Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

SOC 2 Certification in Malaysia | Compliance & Audit

SOC 2 certification in Malaysia covering compliance, audit reports, Type I, Type II, requirements, industries and the SOC 2 audit process.

  1. Home
  2. Knowledge Centre
  3. SOC 2 Certification in Malaysia | Compliance & Audit

SOC 2 Certification in Malaysia – Compliance & Audit Guide

SOC 2 Certification in Malaysia – Compliance & Audit Guide
A practical guide to SOC 2 certification in Malaysia, covering SOC 2 compliance, audit reports, Type I and Type II, key industries, requirements and major Malaysian locations.

SOC 2 Certification in Malaysia – Start Your Enquiry

If your company provides SaaS applications, cloud services, fintech platforms, IT solutions, managed services or other technology products that handle customer information, your customers may ask for independent evidence that their data and supporting systems are properly protected.

For many Malaysian businesses, SOC 2 certification in Malaysia becomes relevant when entering enterprise contracts, responding to vendor security assessments or expanding into international markets. A SOC 2 report gives customers a clearer view of the controls used to protect information and operate the services they depend on.

Although SOC 2 certification is the term commonly used in business searches and procurement discussions, SOC 2 is technically an examination and reporting framework, rather than an ISO-style certification scheme. The outcome is a SOC 2 examination report covering the organization's system and the applicable Trust Services Criteria.

SCS Certification (Partners) – Malaysia Office
Jalan Pinang
50450 Kuala Lumpur, Malaysia
Phone: +6011 6263 6611
Enquiry: Contact SCS Certification

For businesses in Kuala Lumpur, Selangor, Cyberjaya, Penang, Johor Bahru and other Malaysian technology and commercial centres, SOC 2 may form part of customer due diligence, supplier assessment or contractual requirements.

What Is SOC 2 Certification in Malaysia?

SOC 2 focuses on controls relevant to the security, availability, processing integrity, confidentiality and privacy of information and systems.

For Malaysian technology companies, a SOC 2 report can help address customer questions about information protection, access control, incident management, system monitoring and other important controls.

The scope depends on the organization's services, systems and customer requirements.

SOC 2 Compliance in Malaysia

SOC 2 compliance in Malaysia involves establishing, documenting and operating controls relevant to the selected Trust Services Criteria.

Depending on the organization, controls may cover:

  • User access management
  • Privileged access
  • Security monitoring
  • Incident response
  • Change management
  • Risk management
  • Vendor management
  • Backup and recovery
  • Data protection
  • Business continuity
  • Confidentiality and privacy

The controls should reflect the organization's actual operations rather than being created simply to satisfy a checklist.

Industries That May Require SOC 2 Certification in Malaysia

SOC 2 is not automatically mandatory for every Malaysian company or industry. However, customers, contracts and procurement teams may require a SOC 2 report before approving a technology supplier.

SOC 2 Certification for Fintech Companies in Malaysia

Fintech organizations may handle financial information, customer data and transaction-related systems.

Banks, payment partners, enterprise customers and international clients may therefore request SOC 2 certification in Malaysia as part of their supplier or third-party assessment.

SOC 2 Certification for Banks in Malaysia

Banks may request SOC 2 reports from technology suppliers as part of vendor due diligence.

This may include:

  • Cloud service providers
  • SaaS companies
  • Payment technology providers
  • IT service providers
  • Cybersecurity companies
  • Data-processing providers
  • Fintech platforms

SOC 2 Certification for SaaS Companies in Malaysia

Enterprise customers may ask SaaS providers for independent assurance covering application security, access management, monitoring, change control and customer information.

For Malaysian SaaS companies targeting international markets, SOC 2 certification in Malaysia can therefore support enterprise sales and customer due diligence.

SOC 2 Certification for IT Companies in Malaysia

IT outsourcing companies, managed service providers, software developers and cybersecurity providers may encounter SOC 2 requirements when accessing customer systems or information.

SOC 2 Certification for Cloud Service Providers in Malaysia

Cloud and infrastructure providers may be asked to demonstrate how security, availability, access and operational controls are managed.

