In todays world, almost every type of public or private company needs to assess its internal control environment. This is especially true of public and SEC registered companies which are required to report on their internal control environments in their annual reports and filings. With technological, cybersecurity and other issues that have arisen, System and Organization Controls (SOC) Reports necessarily have become the standard for assessing internal controls as the reporting has become more complex. This program provides a brief history of the SOC reporting landscape; an understanding of the types of SOC reporting (i.e., SOC 1, SOC 2, SOC 3, and the new SOC for Cybersecurity) and their reporting structures and coverages; and an overview of recent changes to the SOC standards.