Generated by All in One SEO v4.9.0, this is an llms.txt file, used by LLMs to index the site. # Auditwerx Cybersecurity Compliance & Advisory ## Sitemaps - [XML Sitemap](https://auditwerx.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Auditwerx Articles | News and Industry Updates](https://auditwerx.com/blog/) - Get the latest news and announcements from the Auditwerx blog. - [When to have Privacy Assessed within a SOC 2®*](https://auditwerx.com/which-service-organizations-should-have-privacy-assessed-within-a-soc-2-examination/) - A common reason that a service organization may request that the privacy trust service category be covered in its SOC 2®* examination, when it may not really be necessary, is related to a misconception of what privacy within the context of the SOC 2® examination actually covers. - [Incident Response Preparedness](https://auditwerx.com/incident-response-preparedness/) - New types of incidents are occurring all the time as cyber criminals continue to evolve. The question is, are you continuing to evolve and prepare for these incidents? - [Navigating Risks in the Midst of the COVID-19 Chaos](https://auditwerx.com/navigating-risks-in-the-midst-of-the-covid-19-chaos/) - The impact of COVID-19 has meant making quite a few changes in a rapid fashion to help ensure business continuity. As you work to continue to serve your clients while also supporting a mostly remote workforce, you may have lost focus on the operation of your internal controls. - [Best Practices to Consider in a SOC* Assessment Period](https://auditwerx.com/reminders-best-practices-that-need-to-be-considered-throughout-the-soc-examination-period/) - The impacts of COVID-19 may have caused your company to change up processes and work outside of what is normal operations. Below are some best practices to consider in getting back to “normal” for the current and future SOC* reporting periods. - [A Few Best Practices for AWS Logical Security](https://auditwerx.com/best-practices-for-aws-logical-security/) - The ease of spinning up EC2 instances is coming at the expense of security controls that would otherwise be in place to protect on-premises servers. AWS admins need to use available tools properly to help ensure the logical security of their environments. - [IT Pro Tip: Protect ALL of Your Assets](https://auditwerx.com/auditwerx-it-pro-tip-inventory-management/) - Not only is asset management critical from a financial standpoint (licensing, depreciation, etc.), but it also greatly facilitates security, assessment, and compliance initiatives. - [IT Pro Tip: Working Securely From Home](https://auditwerx.com/it-working-securely-from-home/) - Many are working from home and with this means phishing attempts are on the rise. Opening attachments or clicking links that are unexpected could put your organization and your home network at risk. - [Continuous Controls Monitoring](https://auditwerx.com/continuous-controls-monitoring/) - While most organizations dread that time of year when their audit is performed (SOX, PCI, SOC*, etc.), it doesn't have to be painful. We can help. - [Working From Home and PCI](https://auditwerx.com/working-from-home-and-pci/) - As business as usual changes, it is important to educate and reinforce security awareness training among employees and introduce them to new security considerations in a work from home environment. - [Are Third-Party Tools Costing You Money?](https://auditwerx.com/are-third-party-readiness-tools-costing-your-business-extra-money/) - Third-party SOC* or PCI readiness tools seem easy, don’t they! Taking a hands-off approach to your company’s security compliance may seem like it’s saving you time and money, but is that really true? Find out here. - [What Kind of SOC* Report Does My Company Need?](https://auditwerx.com/what-kind-of-soc-report-does-my-company-need/) - Which SOC* report is right for your service organization? The experienced team at Auditwerx can help guide you through the SOC* process. - [What is a SOC* Report?](https://auditwerx.com/what-is-a-soc-report/) - Not familiar with SOC* reports? That's ok! The experienced team at Auditwerx can help guide you through the SOC* process. - [How to Prepare for a SOC* Assessment](https://auditwerx.com/how-to-prepare-for-a-soc-audit/) - A SOC* report can answer specific client requests regarding your sensitive business practices. Here are 6 tips to help make sure your SOC* assessment is a success. - [SOC 1®* Compliance Checklist](https://auditwerx.com/soc-1-compliance-checklist/) - Are you prepared for your SOC 1®* assessment? Do you know what your assessors will be looking for? If you are ready to start your SOC 1® compliance journey, we have the guidance you need to get started on the right foot by using this handy checklist. - [Understanding PCI DSS v4.0 - Change Summary - Part 3](https://auditwerx.com/understanding-pci-dss-v4-change-summary-part-3/) - In the last part of our “Understanding PCI DSS v4.0” series, we’ll tackle the remaining changes in PCI DSS v4.0 that are likely to impact your day-to-day business practices. - [PCI Pro Tip: Configuration Standards](https://auditwerx.com/pci-configuration-standards/) - The PCI DSS requires that an organization have configuration standards for devices that make up their infrastructure such as firewalls, routers, load balancers, switches and servers. That includes devices that exist virtually as well as those that exist physically. - [PCI Primer: What is PCI DSS?](https://auditwerx.com/what-is-pci-dss/) - We’ve got you covered with all you need to know in our new PCI Primer blog series, and we’re starting with the basics. - [3 Reasons Why PCI DSS Compliance is Important to Your Business](https://auditwerx.com/why-pci-dss-compliance-is-important-to-your-business/) - 3 top reasons why PCI DSS compliance is important to your business - save business time, money, and headaches down the road. - [5 Ways to Implement PCI DSS Everyday](https://auditwerx.com/ways-to-implement-pci-dss-into-your-every-day-business-processes/) - Building good PCI habits is an important your overall security strategy! Making PCI compliance the norm at every level helps reduce your security risk and build trust. - [PCI DSS Merchant Levels](https://auditwerx.com/pci-dss-merchant-levels/) - Merchants are still considered the core of PCI DSS. Auditwerx QSAs can help you navigate merchant levels. - [SOC 1®* ICFR Control Objectives](https://auditwerx.com/soc1-icfr-control-objectives/) - Find out if a SOC 1®* Internal Controls Over Financial Reporting (ICFR) assessment is right for you. - [SOC 2®* Trust Services Criteria](https://auditwerx.com/soc2-trust-services-criteria/) - The SOC 2®* report analyzes 5 specific aspects of your service organization. Learn what they are and prepare for your next SOC 2®* assessmentt today. - [How to Choose a SOC 2®* Assessment Firm](https://auditwerx.com/how-to-choose-a-soc2-audit-firm/) - 4 key considerations to keep in mind when choosing a SOC 2®* assessment firm for your company. - [SOC* Readiness FAQ](https://auditwerx.com/soc-readiness-faq/) - If you're new to the SOC* reporting process, our SOC* readiness assessment is your best tool for success. - [Cybersecurity Awareness Month](https://auditwerx.com/cybersecurity-awareness-month/) - National Cybersecurity Month encourages us all to own our responsibility to protecting our little corner of cyberspace. - [What to Know About Emerging SOC 2®* Compliance Software: Part 1](https://auditwerx.com/what-to-know-about-soc2-compliance-software-part1/) - New software options that promise to streamline SOC 2®* compliance have exploded in recent years - but are they making compliance easier? Find out here. - [What to Know About Emerging SOC 2®* Compliance Software: Part 2](https://auditwerx.com/what-to-know-about-soc2-compliance-software-part2/) - It’s important