SOC 2 Certification in Kuala Lumpur

SOC 2 certification in Kuala Lumpur is relevant to SaaS, fintech, IT, cloud, software and technology businesses operating across areas such as:

  • Kuala Lumpur City Centre
  • KL Sentral
  • Bangsar
  • Bangsar South
  • Mont Kiara
  • Bukit Bintang
  • Mid Valley City
  • Greater Kuala Lumpur

SOC 2 Certification in Selangor

Businesses searching for SOC 2 certification in Selangor may operate in Petaling Jaya, Shah Alam, Subang Jaya, Klang, Sepang, Cyberjaya and surrounding commercial and technology areas.

SOC 2 Certification in Cyberjaya

SOC 2 certification in Cyberjaya can be relevant to software companies, cloud providers, cybersecurity businesses, digital platforms, IT outsourcing companies and data-service providers.

SOC 2 Certification in Penang

Businesses searching for SOC 2 certification in Penang may include organizations in:

  • George Town
  • Bayan Lepas
  • Bayan Baru
  • Butterworth
  • Seberang Perai

SOC 2 Certification in Johor

SOC 2 certification in Johor can support technology and service companies operating in:

  • Johor Bahru
  • Iskandar Puteri
  • Pasir Gudang
  • Senai
  • Tanjung Pelepas

SOC 2 Certification in Other Malaysian Locations

SCS Certification can also support enquiries relating to SOC 2 certification in Melaka, Ipoh, Perak, Kuching, Kota Kinabalu, Sabah, Sarawak and Putrajaya, as well as other Malaysian commercial and technology locations.

The location does not determine the SOC 2 scope. The services, systems, controls and customer requirements determine what is assessed.

SOC 2 Type I and Type II Certification

SOC 2 Type I

A SOC 2 Type I report examines the design and implementation of relevant controls at a specific point in time.

SOC 2 Type II

A SOC 2 Type II report examines whether relevant controls operated effectively over a defined period.

Companies searching for SOC 2 Type II certification in Malaysia should therefore allow sufficient time for the required operating period and evidence collection.

SOC 2 Trust Services Criteria

SOC 2 can cover five Trust Services Criteria:

  • Security – protection against unauthorized access and use.
  • Availability – availability of systems as agreed.
  • Processing Integrity – complete, valid, accurate and timely processing.
  • Confidentiality – protection of confidential information.
  • Privacy – appropriate handling of personal information.

The criteria selected depend on the organization's services and customer requirements.

SOC 1 vs SOC 2 vs SOC 3 Certification

Businesses often compare SOC 1 certification, SOC 2 certification and SOC 3 certification. They serve different purposes.

Report Main Focus Typical Purpose
SOC 1 Controls relevant to financial reporting Financial reporting-related assurance
SOC 2 Security and selected Trust Services Criteria Technology and customer assurance
SOC 3 Similar Trust Services Criteria General-use assurance

SOC 1 Certification

SOC 1 focuses on controls relevant to customers' internal control over financial reporting.

SOC 2 Certification

SOC 2 focuses on controls relevant to security, availability, processing integrity, confidentiality and privacy.

SOC 3 Certification

SOC 3 provides general-use reporting based on similar Trust Services Criteria and contains less detailed information than a SOC 2 report.

Although businesses commonly search for SOC 1, SOC 2 and SOC 3 certification, these are technically SOC reporting engagements rather than ISO-style certifications.

SOC 2 Audit Report in Malaysia

A SOC 2 audit report in Malaysia provides information about the organization's system, applicable criteria, controls examined, testing performed and results.

Customers may request the report during:

  • Vendor approval
  • Security assessments
  • Enterprise procurement
  • Third-party risk reviews
  • Contract negotiations
  • Customer due diligence

SOC 2 Audit Process in Malaysia

The process generally involves:

1. Define the Service

Identify the product or service covered by the engagement.

2. Determine the Scope

Identify relevant applications, infrastructure, people, systems and processes.

3. Select the Criteria

Determine which Trust Services Criteria apply.

4. Review Existing Controls

Assess the organization's current control environment.

5. Address Gaps

Correct weaknesses identified during the review.

6. Collect Evidence

Maintain appropriate records demonstrating that controls are operating.

7. Examination

The applicable controls are examined and tested.

8. SOC 2 Report

The completed SOC 2 report presents the examination results to its intended users.

SOC 2 Certification vs ISO 27001

ISO/IEC 27001 certification and SOC 2 are different forms of assurance.

