The RSI security website breaks down the actions in certain element, but the process in essence goes similar to this: The distinction between the different sorts of SOC audits lies during the scope and length from the assessment: It is relevant to all businesses that take or approach payment cards, https://www.nathanlabsadvisory.com/revolution/assets/company-brochure.pdf