ReadSafety.com
Assurance ReportAmerican Institute of CPAs (AICPA)Last reviewed: August 2026

SOC 1 / SSAE 18

A SOC 1 report is an independent auditor's assessment of a service organization's controls that are relevant to their customers' financial reporting - it is NOT a certification.

What You'll Learn

  • What a SOC 1 report is (and is not)
  • Type I vs Type II reports
  • Why customers request SOC 1 reports
  • The relationship to financial statement audits
  • SSAE 18 (the U.S. attestation standard)
  • SOC 1 vs SOC 2 differences
  • Control objectives and testing

First: What Is This?

A SOC 1 report (System and Organization Controls 1) is an independent auditor's report on the controls at a service organization that are relevant to user entities' internal control over financial reporting (ICFR). It is governed by SSAE 18 (Statement on Standards for Attestation Engagements No. 18) in the United States and ISAE 3402 internationally.

Important: SOC 1 is NOT a certification. It is an assurance report - an independent auditor examines controls and provides an opinion. The service organization does not 'pass' or 'fail' - the auditor describes the controls and whether they operated effectively.

Who Does It Apply To?

Payroll processors
Cloud hosting providers handling financial data
Payment processors
Fund administrators
Any service organization whose services affect customers' financial reporting
SaaS companies (SOC 2 may be more appropriate unless services directly affect financial reporting)
IT service providers (depends on nature of services)
Companies seeking general security assurance (SOC 2 is more appropriate)
Organizations wanting a certification to display (SOC reports are restricted-use documents)
Internal use only (internal audit serves this purpose)

Is It Mandatory?

SOC 1 reports are not legally mandatory. However, they are effectively required by market demand: customers' external auditors need assurance over outsourced processes that affect financial reporting. Without a SOC 1, each customer's auditor would need to audit the service organization directly - which is impractical and expensive.

Type I vs Type II Reports

Professional

A Type I report covers the design of controls at a specific point in time - the auditor opines on whether controls are suitably designed to achieve control objectives. A Type II report covers both design AND operating effectiveness over a period (typically 12 months) - the auditor tests whether controls actually operated as designed throughout the period.

In Plain English

Type I is a snapshot: 'On this specific date, the controls looked properly designed.' Type II is a movie: 'Over the past 12 months, we tested the controls and they actually worked as intended.' Type II is much more valuable because it proves the controls work in practice, not just on paper. Most customers want Type II.

🧠Explain Like I'm 10

Type I is like checking that a fire extinguisher is hanging on the wall (it is there and looks correct). Type II is like checking every month for a year that the fire extinguisher is still there, still charged, and still within its expiration date. Type II proves it actually works over time, not just that it existed on one day.

Practical Example

PayrollCo processes payroll for 500 client companies. A Type II SOC 1 report covers July 1, 2025 to June 30, 2026. The auditor tests controls monthly: Are pay calculations accurate? Are tax withholdings correct? Are bank transfers authorized? Are terminated employees removed promptly? The report describes each control, the test performed, and whether exceptions were found.

Common Mistake

Thinking a Type I report is sufficient for ongoing assurance. Type I only confirms design at a point in time - it says nothing about whether controls actually worked over the year. Most customer auditors require Type II reports because they need evidence of operating effectiveness, not just design.

SOC 1 vs SOC 2

Professional

SOC 1 reports address controls relevant to user entities' financial reporting (ICFR). SOC 2 reports address controls relevant to security, availability, processing integrity, confidentiality, and privacy (Trust Services Criteria). The choice depends on what the service organization's customers need: if the service directly affects financial reporting, SOC 1; if customers need assurance over security and operational controls, SOC 2.

In Plain English

SOC 1 is about money: does this service organization handle our financial data correctly so our financial statements are accurate? SOC 2 is about security and operations: is this service organization keeping our data safe, available, and private? A payroll processor typically needs SOC 1 (because it directly affects financial reporting). A cloud storage provider typically needs SOC 2 (because customers care about security).

🧠Explain Like I'm 10

SOC 1 is like checking that the school cafeteria counts lunch money correctly (financial accuracy). SOC 2 is like checking that the school keeps the building locked, the computers working, and student records private (security and operations). Different checks for different concerns.

Common Mistake

Calling SOC 1 a 'SOC 1 certification.' It is not a certification - it is an assurance report. The service organization does not receive a certificate to hang on the wall. The report is a restricted-use document shared with customers and their auditors. Similarly, there is no 'SOC 1 certified' badge or logo.

Frequently Asked Questions

Who can issue a SOC 1 report?

Only an independent CPA firm (or equivalent qualified auditor) can issue a SOC 1 report. The service organization cannot self-assess or self-certify. The auditor must be independent of the service organization and follow SSAE 18 (U.S.) or ISAE 3402 (international) standards.

Who can read a SOC 1 report?

SOC 1 reports are restricted-use documents. They are intended for the service organization's management, user entities (customers), and user entities' auditors. They should not be made publicly available or used for marketing purposes. SOC 3 reports (a summary version of SOC 2) are the only publicly distributable SOC report.

How often is a SOC 1 report issued?

Typically annually. Type II reports cover a 12-month period (sometimes 6 or 9 months for first-time reports). User entities' auditors need a report that covers their financial statement audit period, so most service organizations align their SOC 1 reporting period with the calendar or fiscal year.

Related Guides

Issuing organization: American Institute of CPAs (AICPA)
Current version: SSAE 18 (effective May 1, 2017)
Effective date: May 1, 2017 (SSAE 18 replaced SSAE 16)
Last reviewed: August 2026
Back to Finance