to understand the limitations of automated SOC 2®* software, as they are often promoted as being able to save you time and money. But is that really the case? - [What to Know About Emerging SOC 2®* Compliance Software: Part 3](https://auditwerx.com/what-to-know-about-soc2-compliance-software-part3/) - While automated tools can never replace a human assessor, there are certain standards you can utilize on a day-to-day basis. Learn more. - [SOC 2®* Readiness Checklist](https://auditwerx.com/soc-readiness-checklist/) - There is no official SOC 2®* readiness checklist, but we can help you get started. Learn how a readiness assessment can support your business goals. - [Why Does My Business Need a SOC* Report?](https://auditwerx.com/why-does-my-business-need-a-soc-report/) - It's important to give your business every advantage in a competitive market. Get our 4 key reasons you should consider a SOC* report for your organization. - [How Much Does a SOC* Report Cost?](https://auditwerx.com/how-much-does-a-soc-report-cost/) - When it comes to balancing compliance needs and ROI, there are a few factors at play when determining the pricing of a SOC* assessment. Learn more. - [SOC 2®* Compliance Checklist](https://auditwerx.com/soc-2-compliance-checklist/) - Learn about the controls analyzed by a SOC 2®* report and discover how you can prep your business ahead of your SOC 2® engagement. - [PCI DSS Compliance Checklist](https://auditwerx.com/pci-dss-compliance-checklist/) - If you are looking to start your own PCI DSS Compliance initiative, we have some advice to help you get started on the right foot. - [The Benefits of a SOC* Readiness Assessment](https://auditwerx.com/benefits-of-a-soc-readiness-assessment/) - SOC* Readiness is the first step to a successful SOC report or engagement. Learn why SOC Readiness should be the first stop on your compliance journey. - [AOC, ROC, SAQ: The Alphabet Soup of PCI DSS](https://auditwerx.com/aoc-roc-saq-what-does-it-all-mean/) - AOC, ROC, SAQ - let's explore the alphabet soup of PCI reporting. - [SOC* Type 1 vs SOC* Type 2](https://auditwerx.com/soc-type1-or-soc-type2/) - If you are new to SOC* reporting, you might be wondering about the different kinds of SOC* reports available. Let's break them down. - [International Fraud Awareness Week](https://auditwerx.com/international-fraud-awareness-week/) - Did you know that it's International Fraud Awareness Week? Auditwerx supports the global effort to minimize the impact of fraud. - [Data Privacy Day](https://auditwerx.com/data-privacy-day/) - Being #PrivacyAware is good for business! Get the keys you need to keep your data secure at home or at work! - [Why You Should Have a Clean Desk Policy](https://auditwerx.com/why-you-should-have-a-clean-desk-policy/) - All of the digital precautions in the world won't matter if you leave your password out on a sticky note. Learn about the benefits of a clean desk policy. - [Protect Sensitive Data on World Backup Day](https://auditwerx.com/protect-sensitive-data-on-world-backup-day/) - March 31 is World Backup Day! Protect your sensitive information against loss or theft. - [Identity Management Day](https://auditwerx.com/identity-management-day/) - Don't take risks with your sensitive information! Auditwerx supports Identity Management Day. - [World Password Day](https://auditwerx.com/world-password-day/) - A strong password is the first step to securing your digital life at work, or at home! - [Tools for Success](https://auditwerx.com/auditwerx-tools-for-success/) - We pride ourselves on providing a simple, but comprehensive, assessment experience to our clients. We have the tools you need to experience a compliance assessment completed on time and on budget. - [The Basics of SOC 1®* Controls](https://auditwerx.com/the-basics-of-soc1-controls/) - Get a better understanding of the kinds of controls that could be examined during a SOC 1®* report. - [PCI DSS Requirements: What You Need to Know](https://auditwerx.com/pci-dss-requirements-what-you-need-to-know/) - There are many different standards you must accept if your company processes payment card information, in relation to the PCI DSS. Learn more. - [What are SOC 1®* IT General Controls?](https://auditwerx.com/what-are-soc1-it-general-controls/) - Understand the controls analyzed during a SOC 1®* assessment. - [PCI DSS 4.0: Key Developments You Need to Know](https://auditwerx.com/pci-dss-v4/) - PCI DSS v4.0 is here to help combat new and evolving security threats to the payment industry. - [SSAE No. 21 & SSAE No. 22: What You Need to Know](https://auditwerx.com/ssae-updates-2022/) - It’s important that your auditor has the knowledge to help your service organization navigate the ever-evolving world of SOC* compliance. Let’s take a look at two recent changes, SSAE No. 21 & SSAE No. 22. - [Meet Our Partners: Bridget Boswell](https://auditwerx.com/meet-our-partners-bridget-boswell/) - With over 20 years of industry experience, including with “Big 10 Firms,” Bridget provides her clients with the industry experience they need to complete their compliance assessments quickly and easily. - [Meet Our Partners: Stacy Martin, CEO](https://auditwerx.com/meet-our-partners-stacy-martin-ceo/) - With over 19 years of experience in financial reporting and internal control attestation, Stacy has the “Big 10 Firm” experience you’re looking for. - [Understanding PCI DSS v4.0 - Change Summary - Part 1](https://auditwerx.com/understanding-pci-dss-v4-change-summary-part-1/) - Now that we’ve taken a look at the broad strokes of the PCI DSS v4.0 changes, let’s take a deeper dive into the impact these changes might have on organizations like yours. - [Understanding PCI DSS v4.0 - Change Summary - Part 2](https://auditwerx.com/understanding-pci-dss-v4-change-summary-part-2/) - In Part 2 of our “Understanding PCI DSS v4.0” series, we will explore additional changes introduced in PCI DSS v4.0 as included in the “Evolving Requirement” section that analyzes changes needed to required business tasks that are related to remaining compliant with the PCI DSS. - [SOC 2®*: Privacy vs. Confidentiality](https://auditwerx.com/soc-2-privacy-vs-confidentiality/) - Did you know that there is a difference between “Privacy” and “Confidentiality” when it comes to assessing SOC 2®* compliance? - [PCI 4.0.1 Req 12.8.5: Vendor Oversight](https://auditwerx.com/pci-4-0-1-requirement-12-8-5-vendor-oversight-responsibility-matrices-and-scope-implications/) - As organizations increasingly rely on third-party service providers (TPSPs) to support payment processing environments, the need for clear oversight and accountability has never been more critical. - [Why GRC Tools Can't Replace Your Assessment Firm](https://auditwerx.com/compliance-reports-why-your-grc-tool-cant-replace-an-assessment-firm/) - SOC 2® reports, HIPAA attestations, or PCI DSS Reports are not simply printouts from a software dashboard. They are formal, independent assessments provided by qualified third-party firms like Auditwerx. Understanding this critical difference is key to a truly effective and credible compliance strategy. - [Auditwerx Can Partner with Your Existing Compliance Tools](https://auditwerx.com/auditwerx-partner-compliance-tools/) - Many organizations use compliance tools throughout the year to maintain or monitor compliance initiatives, but you still need an experienced assessor. - [Specialized Assessment Firms: Unmatched Value for Compliance](https://auditwerx.com/why-specialized-assessment-firms-deliver-unmatched-value-for-your-compliance-reports/) - When it comes to highly specialized compliance assessments – like SOC 2®, HIPAA, or PCI DSS – does a Big 4 firm always translate to the best experience or the most reliable report for your organization's unique needs? At Auditwerx, we believe the answer is often found in the dedicated focus of a specialized assessment firm. - [Limits of Security-Only, 3-Month Reports for SOC 2® Position](https://auditwerx.com/why-security-only-3-month-reports-might-not-address-your-soc-2-compliance-position/) - When it comes to SOC 2® compliance, it’s crucial to understand a key fact: GRC tools cannot issue an official SOC 2® report. Only a licensed, independent Certified Public Accountant (CPA) firm can provide the official attestation required for a valid SOC 2® report. - [Why a 3-Month GRC Report Isn't a Valid SOC 2® Attestation](https://auditwerx.com/why-a-3-month-grc-tool-security-report-is-not-a-true-soc-2-attestation/) - In today's digital world, showing your clients that you are committed to protecting their data is a top priority. For many service organizations, a SOC 2® report has become the gold standard for demonstrating this commitment. Here’s why a 3-month report isn't a substitute for a comprehensive report from a professional assessment firm like Auditwerx. - [CMMC Acquisition Rule Published: Phase 1 Begins Nov 10](https://auditwerx.com/the-final-countdown-cmmc-acquisition-rule-published-phase-1-begins-november-10th/) - The Department of Defense (DoD) has officially published the Final Cybersecurity Maturity Model Certification (CMMC) Acquisition Rule, marking the beginning of a new era for safeguarding sensitive government information.The most important date to remember is November 10, 2025, when CMMC requirements will begin appearing in new DoD contracts. Knowing what’s coming next is the key to staying ahead. - [PCI Frequencies Gone? Welcome to Targeted Risk Analysis](https://auditwerx.com/pci-where-did-the-frequencies-go-welcome-to-the-world-of-targeted-risk-analysis/) - With PCI DSS 4.0, nine of the requirements were rewritten to allow the assessed entity to define how frequently the control should be completed. While that flexibility sounded great to some folks, others weren’t exactly thrilled—because guess what? It means more paperwork. Every. Single. Year. These nine requirements now require a Targeted Risk Analysis (TRA) to justify the timing you choose. Let’s walk through each one and decide what might be best for your company. - [Maximize Your GRC Tool's Impact with Auditwerx Guidance](https://auditwerx.com/maximize-your-grc-tools-impact-how-auditwerx-helps-you-get-it-right/) - We can help you unlock the full potential of your GRC tool, transforming it into a powerful asset that works seamlessly with your assessment process. - [PCI DSS: Manage End-of-Life Assets & Avoid Tech Obsolescence](https://auditwerx.com/is-your-tech-ticking-toward-obsolescence-catch-end-of-life-assets-before-they-crash/) - PCI DSS 4.0.1 requirement 12.3.4 requires that all software and hardware is supported by the vendor. That sounds easy. Right? It's not. Let's discuss. - [Guardians of the Gate: Mastering PCI DSS Controls for Accounts](https://auditwerx.com/guardians-of-the-gate-mastering-pci-dss-controls-for-system-and-application-accounts/) - Let’s be honest: system and application accounts aren’t exactly the life of the party. They do their work quietly behind the scenes, much like the custodians who keep the real world running smoothly. But when it comes to PCI DSS 4.0.1 requirements—specifically 7.2.5, 7.2.5.1, and 8.6.1 through 8.6.3—these digital custodians become the stars of the security show. Ready for a quick, fun, and informative stroll through these must-know controls? Grab your metaphorical flashlight; we’re heading into the vault! - [GRC Tools: Power-Up Your Compliance, Get Specialized Guidance](https://auditwerx.com/grc-tools-your-compliance-power-up-not-a-replacement-for-specialized-guidance/) - At Auditwerx, we're advocates for smart technology. We believe GRC tools are excellent investments that can significantly enhance your compliance program. However, their true power is unlocked when combined with specialized guidance and the independent assurance only a qualified assessment firm can provide. Think of it less as a competition and more as a powerful partnership. - [SOC 2® Readiness: Why GRC Tools Need an Assessment Firm](https://auditwerx.com/grc-tools-and-being-ready-for-soc-2-why-you-need-an-assessment-firm/) - While GRC tools can be helpful for tracking security controls in a limited scope, they don’t provide the in-depth analysis and comprehensive support necessary to ensure full SOC 2® compliance. In this blog post, we’ll explore the key differences between GRC tools and working with an assessment firm like Auditwerx, and why choosing the right path is crucial to preparing your business for a successful SOC 2® certification. - [CMMC 2.0 Final Rule: Get the Roadmap for What's Next](https://auditwerx.com/cmmc-2-0-the-final-rule-is-here-get-the-roadmap-for-whats-next/) - The final Cybersecurity Maturity Model Certification (CMMC) Acquisition Rule has been published. This isn't just a regulatory update; it's the beginning of a phased, multi-year journey for the entire Defense Industrial Base (DIB). The most important date to remember is November 10, 2025, when CMMC requirements will begin appearing in new DoD contracts. Knowing what’s coming next is the key to staying ahead. - [Understanding the 2022 DoD SRG](https://auditwerx.com/understanding-the-2022-dod-srg/) - Did you know that according to the 2022 Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG) the Cloud Service Providers (CSPs) with an IL4 or IL5 status may need a SOC 1®* report? - [Secure PCI Compliance Portal](https://auditwerx.com/pci-compliance-portal/) - An Auditwerx QSA is the partner you need for an efficient, timely, and accurate PCI DSS compliance report. Our QSA team is fully trained to map to the PCI DSS v4.0 framework and can help you through each step of the PCI compliance process. If you’re ready to simplify PCI, contact Auditwerx today. - [What is PCI Compliance and Who Needs It?](https://auditwerx.com/what-is-pci-compliance-and-who-needs-it/) - Securing sensitive payment information is crucial in today’s ever-changing digital landscape. The PCI DSS was created in order to encourage and enhance consistent and effective data security measures designed to protect payment account data. - [SOC 2®* Type 2 Compliance: What It Is and Why You Need It](https://auditwerx.com/soc-2-type-2-compliance-what-is-it-and-why-do-you-need-it/) - A SOC 2®* Type 2 assessment demonstrates your organization’s commitment to securing sensitive data. - [What is PCI DSS?](https://auditwerx.com/what-is-pci-dss-2/) - PCI DSS compliance doesn’t have to be complicated. Let’s break down the key information you need to know about what the PCI DSS requires, and how a certified QSA can help simplify the process. - [SOC 2®* Compliance and Certification](https://auditwerx.com/soc-2-compliance-and-certification/) - Cybersecurity is a continuous process that must evolve to meet ongoing threats. Becoming SOC 2®* compliant is one way to show your current and future clients that you take data security seriously and are ready to meet their needs in today’s digital environment. - [Understanding HIPAA IT Compliance](https://auditwerx.com/understanding-hipaa-it-compliance/) - Let’s break down the keys of HIPAA compliance and what that might mean for your organization. - [Another Successful Peer Review for Auditwerx](https://auditwerx.com/peer-review-2022/) - Auditwerx is proud to announce that we have received the highest possible pass score during our latest peer review, demonstrating our commitment to high-quality compliance reporting. - [The Cost of Non-Compliance](https://auditwerx.com/the-cost-of-non-compliance/) - The costs of poor cybersecurity compliance management are much more than those associated with compliance reporting and process optimization. - [SOC 2®* Compliance Explained ](https://auditwerx.com/soc-2-compliance-explained/) - Developed by the AICPA, SOC 