Skip to main content
KPMG Adaptability Pulse Survey

Learn how companies drive bold action at scale

Access the survey results
KPMG Adaptability Pulse Survey

Learn how companies drive bold action at scale

Access the survey results

Rethinking the PCI and SOC 2 delivery model

Should you use one firm for PCI and SOC 2 reports, or two? Explore the advantages, challenges, and considerations associated with each assurance approach.

This article, Rethinking the PCI and SOC 2 Delivery Model: Specialization vs. Integration in Cybersecurity Assurance, examines two common approaches to obtaining PCI and SOC 2 assurance. As organizations navigate increasing compliance, governance, and stakeholder expectations, they must determine whether an integrated provider or separate specialist firms best align with their objectives, risks, and operational needs. The article explores the perspectives, benefits, and potential limitations of each model to help organizations make informed decisions about their assurance strategy.

Choosing Your Assurance Model: Integration vs. Specialization

The key question is not simply whether one provider can perform both engagements, but how organizations balance efficiency, expertise, governance, and stakeholder expectations when designing their assurance programs.

  • The Integrated Model: A single provider performs both PCI and SOC 2 engagements, offering coordinated planning, streamlined communication, reduced duplication of effort, and potentially greater operational efficiency.

  • The Specialized Model: Separate firms perform PCI and SOC 2 engagements, allowing organizations to leverage distinct technical and assurance expertise, independent perspectives, and methodologies tailored to the objectives of each assessment.

  • The Decision Factors: Organizations should consider factors such as scope overlap, resource availability, governance objectives, stakeholder expectations, regulatory environment, and desired levels of independence when evaluating the most appropriate assurance model.

Dive into our thinking:

Download the full article to explore how to balance efficiency and trust in your cybersecurity assurance program.

Download PDF

Meet the team

Image of Nina Currigan
Nina Currigan
Partner, Tech Assurance Audit National SOC Solution Leader, KPMG US
Image of Adam Brand
Adam Brand
Principal, Advisory, Line of Business, Products, KPMG US

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline