Frequently Asked Questions
Got questions? We’ve got answers.
SOC 1 applies when your services affect a client's internal control over financial reporting — payroll, outsourced accounting, transaction processing, and similar. SOC 2 reports against the AICPA Trust Services Criteria and is the report technology and SaaS companies are most often asked for, as a Type I (control design) or Type II (operating effectiveness over a period). SOC 3 is a general-use summary you can share publicly without an NDA. We help you confirm scope and report type before any engagement begins.
Every engagement begins with a scoping conversation and an independence and conflict check. From there we agree the system boundary, applicable criteria or standard, and the engagement plan. For first-time examinations we usually recommend a readiness assessment first, so control gaps surface before formal fieldwork rather than during it.
Typically: a description of the in-scope system, your policies and procedures, evidence of the controls in operation, and access to the people who run them for walkthroughs. Where you already use a GRC or evidence-collection platform, we work from it rather than asking you to duplicate evidence.
Attestation work is performed under AICPA attestation standards by a CPA-led practice. ISO work is aligned to the relevant ISO/IEC management-system standards, and IT assurance work draws on recognized IT control frameworks. Engagements are scoped up front to preserve independence.
It depends on the report type, the size of the environment, and your readiness. A Type II examination, for example, also includes an observation period. We agree a realistic timeline at kickoff and flag anything that threatens it as fieldwork progresses, rather than at the end.
Pricing is scoped per engagement, based on the report or standard involved, the number of in-scope systems and locations, and the criteria being tested. Once scope is confirmed you receive a fixed proposal — discuss your requirement with us and we'll take you through it.

Explore common queries about working with BFAG CPA LLC. Still unsure?
Contact us — we’re happy to help.
Service-Specific FAQs
SOC 2
SOC 2 is a framework for evaluating controls related to security, availability, processing integrity, confidentiality, and privacy. It is particularly relevant for SaaS companies, technology providers, cloud service providers, and organisations that handle customer data.
Yes. We support organisations with SOC 2 readiness assessments, control design, documentation, implementation support, evidence preparation, and audit readiness for both Type I and Type II engagements.
Yes. Our support can include policies, procedures, control documentation, risk assessments, evidence requirements, control-owner guidance, remediation tracking, and audit-readiness support.
ISO/IEC 27001
ISO/IEC 27001 is an international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It helps organisations manage information-security risks systematically and demonstrate their commitment to information security.
Yes. We support the organisation through gap assessment, ISMS design, risk assessment, Statement of Applicability, policy and control implementation, awareness, internal audit, and management review preparation. Certification itself is performed by an independent accredited certification body.
Yes. We provide independent internal audit support, identify non-conformities and improvement opportunities, and help management prepare for the certification audit. The certification audit itself must be conducted by an independent certification body.
SOC 2 vs ISO/IEC 27001
Neither is universally better. The appropriate choice depends on customer expectations, target markets, contractual requirements, and business objectives. ISO 27001 provides a formal ISMS and certification model, while SOC 2 provides an independent attestation over defined controls and trust-services criteria.
Yes. Many organisations use a common information-security control environment to address both frameworks. A cross-framework assessment can identify overlapping controls and reduce duplicated implementation and evidence requirements.
Yes. We can develop a combined roadmap, map common controls, identify framework-specific requirements, and establish a consolidated governance and evidence-management approach.
GDPR
The General Data Protection Regulation (GDPR) is the European Union's data protection law. It can apply to organisations outside the EU when they offer goods or services to individuals in the EU or monitor their behaviour, depending on the circumstances.
A GDPR assessment can cover data mapping and inventories, lawful bases for processing, privacy notices, data subject rights, retention, consent management, processor and third-party arrangements, international data transfers, security controls, breach management, and privacy governance.
Yes. We provide ongoing support through a DPO / Data Privacy Officer or Data Privacy Professional retainership, including privacy governance, assessments, documentation, third-party reviews, awareness, and ongoing compliance support.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) establishes requirements for protecting certain health information in the United States. Organisations such as covered entities and business associates may have HIPAA obligations depending on their activities and relationships.
A HIPAA assessment can review administrative, physical, and technical safeguards, access controls, security policies, risk analysis, workforce security, incident response, business continuity, vendor management, documentation, and other applicable HIPAA Security, Privacy, and Breach Notification requirements.
Yes. We provide a prioritised remediation roadmap and implementation support covering policies, procedures, risk management, security controls, vendor requirements, awareness, and evidence preparation.
GDPR & HIPAA Combined
Yes. Where an organisation operates across the EU and US healthcare ecosystem, a combined assessment can identify overlapping privacy and security requirements while separately addressing requirements specific to GDPR or HIPAA.
Yes. We can perform a multi-framework mapping to identify common controls and reduce duplication across privacy, information security, risk, and compliance programmes.
Our services focus on assessment, compliance readiness, governance, risk management, documentation, and implementation support. We do not provide legal advice or represent that an engagement itself constitutes regulatory certification or approval.
NIST Cybersecurity Framework (CSF 2.0)
The NIST Cybersecurity Framework provides a structured approach for organisations to identify, assess, manage, and reduce cybersecurity risk. NIST CSF 2.0 is organised around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
NIST CSF can be used by organisations across industries and of different sizes — particularly those looking to strengthen cybersecurity governance, establish a risk-based security programme, improve cyber resilience, or align existing controls with a recognised framework.
Our assessment can include cybersecurity governance, risk management, asset management, access control, awareness and training, data security, vulnerability management, detection capabilities, incident response, recovery, and third-party cybersecurity risks.
Yes. We provide a prioritised gap and risk report along with a practical remediation roadmap. Where required, we can also provide ongoing implementation and monitoring support.
Yes. We can perform multi-framework mapping to identify common controls and requirements across NIST CSF, ISO/IEC 27001, SOC 2, CIS Controls, COBIT, and applicable regulatory requirements — reducing duplicated effort and establishing a consolidated cybersecurity and compliance programme.
No. NIST CSF is a cybersecurity risk-management framework, not a certification scheme. An assessment can demonstrate alignment with the framework and identify areas for improvement, but it should not be represented as “NIST certification.”
Yes. Depending on the organisation, the assessment can be mapped against applicable RBI, SEBI, IRDAI, or other regulatory and contractual requirements to provide management with a consolidated view of cybersecurity and compliance gaps.
Yes. Organisations can engage us on a retainership basis for cybersecurity risk management, control monitoring, remediation tracking, management reporting, periodic assessments, and IT GRC support.