ISO 27001 establishes requirements for an information security management system and can result in certification.

SOC 2 examines controls against applicable Trust Services Criteria and results in a SOC report.

Some Malaysian companies maintain both because customers may request different forms of assurance.

SOC 2 Certification Cost in Malaysia

There is no single SOC 2 certification cost in Malaysia.

Pricing depends on:

  • Organization size
  • Scope
  • Number of systems
  • Selected criteria
  • Type I or Type II
  • Existing controls
  • Locations
  • Evidence requirements
  • Examination period

A proper scope review is therefore needed before providing a meaningful quotation.

Is SOC 2 Certification Mandatory in Malaysia?

SOC 2 certification is not universally mandatory in Malaysia.

However, a customer, bank, multinational company or contractual partner may require a SOC 2 report before approving a technology supplier.

This means SOC 2 can be a commercial or contractual requirement even where there is no general legal requirement.

How to Get SOC 2 Certification in Malaysia

A company should begin by identifying:

  1. The service to be assessed.
  2. The systems supporting the service.
  3. The applicable Trust Services Criteria.
  4. Whether Type I or Type II is required.
  5. Existing controls.
  6. Areas requiring improvement.
  7. Evidence that needs to be maintained.
  8. The intended report users.

This approach helps keep the SOC 2 scope practical and relevant.

Why Choose SCS Certification?

SCS Certification supports organizations seeking structured certification, compliance and assurance solutions.

For a SOC 2 certification in Malaysia enquiry, the discussion can cover:

  • SOC 2 requirements
  • Scope definition
  • SOC 2 readiness
  • Trust Services Criteria
  • Type I and Type II
  • Control review
  • Evidence requirements
  • Customer requirements
  • Information-security controls

The objective is to develop a practical approach based on the organization's actual services and customer expectations.

Frequently Asked Questions

What is SOC 2 certification in Malaysia?

SOC 2 certification is the commonly used business term for obtaining a SOC 2 examination report. Technically, SOC 2 is an examination and reporting framework.

Is SOC 2 certification mandatory in Malaysia?

No. It is not universally mandatory, although customers and contracts may require a SOC 2 report.

How do I get SOC 2 certification in Malaysia?

Define the service and scope, select the applicable criteria, review controls, address gaps, collect evidence and complete the SOC 2 examination.

What is SOC 2 compliance in Malaysia?

SOC 2 compliance refers to operating controls relevant to the applicable Trust Services Criteria within the agreed scope.

What is a SOC 2 audit report?

It is a report describing the applicable system, controls, examination procedures and results.

What is SOC 2 Type II certification in Malaysia?

It refers to the process associated with obtaining a SOC 2 Type II report, which examines the operating effectiveness of controls over a defined period.

Do fintech companies need SOC 2 certification in Malaysia?

Not universally, but banks, enterprise customers and business partners may require it as part of supplier assurance.

Do SaaS companies need SOC 2 certification in Malaysia?

A SaaS company may need SOC 2 when enterprise or international customers make it a contractual or procurement requirement.

What is the difference between SOC 1, SOC 2 and SOC 3?

SOC 1 primarily addresses controls relevant to financial reporting. SOC 2 addresses security and selected Trust Services Criteria. SOC 3 provides general-use reporting based on similar criteria.

What does SOC 2 certification cost in Malaysia?

There is no fixed cost. Scope, systems, criteria, organization size and Type I or Type II requirements affect the cost.

Contact SCS Certification

SCS Certification – Malaysia

SCS Certification (Partners) – Malaysia Office
Jalan Pinang
50450 Kuala Lumpur, Malaysia
Phone: +6011 6263 6611
Enquiry: Contact SCS Certification

SCS Certification – UAE

SCS services are available across Dubai, Abu Dhabi, Sharjah, Ajman, Ras Al Khaimah, Fujairah and Umm Al Quwain, including commercial areas, free zones and industrial locations.

SCS Certification – UK

SCS CERTIFICATION EUROPE LIMITED

SCS Certification – Canada

SCS Certification (E) Limited
Oaklea Blvd
Brampton, ON
L6Y 5A2, Canada
Phone: +1 437 410 8055

SCS Certification – India

SCS Certification services are available across India.

