SOC reports offer a confirmation of services provided by a service organization including information that users need to assess and address the risks associated with an outsourced service. They are designed to help Information Technology service organizations build trust and confidence in their service delivery processes and controls through a report by an independent Certified Public Accountant.
Expedient SOC reports use the National Institute of Standards and Technology (NIST) Special Publications control framework, including NIST SP 800-53. More information about SOC reporting is available from the American Institute of Certified Public Accountants (AICPA).