2®* focuses on the five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. - [PCI Assessment: What You Need to Know](https://auditwerx.com/pci-assessment-and-certification-what-you-need-to-know/) - Payment compliance doesn’t have to be daunting, and choosing a reliable and experienced PCI compliance company can make all the difference. - [Maintaining Compliance Throughout the Year](https://auditwerx.com/maintaining-compliance-throughout-the-year/) - Ensuring proper monitoring and updates of your cybersecurity controls on an ongoing basis will ease the compliance reporting process and help your business stay secure. - [What is in a SOC* Report and Why Do I Need One?](https://auditwerx.com/what-is-in-a-soc-report-and-why-do-i-need-one/) - Have your clients been asking about your SOC* status? More businesses are relying on SOC* reports for reassurance regarding their partner’s security environment. - [Understanding Automated Compliance Monitoring Tools](https://auditwerx.com/understanding-automated-compliance-monitoring-tools/) - Let’s break down the ways that compliance software may help your business and get a better understanding of the potential capabilities a new compliance tool may offer. - [What is a SOC 1®* Report?](https://auditwerx.com/what-is-a-soc1/) - The SOC 1®* report is designed to offer clarity for clients when your services may impact their financial statements. - [What is SOC*+?](https://auditwerx.com/what-is-soc-plus/) - A SOC*+ report allows for your controls to be mapped to multiple security frameworks, enabling you to demonstrate compliance with multiple standards within a single report. - [The Importance of Independence in SOC* Reporting](https://auditwerx.com/the-importance-of-independence-in-soc-reporting/) - Understanding the importance of utilizing an independent assessment firm like Auditwerx can have a big impact on how your organization chooses to meet compliance obligations. - [SOC 2®* Assessments and the Effects of Software Tools](https://auditwerx.com/soc2-examinations-and-the-effects-of-software-tools/) - Updates on Recent Clarifications Provided by the AICPA. Learn the impact that using a GRC tool can have on your SOC* compliance initiatives. - [Fourth Quarter Compliance Reporting Requirements? Don't delay.](https://auditwerx.com/fourth-quarter-reporting-requirements-start-now-for-a-timely-audit/) - In many industries, compliance reporting is expected to be delivered by December each year. If that is the case for your organization, it’s time to consider securing an assessment firm in order to meet the appropriate deadlines. - [Auditwerx Offers Microsoft SDPR Compliance Solutions](https://auditwerx.com/auditwerx-offers-microsoft-sdpr-compliance-solutions/) - Suppliers, partners, and vendors that are part of the Microsoft ecosystem are required to certify compliance with the Microsoft Supplier Data Protection Requirements (SDPR). - [The Compliance Reporting You Need on Your Schedule](https://auditwerx.com/the-compliance-reporting-you-need-on-your-schedule/) - When your clients are asking to see your cybersecurity certifications, you need efficient reporting services to show your commitment to data protection and effective security controls in a timely manner. Auditwerx consistently works to provide the cybersecurity solutions you need in a way that works with your business needs. - [Don't Delay Fourth Quarter Reporting Requirements](https://auditwerx.com/fourth-quarter-reporting-requirements-current-clients/) - When it comes to cybersecurity reporting, Auditwerx is your true partner. Our services are tailored to work with your business needs in order to secure a seamless and successful assessment. - [The HIPAA Security Rule: Basic Requirements ](https://auditwerx.com/the-hipaa-security-rule-basic-requirements/) - Your organization must assess the security risks involved with storing or transmitting ePHI and ensure compliance with the HIPAA security rule and proper documentation of your compliance processes. - [Does Cybersecurity Compliance Offer a Competitive Advantage?](https://auditwerx.com/does-cybersecurity-compliance-offer-a-competitive-advantage/) - The cybersecurity landscape continues to evolve – and so do the risks to your organization. Compliance may feel like a slog, or may be a difficult sell due to the perceived cost, but did you know that being able to demonstrate a comprehensive compliance program may also help your organization differentiate themselves from the competition and win new business? - [Common Reasons for Control Exceptions in SOC 2®* Type 2 Reports](https://auditwerx.com/common-reasons-for-control-exceptions-in-soc-2-type-2-reports/) - Did you know it is extremely common for SOC 2®* Type 2 reports to contain control exceptions? Let’s take a look at some factors that impact control exceptions in SOC 2® Type 2 reports. - [How Quickly Can I Get a Compliance Report?](https://auditwerx.com/how-quickly-can-i-get-a-compliance-report/) - While it may be frustrating to learn that an assessment could take several months to be completed properly, you owe it to your clients and key stakeholders to ensure that your report is completed in the proper manner. - [3 Tips for Choosing a Security Compliance Partner](https://auditwerx.com/3-tips-for-choosing-a-security-compliance-partner/) - Consider these 3 aspects when doing your due diligence in choosing an assessment partner for the first time or looking for a new partner. - [Does Your Assessor Do These 3 Things When Collecting Evidence?](https://auditwerx.com/does-your-service-auditor-do-these-3-things-when-collecting-evidence/) - A generic list of evidence artifacts doesn’t properly address your organization’s unique concerns and security needs, leading to a compliance report that is lacking in the essential information your clients are looking for. - [SOC 2®* Certification: The Basics](https://auditwerx.com/soc-2-certification-the-basics/) - A SOC 2®* certification offers detailed assurance of cybersecurity controls in place at service organizations like yours. - [What is a SOC 1®* Report: How to Prepare and Why You Need It ](https://auditwerx.com/what-is-a-soc-1-report-how-to-prepare-and-why-you-need-it/) - A SOC 1®* report could help demonstrate the IT general controls and business process controls in place to achieve control objective statements. - [SOC 2®* Type 2: Definition and Scope](https://auditwerx.com/soc-2-type-2-definition-and-scope/) - Explore what SOC 2®* Type 2 certification is, its significance for your business, the benefits of SOC 2®Type 2 compliance, and how to achieve SOC 2® Type 2 certification for your organization. - [Law Firms and the Importance of Strong Cybersecurity Practices](https://auditwerx.com/law-firms-and-the-importance-of-strong-cybersecurity-practices/) - Like other major corporations and professional service providers, the reputation of a law firm plays a crucial role in its profitability and sustainability. Learn how a SOC 2®* can help. - [Strategic Compliance Solutions with Drata](https://auditwerx.com/auditwerx-enhances-strategic-compliance-solutions-through-partnership-with-drata/) - Auditwerx, a division of Carr, Riggs, and Ingram, LLC, proudly announces its strategic partnership with Drata, the most advanced security and compliance automation platform. - [6 Key Automation Risks Assessed in the AICPA Peer Review](https://auditwerx.com/6-key-automation-risks-assessed-in-the-aicpa-peer-review/) - If your organization is undergoing a SOC* assessment and using an automation tool, it's essential to be aware of the heightened scrutiny you might face. Learn more. - [ISO 27001 vs. SOC 2®*](https://auditwerx.com/iso-27001-vs-soc-2-navigating-your-information-security-compliance-audit/) - Are clients or potential customers starting to ask for your latest information security compliance report? If you