Authoritative SOC 2 Resources

SEO Fields

SEO Title:
SOC 2 Certification in Malaysia | Compliance & Audit

Meta Description:
SOC 2 certification in Malaysia covering compliance, audit reports, Type I, Type II, requirements, industries and the SOC 2 audit process.

Focus Keyword:
SOC 2 certification in Malaysia

Open Graph Title:

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

SOC 2 cost in Malaysia depends on the service scope, systems involved, Trust Services Criteria, organization size, existing controls and whether Type I or Type II is required. A scope-based quotation is more useful than a generic price.
There is no single starting price that applies to every Malaysian organization. The scope and examination requirements should be reviewed first so the quotation reflects the actual work involved.
Provide your service description, systems in scope, approximate company size, customer requirement, preferred Type I or Type II report and target date. This information allows the engagement to be assessed more accurately.
An indicative discussion is possible, but a meaningful quotation normally requires basic scope information. Systems, criteria, report type and readiness can significantly affect the overall effort.
Start by confirming exactly what your customer requires, define a focused scope, identify control gaps and organize evidence immediately. For Type II, the required operating period still needs to be respected.
A 30-day preparation target may be possible for some organizations, but it should not be treated as a universal timeframe for completing a full SOC 2 engagement. Type II requires controls to operate over a defined period.
Type I can generally be approached faster than Type II because it evaluates control design and implementation at a specific point in time. Actual timing still depends on scope and organizational readiness.
Preparation can be accelerated through early scope definition, gap identification and evidence planning. However, the required Type II operating period cannot simply be eliminated by accelerating documentation.
Much of the preparation, meetings, documentation review and evidence exchange can be handled remotely. The exact arrangement depends on the engagement and examination requirements.
Yes. Startups providing SaaS, cloud, fintech, cybersecurity or other technology services can pursue SOC 2 when their customers require independent assurance.
It can be particularly relevant when overseas enterprise customers request evidence of security and operational controls before signing or expanding a contract.
A SOC 2 report can support enterprise due diligence by providing independent information about controls within the examined system. Customers may still request additional evidence.
Not automatically. A US customer may request SOC 2 as part of its vendor security or procurement process, particularly for SaaS and cloud services.
There is no universal requirement. International customers may nevertheless make SOC 2 a contractual, procurement or vendor-assurance requirement.
It can support customer assurance discussions where prospective US customers request independent controls reporting. It should be viewed as part of a broader enterprise-readiness strategy rather than a general market-entry license.
It may help with technology customer and vendor due diligence when Singapore-based customers request independent assurance. Acceptance depends on the individual customer's requirements.
Yes, where multinational customers use SOC 2 as part of their third-party risk or procurement process. The usefulness depends on whether the report scope matches the service being purchased.
No, SOC 2 is not universally mandatory for all SaaS companies. A customer, contract or procurement process may nevertheless require a SOC 2 report.
It is not automatically mandatory for every Malaysian fintech company. Banks, partners, enterprise customers or international clients may request it as part of their supplier assessment.
No general SOC 2 requirement applies to every IT company. The need often arises from customer contracts, vendor assessments or enterprise procurement.
Not universally. Cloud customers may require SOC 2 as evidence of controls relating to security, availability and operations.
Not for every cybersecurity company. It can become commercially important when enterprise customers require independent assurance over the provider's systems and controls.
An MSP may be asked for SOC 2 when customers depend on it for infrastructure, security, systems administration or other managed services. The requirement depends on the customer's risk and procurement process.
Not every software company needs SOC 2. It is more commonly relevant where the company operates a continuing service or platform and customers require independent assurance.
A data-processing provider may encounter SOC 2 requirements when customers need assurance concerning controls over systems and information used to provide the service.
There is no universal SOC 2 requirement for every payment technology company. Banks, payment partners and enterprise customers may request it during supplier due diligence.
A bank may request a SOC 2 report from technology suppliers as part of its vendor or third-party risk assessment. The exact requirement depends on the bank and service relationship.
A SOC 2 report can provide structured independent assurance about controls within its scope and may help answer parts of a customer's security review.
It may reduce some repetitive assurance work because customers can review an existing independent report. However, individual customers may still request questionnaires or supplemental evidence.
Potentially, if the customers' requirements align with the report's scope, criteria, reporting period and intended use. Each customer may still apply its own vendor-risk requirements.
