colorado businesses, turn to the experts who’ve been helping service organizations all throughout the Rockies for years, and that’s NDB.

Compliance can be difficult and time consuming, but not with NDB, as we’ve built a highly efficient, scalable roadmap for ensuring rapid SSAE 18 SOC 1 completion – so contact Christopher G. Nickell today at 1-800-277-5415, ext. 706, or email him at This email address is being protected from spambots. You need JavaScript enabled to view it..

Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

SOC 2 Compliance Audits, Reports, & Services for A...
SOC 1 SSAE 18 Compliance Auditors | Denver, Colora...

Get A Free Quote Today!

Fill out my online form.