haven’t heard from them yet, expect those inquiries soon. ISO 27001 and SOC 2®* are two leading frameworks that can elevate your organization’s information security compliance initiatives. - [CMMC Program Final Rule Published](https://auditwerx.com/cybersecurity-maturity-model-certification-program-final-rule-published/) - On October 15, 2024, the U.S. Department of Defense (DoD) published the final Cybersecurity Maturity Model Certification (CMMC) program rule in the Federal Register. - [Final Rule Publication for CMMC Ready for 2025](https://auditwerx.com/final-rule-publication-for-cmmc-2-0-sets-the-stage-for-a-release-in-2025/) - The Department of Defense (DoD) has announced the final rule for Cybersecurity Maturity Model Certification (CMMC) 2.0, and contractors will be expected to meet these standards in 2025. - [PCI 4.0.1 – Key Changes You Need to Know](https://auditwerx.com/pci-4-0-1-key-changes-you-need-to-know/) - You’ve put it off, you’ve ignored it, you’ve just been busy… whatever the case, PCI Version 4.0.1 new requirements are a reality as of April 1, 2025. Let’s dive into each new requirement. - [PCI 12.5.2 Scoping Exercise: A Comprehensive Guide](https://auditwerx.com/pci-12-5-2-scoping-exercise-a-comprehensive-guide/) - The Payment Card Industry Data Security Standard (PCI DSS) version 4.0 introduced a formal requirement for a documented scoping exercise under PCI 12.5.2. This guide breaks down the scoping process, offering practical steps and tips to streamline compliance. - [HIPAA vs. HITRUST: Understanding Key Differences](https://auditwerx.com/hipaa-hitrust-key-differences/) - In today's interconnected world, ensuring healthcare data security is paramount. If your organization handles patient health information (PHI), you're undoubtedly familiar with the need for strict healthcare compliance. Learn about the difference between HIPAA and HITRUST and what it means for your organization. - [Service Accounts vs User Accounts – Key Differences for PCI](https://auditwerx.com/pci-service-accounts-vs-user-accounts/) - PCI DSS 4.0.1 requirement 12.3.4 requires that all software and hardware is supported by the vendor. That sounds easy. Right? It's not. Let's discuss. - [Patch, Scan, Repeat: Mastering PCI DSS Vulnerability Management](https://auditwerx.com/mastering-pci-dss-vulnerability-management/) - Meeting the requirements of the Payment Card Industry Data Security Standard (PCI DSS) isn't just about checking boxes—it's about creating a secure environment that protects cardholder data. One of the most critical components of PCI compliance is a strong vulnerability management program. - [SOC 2®* Compliance: GRC Tool vs. Assessment Firm](https://auditwerx.com/soc-2-compliance-grc-tool-vs-assessment-firm/) - While GRC tools are invaluable for continuous monitoring and preparing for compliance, it's crucial to understand that a SOC 2® report issued by an accredited, independent assessment firm holds significantly more credibility, depth, and recognition than a report generated from a GRC tool's automated output. - [Auditwerx Can Assist with GRC Tool Set Up](https://auditwerx.com/auditwerx-can-assist-with-grc-tool-set-up/) - We can help you unlock the full potential of your GRC tool, transforming it into a powerful asset that works seamlessly with your assessment process. - [Debunking Common Myths About GRC Tools and SOC* Reports](https://auditwerx.com/debunking-common-myths-about-grc-tools-and-soc-reports/) - Governance, Risk, and Compliance (GRC) tools and SOC* reports are essential components of any organization's risk management strategy. However, there are several myths surrounding these resources that can lead to confusion and ineffective use. Whether you're a small business or a large enterprise, understanding the reality behind these myths can help you maximize the value of your GRC framework and SOC reports. - [Why a Quality SOC* Assessment Matters](https://auditwerx.com/why-a-quality-soc-assessment-matters/) - Your assessment partner needs to be able to work closely with your key stakeholders to properly address your unique processes and controls. An experienced team with a long-standing reputation can help facilitate your SOC assessment in an efficient manner, saving your organization time and money. - [Why SOC* Examination Period Length Matters](https://auditwerx.com/why-soc-examination-period-length-matters/) - While GRC tools often push a 3-month examination period for a SOC assessment, a 6 -month evaluation provides a more comprehensive and credible view of your organization's controls. - [Risks for Service Organizations When Using SOC 2®* Tools](https://auditwerx.com/risks-for-service-organizations-when-using-soc-tools/) - When SOC 2®* tools are properly designed and managed, they can benefit service organizations and service assessors alike. However, depending on the scope of the tools, there are risks that both parties need to be aware of when it comes to SOC 2® reporting. ## Pages - [Security Compliance Reporting & Advisory Services](https://auditwerx.com/) - Auditwerx is a candidate C3PAO ready to help with CMMC readiness. Learn more >> Build Confidence with Compliance. Auditwerx specializes in security advisory, compliance and reporting services for clients throughout the United States and internationally. Our services are designed to identify organizational threats, solve complex business challenges, review internal business processes and controls, and protect - [CMMC Readiness Assessment Services](https://auditwerx.com/cmmc-readiness-services/) - Eliminate Surprises with CMMC Readiness As a Candidate C3PAO, we prepare you with the mindset of the assessor. We provide CMMC Readiness assessment servvices to identify and remediate NIST SP 800-171 deficiencies, ensuring your SSP and POA&M are assessment ready. Get the peace of mind that comes with Candidate C3PAO-vetted preparation Prepare efficiently for your - [Careers at Auditwerx | Join Our Team](https://auditwerx.com/careers/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> Careers Check success off your to-do list. View Available Positions Why Choose Auditwerx Join our growing team of cyber professionals committed to continuous learning and having fun as we serve our clients across the US and Canada. We are - [About Auditwerx | Compliance Reporting Firm](https://auditwerx.com/about-us/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> About Us We are assessment professionals. We are IT professionals. We are Auditwerx. Your Partner for Security Compliance & Attestation Auditwerx is headquartered in Tampa, Florida. We have served clients throughout the U.S. and internationally since 2009, providing over - [Microsoft SDPR Compliance Services & Reporting](https://auditwerx.com/microsoft-sdpr-compliance-services/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> Microsoft SDPR Compliance Your organization will be required to demonstrate compliance with the Microsoft SDPR before becoming a vendor, and on a yearly basis for existing vendors. Get Your FRee Download Comprehensive Microsoft SDPR Solutions. Microsoft SDPR Compliance is - [NIST CSF Compliance Services & Reporting](https://auditwerx.com/nist-csf-compliance-services/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> NIST CSF Compliance Build trust by demonstrating compliance with NIST CSF. Identify and implement strong security practices as an organization. Get Your Free Download Streamline NIST CSF Compliance. Experienced compliance team, high-quality reporting. The U.S. Commerce Department’s National Institute - [Privacy Compliance Reporting Services](https://auditwerx.com/privacy-compliance/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> Privacy Compliance It is incumbent on organizations to keep personal data secure, not only due to concerns on compliance risks, but