Yes, a report may support international customer discussions when the covered service and controls meet their requirements. Customer acceptance should always be confirmed directly.
It may be considered where a government procurement process or contract requests SOC reporting or equivalent assurance. The applicable tender or procurement requirements should be checked rather than assuming automatic acceptance.
It can provide evidence of an organization's control environment where the tender recognizes or requests such assurance. It does not automatically replace specific tender, regulatory or cybersecurity requirements.
Requirements can include the report type, system scope, Trust Services Criteria, reporting period and information about relevant controls. Enterprise customers may also request supporting security documentation.
Prepare your service description, system architecture, applications, infrastructure, employee roles, customer requirements, existing policies, security controls and any previous assurance reports.
Evidence can include access reviews, employee training, security monitoring, incident records, change records, vulnerability management, vendor assessments, backup testing and other operational records relevant to the scope.
The appropriate evidence period depends on the examination type and defined reporting period. For Type II, evidence needs to demonstrate the operation of controls during the period being examined.
Evidence can be maintained in different formats depending on the control and organization. The important consideration is whether the evidence reliably demonstrates that the relevant control operated as described.
Appropriate policies and procedures are normally part of establishing the control environment. They should reflect actual operations rather than being created only as paperwork for the examination.
Existing ISO 27001 documentation may provide a useful foundation because many security controls overlap. It should still be mapped against the actual SOC 2 scope and applicable Trust Services Criteria.
Yes. Malaysian organizations may pursue both when customers or business objectives call for different forms of assurance. The two frameworks should be planned together where controls overlap.
Neither is universally better. The practical choice depends on what customers, contracts, procurement teams and business partners require.
SOC 2 and ISO 27001 are different assurance approaches. A SOC 2 report does not automatically provide ISO 27001 certification.
Not necessarily. A customer specifically requesting a SOC 2 report may still require that report even when the supplier already holds ISO 27001 certification.
Many security controls can overlap, including access management, incident response, risk management and change control. The controls still need to be evaluated against the specific requirements of each engagement.
Compliance refers to the organization's implementation and operation of relevant controls. The SOC 2 report is the formal reporting output of the examination performed over the defined scope.
Businesses commonly call it SOC 2 certification, but technically SOC 2 is an examination and reporting framework. The formal deliverable is a SOC 2 report.
AICPA establishes the relevant Trust Services Criteria and publishes SOC-related professional resources; it does not function as a certification body issuing an ISO-style certificate to every service organization.
SOC 2 engagements are performed under the applicable professional attestation framework by qualified practitioners. The organization selecting a provider should verify the proposed practitioner's qualifications and engagement arrangements.
Compare the proposed scope, report type, Trust Services Criteria, practitioner qualifications, independence, experience, deliverables, timeline and total fees. Avoid selecting solely on the lowest quotation.
Ask what will be examined, which criteria apply, whether the engagement is Type I or Type II, what evidence is required, how the timeline is structured and exactly what report will be delivered.
Price should be considered alongside scope, qualifications, examination approach, deliverables and customer acceptance requirements. An apparently low quotation may not cover the same scope as another proposal.
Preparation support and independent examination are distinct activities. The organization should understand who is providing consulting or readiness assistance and who is responsible for the independent examination report.
An identified exception is evaluated within the examination process and may affect the reporting outcome depending on its nature and significance. Organizations should address control weaknesses as early as possible.
Yes, preparation can begin with a readiness review and gap assessment. Controls that need improvement can then be prioritized before the formal examination.
A separate readiness assessment is not necessarily mandatory, but it can help identify weaknesses before the examination and reduce avoidable preparation problems.
That is not a barrier to starting. A first engagement normally begins by defining the service, system boundary, criteria and customer requirement, followed by control preparation and examination.
It can, provided the organization can support the required operating period with appropriate controls and evidence. The decision should be based on readiness and customer requirements.
Yes. A Type I report can provide an initial point-in-time assessment, while a subsequent Type II engagement evaluates operating effectiveness over a defined period.
The choice should be based primarily on what customers require. Type I may address an immediate point-in-time assurance need, while Type II provides evidence of operating effectiveness over a period.
The overall timeline depends on preparation, scope and the defined examination period. Type II requires sufficient time for controls to operate and for evidence to be collected and tested.
