Glossary · Frameworks & standards

What is SOC 1?

Also known as: SOC 1 report, Service Organization Control 1, SSAE 18 SOC 1

SOC 1 is an attestation report, defined by the AICPA under SSAE 18, that evaluates a service organization's controls relevant to its customers' internal control over financial reporting (ICFR). It is requested by customers whose financial statements are affected by the services they buy - such as payroll, payments, or billing platforms - and their auditors.

Key takeaways

  • SOC 1 covers controls relevant to customers' financial reporting (ICFR), not general security.
  • Issued by a licensed CPA firm under SSAE 18 (AT-C 320).
  • Comes in Type I (design at a point in time) and Type II (operating effectiveness over a period).
  • Its audience is restricted to customer organizations (user entities) and their auditors.
  • Common for payroll, payments, billing, and other financial-data processors; many fintechs need both SOC 1 and SOC 2.

When do you need a SOC 1 report?

You need SOC 1 when the service you provide could affect your customers' financial statements. Classic examples are payroll processors, payment and billing platforms, and other systems whose output flows into a customer's books. In those cases the customer's financial auditor will often request your SOC 1 to rely on your controls.

If instead your buyers are concerned with how you secure their data, the report they want is SOC 2. Many financial-technology companies end up needing both.

SOC 1 vs SOC 2

SOC 1 and SOC 2 use the same audit machinery - SSAE 18, Type I/II, and a licensed CPA firm - and share much of the same underlying control evidence around access, change management, and monitoring. The difference is scope: SOC 1 is about financial-reporting controls, while SOC 2 is about the Trust Services Criteria for security and data protection.

Frequently asked questions

What is the difference between SOC 1 and SOC 2?
SOC 1 covers controls relevant to your customers' financial reporting; SOC 2 covers security and data-protection controls. SOC 1 answers 'could your service distort our books?', while SOC 2 answers 'can we trust you with our data?'.
Is SOC 1 a certification?
No. Like SOC 2, SOC 1 is an attestation report with an auditor's opinion issued by a licensed CPA firm - not a certificate from a standards body.
Can SOC 1 and SOC 2 be done together?
Yes. They share the SSAE 18 framework and much of the same control evidence, so organizations that need both commonly run them together to reduce cost and duplicate effort.

Authoritative sources

← Back to the glossary