reputational risk can cost organizations significantly. Auditwerx can help. Why a Privacy Compliance Assessment? Privacy concerns and legislation - [HITRUST CSF Assessment Services](https://auditwerx.com/hitrust-assessment/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> HITRUST Assessment A HITRUST assessment can help you save time and money by creating a clear framework for complying with various regulatory requirements. Why a HITRUST Assessment? HITRUST uses a Common Security Framework (CSF) to help healthcare organizations manage - [HIPAA Compliance Assessment Services | HIPAA Risk Assessment](https://auditwerx.com/hipaa-assessment/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> HIPAA Compliance Auditwerx can serve as the independent third party you need, to not only ensure HIPAA compliance, but also strengthen your existing internal controls. Why a HIPAA Compliance Assessment? Assessing and implementing the necessary safeguards for HIPAA compliance - [PCI DSS Compliance Reporting Services | PCI DSS QSA](https://auditwerx.com/pci-2/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> PCI DSS Compliance Auditwerx is a PCI Qualified Security Assessor Company (QSAC) and has offered PCI DSS compliance solutions for businesses of all sizes for over 10 years. Get Your PCI DSS v4.0 Download Full-Service PCI DSS Compliance Solutions - [ISAE 3402 Compliance Reporting Services](https://auditwerx.com/isae3402/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> ISAE 3402* The ISAE 3402* provides your customers with the assurance your service business is maintaining effective and efficient internal controls related to financial, information, or security reporting. From Start Ups to Large Organizations, Auditwerx is the ISAE 3402* - [CSAE 3416 Compliance Reporting Services](https://auditwerx.com/csae3416/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> CSAE 3416* The CSAE 3416* report provides your customers with the assurance your organization is maintaining effective and efficient internal controls related to financial, informational, or security reporting. From Start Ups to Large Organizations, Auditwerx is the CSAE 3416* - [SOC* for Cybersecurity Compliance Services](https://auditwerx.com/cybersecurity/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC* for Cybersecurity SOC* for Cybersecurity offers a structured approach to implementing security controls which are effective, measurable, and mitigate risk. DISCOVER: What Kind of SOC Report Do You Need? Why SOC* for Cybersecurity? In response to the heightened - [SOC 3® Compliance Reporting Services](https://auditwerx.com/soc-3-reporting/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC 3®* Highlighting your internal control environment could give you the competitive edge you need, but a SOC 2®* report contains confidential information. Market your capabilities with a SOC 3®* report DISCOVER: What Kind of SOC Report Do You - [SOC 2®+ Compliance Reporting | Test Once, Report Many](https://auditwerx.com/soc-2-reporting/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC 2®+* Test once, report many. Customer requests for a variety of certifications can seem never ending – but it doesn’t have to be that way. During a SOC 2®+* assessment, controls can be mapped to multiple security frameworks - [SOC 2® Compliance Reporting Services](https://auditwerx.com/soc2/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC 2®* A SOC 2®* report offers comfort over the internal controls at service organizations like yours, so you can gain an edge on your competition. Contact a SOC 2® Specialist From SOC 2®* Readiness to Your Final Report, - [SOC 1® (SSAE 18) Compliance Reporting Services](https://auditwerx.com/soc1-ssae18/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC 1®* (SSAE 18) Clients want information about controls over processes that affect their financial statements. A SOC 1® report provides the confidence clients need about how their data is processed. DISCOVER: What Kind of SOC Report Do You - [SOC* Readiness Services | SOC 1®, SOC 2®, & More](https://auditwerx.com/soc-readiness-services/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC* Readiness Services Take the mystery out of SOC* reporting with a SOC* readiness assessment. Identify and remediate gaps in your controls before your SOC* report. DISCOVER: What Kind of SOC Report Do You Need? Experienced Assessment Team What - [SOC* Compliance Reporting Process | SOC 1®, SOC 2®, & More](https://auditwerx.com/socprocess/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC* Reporting Process Our assessment professionals have conducted 2,500+ SOC* evaluations throughout the U.S. & Canada. We can help your organization complete your assessment on time and on budget. DISCOVER: What Kind of SOC Report Do You Need? Trusted - [SOC* Reporting & Compliance Services | SOC 1®, SOC 2®, & More](https://auditwerx.com/criauditwerx/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> SOC* Suite of Services SOC* reporting doesn’t have to be a hassle when you have a trusted security compliance partner to guide you through the process. Auditwerx is here to help. DISCOVER: What Kind of SOC Report Do You - [Contact Auditwerx Compliance Professionals Today](https://auditwerx.com/contact-us/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> Contact Us Fill out the simple form below to speak to a specialist about your compliance needs. Auditwerx, LLC, a Division of Carr, Riggs & Ingram Capital, LLC 4010 Boy Scout Boulevard, Suite 475Tampa, Florida 33607 (866) 446-4038 info@auditwerx.com - [Auditwerx Compliance Reporting | Client Resources](https://auditwerx.com/client-resources/) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> Client Resources Auditwerx submits to multiple internal and third-party quality control processes. Client Payment Portal Pay your bill, set up recurring payments, connect multiple client numbers to one payment portal account, view your payment history, and more with Auditwerx’s - [Auditwerx Compliance Reporting Services](https://auditwerx.com/our-services/) - Auditwerx is a candidate C3PAO ready to help with CMMC readiness. Learn more >> Our Services Auditwerx offers full-service security compliance & advisory solutions to help you painlessly meet your compliance goals and grow your business. Certified Public Accountant (CPA) PCI Qualified Security Assessor (QSA) Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) - [Privacy Policy](https://auditwerx.com/privacy-policy/) - Privacy Policy Privacy Policy This Privacy Policy was last updated on April 11, 2024. This site (together with any successor site(s), computer systems, cloud-based storage accounts, and associated social media websites, hereinafter collectively referred to as the “Website”) is operated by Auditwerx (“we,” “us,” or “Auditwerx”). This Privacy Policy describes our practices in connection with - [Healthcare Compliance Reporting Services | HIPAA | HITRUST](https://auditwerx.com/healthcare-compliance/) - Auditwerx is a candidate C3PAO ready to help with CMMC readiness. Learn more >> Healthcare Compliance Auditwerx is a trusted partner for healthcare compliance reporting such as HIPAA and HITRUST. Show Your Commitment to Healthcare Compliance. Demonstrate a strong security position and build trust with your customers by showing your commitment to compliance in the - [Security Compliance Assessment Services](https://auditwerx.com/security-assessment/) - Get the “buzz” on CMMC Readiness. Start preparing for 2025 requirements. >> Security Compliance Auditwerx can help your organization simplify security compliance. Our experienced team offers the industry expertise you need. Security Compliance Solutions Show Your Committment to Security Compliance. Demonstrate a strong security position and build trust with current and future customers