No practical Type II approach should rely only on retrospective paperwork. The examination is intended to evaluate whether relevant controls operated effectively during the defined period.
SOC 2 can address privacy and confidentiality controls where those criteria are included and relevant to the service. Malaysian organizations should separately consider applicable personal-data obligations.
No. SOC 2 provides assurance over defined controls and does not automatically replace Malaysian legal or regulatory obligations concerning personal data or other regulated information.
Privacy can be included as one of the Trust Services Criteria when appropriate to the service and examination scope. The selected criteria should reflect the organization's actual requirements.
Yes. Confidentiality is one of the Trust Services Criteria and can be included when relevant to the organization's service and customer expectations.
Yes. Availability can be included when system availability is relevant to the service and customer commitments.
Yes. Processing Integrity may be relevant where customers depend on accurate, complete, timely and authorized processing within the examined service.
No. The applicable criteria depend on the service, systems, risks and customer requirements. Security is commonly relevant, while the other criteria are included when appropriate.
The scope can include applications, infrastructure, people, processes and supporting technology used to provide the service. The boundary should be clearly defined before examination work begins.
Cloud infrastructure can form part of the service environment depending on how the organization uses it and how the system is defined. Third-party service arrangements should be considered when establishing the scope.
Yes. Hosting providers, cloud platforms, security providers and other third parties supporting the service can be relevant to the control environment and examination scope.
Access management is commonly relevant to SOC 2. Depending on scope, evidence may include onboarding, offboarding, privileged access, authentication and periodic access reviews.
Incident management can form part of the control environment, particularly where security incidents could affect the service or customer information.
Change management is commonly relevant for technology services because uncontrolled changes can affect system security, availability or processing. The exact controls depend on the defined scope.
Backup and recovery controls may be relevant, particularly when availability or operational resilience is within scope. The specific evidence depends on the service architecture and selected criteria.
The testing expected depends on the organization's risks, systems and examination scope. Penetration testing may provide useful security evidence, but requirements should not be assumed to be identical for every company.
Vulnerability management can be relevant to the security control environment. The appropriate testing and evidence should be determined based on the organization's systems and risks.
It can be shared with intended users in accordance with the report's terms and confidentiality arrangements. The company should ensure that the report's scope meets the customer's requested assurance.
Customers may review the report and request clarification or supporting information according to the report's terms. They may also conduct their own supplier assessment.
SOC 2 is associated with defined examination periods rather than a simple permanent certificate model. Organizations commonly plan subsequent reporting periods when customers require current assurance.
Maintain controls continuously, assign control owners, retain evidence, review access, monitor incidents, manage changes and address identified weaknesses throughout the year.
Begin with the customer's exact requirement, define the service boundary, confirm the report type and assess current controls. This prevents the organization from preparing evidence that does not match what the customer actually needs.
SCS Certification can discuss the organization's service, scope, customer requirements, controls, evidence needs and intended SOC 2 report type to determine an appropriate approach.
Yes. A quotation discussion can be based on the service, systems, organization size, applicable criteria, report type and target timeline.
A Kuala Lumpur organization can provide its service details, systems, customer requirements and desired Type I or Type II outcome for a scope discussion and quotation.
Companies in Selangor can begin with their service description, system scope, customer requirement and target deadline. The location itself does not determine the SOC 2 examination scope.
Cyberjaya technology companies can begin by identifying the platform or service to be examined and the controls supporting it, followed by scope and readiness discussions.
Penang companies can request a SOC 2 scope review based on their technology service, systems, customer requirements and preferred report type.
A Johor-based company can start by defining its service, systems and customer assurance requirement. SOC 2 scope is determined by the service environment rather than the company's physical location.
Yes. SOC 2 enquiries can be considered for Malaysian organizations in Kuala Lumpur, Selangor, Cyberjaya, Penang, Johor and other locations, subject to the engagement arrangement.
The AICPA & CIMA publishes the Trust Services Criteria used for SOC 2 engagements. Its official resource describes criteria covering Security, Availability, Processing Integrity, Confidentiality and Privacy.
A Malaysian organization can contact SCS Certification with its service description, system scope, customer requirement, desired report type and target timeline to discuss the appropriate SOC 2 engagement.