WEBINAR
SOC 2 vs. HITRUST: A Practitioner Debate on What Third-Party Risk Actually Needs
October 8, 2026 | 10:00 AM CT
When SOC 2 was drafted, its authors did not expect it to apply to companies under 100 employees. Today roughly 90 percent of the organizations going through a SOC 2 are under that threshold.
Part one of this series put the industry data on the table. Part two brings in the other side of the conversation. Nick Norton, co-founder of Geels-Norton (now a Smith & Howard firm) and now leading the cyber risk practice at Smith & Howard, has spent his career issuing SOC 2 reports for high-growth and public SaaS companies. He joins Ryan Patrick of HITRUST and AJ Yawn of Rippling and the GRC Engineering Club for a live, unscripted conversation about where SOC 2 breaks down in third-party risk management, what HITRUST is actually building, and what a workable path forward looks like for the TPRM teams stuck in the middle.
You will leave with a clear read on what a SOC 2 report gives a TPRM team and what it leaves out, how HITRUST positions itself as a third-party risk company, why one audit feeding many reports may be closer than you think, and what still has to change in contracts and procurement before any of it matters.
Speakers

.png?width=200&height=227&name=FY26%20-%20Q3%20-%20Speaker%20Headshot%20-%20AJ%20Yawn%20(1).png)

AJ Yawn
Author, GRC Engineering Lead
Rippling
Nick Norton
Partner, Cyber Risk
GN, a S+H company AuditEdge
Ryan Patrick
EVP, TPRM Customer Solutions
HITRUST