by showing - [Auditwerx Client Testimonials & Success Stories](https://auditwerx.com/testimonials/) - Get the “buzz” on CMMC Readiness. Start preparing for 2025 requirements. >> Testimonials We make it our priority to make your organizations engagement as seamless as possible. Don’t just take it from us, explore reviews from real Auditwerx clients! Recommended by our hosting partner, Auditwerx helped us securing a SOC 2®* Type 1 and Type - [Subscribe to the Auditwerx Checkpoint Newsletter](https://auditwerx.com/auditwerx-newsletter-sign-up/) - Newsletter Sign Up Stay up-to-date with the latest news and information from Auditwerx. Auditwerx, LLC, a Division of Carr, Riggs & Ingram Capital, LLC 4010 Boy Scout Boulevard, Suite 475Tampa, Florida 33607 (866) 446-4038 info@auditwerx.com Join our newsletter. Form issues? Contact us directly at sales@auditwerx.com. This site is protected by reCAPTCHA and the Google Privacy - [Thank You](https://auditwerx.com/thank-you/) - Thank you! We’re looking forward to meeting with you! Please use the calendar below to schedule your free consultation. Can’t see the calendar? Contact us directly at sales@auditwerx.com for your free consultation. - [Thank You - PCI Guide](https://auditwerx.com/thank-you-pci-guide/) - Thank you! Your free download will be sent to your email. Recommended Resources - [Thank You Careers](https://auditwerx.com/thank-you-careers/) - Thank you! Your application has been submitted. Recommended Resources - [Page List](https://auditwerx.com/page-list/) ## Landing Pages - [Sept25 Auditwerx Brand New Form](https://auditwerx.com/sept25-auditwerx-brand-new-form/) - Seamless Compliance Reporting Build trust with a high-quality security compliance assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient security compliance and attestation services tailored to your unique needs. - [Thank You for Contacting Auditwerx](https://auditwerx.com/thank-you-for-contacting-auditwerx/) - Thank you! We’re looking forward to meeting with you! Please use the calendar below to schedule your free consultation. Can’t see the calendar? Contact us directly at sales@auditwerx.com for your free consultation. - [SOC 1® Sept25 New Form](https://auditwerx.com/soc-1-sept25-new-form/) - Your Path to Seamless SOC 1® Reporting Build trust with a high-quality SOC 1® assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient SOC 1® services tailored to your - [SOC 2® Sept25 New Form](https://auditwerx.com/soc-2-sept25-new-form/) - Your Path to Seamless SOC 2® Reporting Build trust with a high-quality SOC 2® assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient SOC 2® services tailored to your - [PCI DSS Sept25 New Form](https://auditwerx.com/pci-dss-sept25-new-form/) - Your Path to Seamless PCI DSS Reporting Build trust with a high-quality PCI DSS assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient PCI DSS services tailored to your - [CMMC Sept25 New Form](https://auditwerx.com/cmmc-sept25-new-form/) - Your Path to Seamless CMMC Reporting Build trust with a high-quality CMMC assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient CMMC services tailored to your unique needs. Form - [CMMC Sept25](https://auditwerx.com/cmmc-sept25/) - Your Path to Seamless CMMC Reporting Build trust with a high-quality CMMC assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient CMMC services tailored to your unique needs. By - [PCI DSS Sept25](https://auditwerx.com/pci-dss-sept25/) - Your Path to Seamless PCI DSS Reporting Build trust with a high-quality PCI DSS assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient PCI DSS services tailored to your - [SOC 2® Sept25](https://auditwerx.com/soc-2-sept25/) - Your Path to Seamless SOC 2® Reporting Build trust with a high-quality SOC 2® assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient SOC 2® services tailored to your - [SOC 1® Sept25](https://auditwerx.com/soc-1-sept25/) - Your Path to Seamless SOC 1® Reporting Build trust with a high-quality SOC 1® assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient SOC 1® services tailored to your - [Sept25 Auditwerx Brand](https://auditwerx.com/sept25-brand/) - Your Path to Seamless Compliance Reporting Build trust with a high-quality security compliance assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient security compliance and attestation services tailored to - [PCI Landing Page Aug25](https://auditwerx.com/pci-dss-landing-page-aug25/) - Buzz into PCI DSS. PCI Compliance doesn’t have to be a hassle. Auditwerx is a PCI Qualified Security Assessor Company (QSAC) and has offered simple PCI DSS compliance solutions for businesses of all sizes since 2009. Experienced Team Trusted Reporting Partner High-Quality Reporting $$$ Friendly Solutions Book Your Consultation Free PCI DSS Download By proceeding, - [SOC 1 Landing Page Jan25](https://auditwerx.com/soc-1-landing-page-jan25/) - Buzz into SOC 1®. SOC 1® doesn’t have to be a hassle. A SOC 1® report offers an independent third-party opinion of the internal controls that may affect a user entity’s financial reporting. Our simple SOC 1® process makes it easy for any size organization to build trust with their clients. Experienced Team Trusted Reporting - [CMMC Event Follow Up](https://auditwerx.com/cmmc-event-follow-up/) - 8 Steps to CMMC Compliance Start preparing for your CMMC compliance initiatives today. Submit this form to receive our free guide, “8 Steps to CMMC Compliance.” By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy. Trusted Security Compliance Solutions Contact Us 4010 Boy Scout Boulevard, Suite 475 Tampa, Florida - [Simplify Security Compliance](https://auditwerx.com/simplify-security-compliance/) - Simplify Security Compliance. Auditwerx is part of Carr, Riggs & Ingram Capital, LLC (CRI), a nationally recognized top 25 accounting and advisory firm. Our experienced team is committed to providing you with high-quality security reporting that goes above and beyond your expectations. Book a Consultation Free SOC Download By proceeding, you are agreeing to the - [Auditwerx CMMC Event Page](https://auditwerx.com/auditwerx-cmmc-event-page/) - Join the Waitlist for CMMC Level 2. By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy. Upcoming Events SaaStr Sept. 10-12 | SF Bay Area Auditwerx is a proud sponsor of SaaStr 2024! Join a community of B2B software decision makers in San Francisco! Visit our team at booth #G118 to - [Thank You PCI DSS Download](https://auditwerx.com/thank-you-pci-dss-download/) - Thank you! Your free download will be sent to your email. Recommended Resources - [Thank You Adding It Up Download](https://auditwerx.com/thank-you-adding-it-up-download/) - Thank you! Your free download will be sent to your email. Recommended Resources - [Thank You CMMC Download](https://auditwerx.com/thank-you-cmmc-download/) - Thank you! Your free download will be sent to your email. Recommended Resources - [About Auditwerx](https://auditwerx.com/lp-about-auditwerx/) - Buzz into Compliance. Simplify your security evaluation with our trusted team of skilled assessors. Auditwerx offers cost effective solutions for SOC*, PCI DSS, CMMC readiness, and more. Experienced Team Trusted Reporting Partner High-Quality Reporting $$$ Friendly Solutions Book Your Consultation Free SOC Download By proceeding, you are agreeing to the terms and conditions in the - [Auditwerx Event Discount](https://auditwerx.com/auditwerx-event-discount/) - Get the “Buzz” on Compliance Book a consultation for an exclusive discount from today’s event! By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy. Upcoming Events SaaStr Sept. 10-12 | SF Bay Area Auditwerx is a proud sponsor of SaaStr 2024! Join a community of B2B software decision makers - [CMMC Readiness Landing Page 2024](https://auditwerx.com/cmmc-readiness-landing-page-2024/) - Buzz into CMMC. CMMC compliance doesn’t have to be a hassle. Auditwerx is your source for CMMC compliance solutions. Don’t delay your necessary compliance initiatives. We can help you get started. Experienced Team Trusted Reporting Partner High-Quality Reporting $$$ Friendly Solutions Book Your Consultation 8 Steps to CMMC Compliance By proceeding, you are agreeing to the - [Auditwerx Premeeting Questionnaire](https://auditwerx.com/auditwerx-premeeting-questionnaire/) - Help us prepare properly for your meeting. By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy. Trusted Security Compliance Solutions Contact Us 4010 Boy Scout Boulevard, Suite 475 Tampa, Florida 33607 Office: 866.446.4038 SOC Services SOC Readiness Services SOC Process SOC 1® (SSAE 18) SOC 2® SOC 2®+ SOC - [SOC 2 Landing Page Jan25](https://auditwerx.com/soc-2-landing-page-jan25/) - Buzz into SOC 2®. SOC 2® doesn’t have to be a hassle. A SOC 2® report offers comfort over the internal controls at service organizations like yours. Our simple SOC 2® process makes it easy for any size organization to build trust with their clients. Experienced Team Trusted Reporting Partner High-Quality Reporting $$$ Friendly Solutions - [Auditwerx Upcoming Events](https://auditwerx.com/upcoming-events/) - CEIC East Conference Nov. 21-22 | Gaylord National Resort and Convention Center, MD Auditwerx is a proud sponsor of CEIC East Conference! Join us at Booth #37 and discover how Auditwerx can support your CMMC compliance initiatives. Register Today By proceeding, you are agreeing to the terms and conditions in the Auditwerx Privacy Policy. Can’t - [SaaStr](https://auditwerx.com/saastr/) - SaaS Companies Choose Auditwerx for Security Compliance Reporting. Auditwerx has served clients throughout the U.S. and Canada since 2005. As a division of Carr, Riggs & Ingram Capital, LLC (CRI), a top 25 nationally ranked accounting and advisory firm, our clients receive the resources, skills and experience of a much larger firm, but with the accessibility ## My Templates - [Contact Pop Up Landing Pages](https://auditwerx.com/?elementor_library=contact-pop-up-landing-pages) - Trusted Partner. Simple Solutions. Contact the experienced team at Auditwerx to learn about our comprehensive security compliance solutions. Form issues? Contact us directly at sales@auditwerx.com. - [Let's Talk Compliance Pop Up](https://auditwerx.com/?elementor_library=lets-talk-compliance-pop-up) - LEt’s Talk Compliance Tell us a little about what you need, and our team will schedule a no-pressure conversation. No obligations, just answers you need. Form issues? Contact us directly at sales@auditwerx.com. - [Landing Page Template Nov. 2025](https://auditwerx.com/?elementor_library=landing-page-template-nov-2025) - Seamless Compliance Reporting Build trust with a high-quality security compliance assessment. Auditwerx, a division of Carr, Riggs & Ingram, LLC (CRI), combines the resources of a top 25 accounting firm with the specialized focus of a boutique compliance provider. We deliver high-quality, transparent, and efficient security compliance and attestation services tailored to your unique needs. - [Blog Archive](https://auditwerx.com/?elementor_library=blog-archive) - Auditwerx Blog In-depth analysis & guidance on SOC 2®, CMMC, PCI DSS, GRC tools and more. Recent Posts - [Single Post Template](https://auditwerx.com/?elementor_library=single-post-template) - [Event Bar Global](https://auditwerx.com/?elementor_library=event-bar-global) - CMMC Phase 1 Starts Nov. 10. Auditwerx is ready to help you with CMMC readiness. >> - [Main Footer](https://auditwerx.com/?elementor_library=main-footer) - Trusted Security Compliance Solutions Contact Us 4010 Boy Scout Boulevard, Suite 475 Tampa, Florida 33607 Office: 866.446.4038 SOC* Suite of Services SOC* Compliance Reporting Process SOC* Readiness Services SOC 1® (SSAE 18) Reporting SOC 2® Reporting SOC 2®+ Reporting SOC 3® Reporting SOC* for Cybersecurity Reporting CSAE 3416 Reporting ISAE 3402 Reporting PCI DSS Compliance - [Cookie Banner](https://auditwerx.com/?elementor_library=cookie-banner) - We use cookies to ensure the best experience. By accessing our site, you agree to our cookie policy. OK Cookie POlicy - [404 Page](https://auditwerx.com/?elementor_library=404-page) - 404 NOT FOUND Uh Oh! It looks like the page you are looking for does not exist. Return to Homepage - [Default Kit](https://auditwerx.com/?elementor_library=default-kit) - [Home Page Header](https://auditwerx.com/?elementor_library=home-page-header) - [Main Header](https://auditwerx.com/?elementor_library=main-header) - [Elementor Loop Item #21090](https://auditwerx.com/?elementor_library=elementor-loop-item) - [CTA Row - Button](https://auditwerx.com/?elementor_library=cta-row-button) - Learn More - [CTA Row - Icon](https://auditwerx.com/?elementor_library=cta-row-icon) - [CTA Row - Text](https://auditwerx.com/?elementor_library=cta-row-text) - Stress-free compliance audits. - [PPC Footer](https://auditwerx.com/?elementor_library=ppc-footer) - 3000 Bayport Drive Suite 500Tampa, FL 33607Office: 866.446.4038 SOC Services SOC Readiness Services SOC 1® (SSAE 18) SOC 2® SOC 2®+ SOC 3® SOC Process Canadian Examinations International Examinations PCI Services Cybersecurity Internal Control & Data Security Audits Other Services HIPAA Assessment HITRUST Assessment Agreed Upon Procedures Privacy & Compliance About Us Testimonials Careers Blog - [PPC Landing Page](https://auditwerx.com/?elementor_library=ppc-landing-page) - 866-446-4038 Build Trust and Confidence with a SOC 1 Report. Win new business and give existing customers confidence with a SOC 1® report. Our SOC 1® Partners have a minimum of 15 years of professional audit experience in both financial reporting and internal control auditing. Our dedicated team will utilize the highest level of business - [CTA Row](https://auditwerx.com/?elementor_library=cta-row) - Get started today Contact Us - [Page Header - Dark Blue - Check Highlight](https://auditwerx.com/?elementor_library=page-header-dark-blue-check-highlight) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Dark Blue - Check Pattern](https://auditwerx.com/?elementor_library=page-header-dark-blue-check-pattern) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Dark Blue - Poly](https://auditwerx.com/?elementor_library=page-header-dark-blue-poly) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Light Blue - Check Pattern](https://auditwerx.com/?elementor_library=page-header-light-blue-check-pattern) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Light Blue - Logo Pattern](https://auditwerx.com/?elementor_library=page-header-light-blue-logo-pattern) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Light Blue - Poly](https://auditwerx.com/?elementor_library=page-header-light-blue-poly) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Gold - Logo Pattern](https://auditwerx.com/?elementor_library=page-header-gold-logo-pattern) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Gold - Poly](https://auditwerx.com/?elementor_library=page-header-gold-poly) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment - [Page Header - Gold - Check Highlight](https://auditwerx.com/?elementor_library=page-header-gold-check-highlight) - Services SOC Readiness Services Prepare for a SOC Engagement with a Readiness Assessment ## Categories - [SOC 2®](https://auditwerx.com/category/soc-reporting/soc2/) - [SOC 1®](https://auditwerx.com/category/soc-reporting/soc1/) - [SOC Reporting](https://auditwerx.com/category/soc-reporting/) - [PCI DSS](https://auditwerx.com/category/pci-dss/) - [SOC Readiness](https://auditwerx.com/category/soc-reporting/soc-readiness/) - [HIPAA](https://auditwerx.com/category/hipaa/) - [News & Updates](https://auditwerx.com/category/news-updates/) - [CMMC](https://auditwerx.com/category/cmmc/)