Glossary · Frameworks & standards
What is SOC 1?
Also known as: SOC 1 report, Service Organization Control 1, SSAE 18 SOC 1
SOC 1 is an attestation report, defined by the AICPA under SSAE 18, that evaluates a service organization's controls relevant to its customers' internal control over financial reporting (ICFR). It is requested by customers whose financial statements are affected by the services they buy - such as payroll, payments, or billing platforms - and their auditors.
Key takeaways
- SOC 1 covers controls relevant to customers' financial reporting (ICFR), not general security.
- Issued by a licensed CPA firm under SSAE 18 (AT-C 320).
- Comes in Type I (design at a point in time) and Type II (operating effectiveness over a period).
- Its audience is restricted to customer organizations (user entities) and their auditors.
- Common for payroll, payments, billing, and other financial-data processors; many fintechs need both SOC 1 and SOC 2.
When do you need a SOC 1 report?
You need SOC 1 when the service you provide could affect your customers' financial statements. Classic examples are payroll processors, payment and billing platforms, loan servicers, expense and invoicing systems, and other services whose output flows into a customer's books. In those cases the customer's financial auditor (the user auditor) will often request your SOC 1 so they can rely on your controls instead of testing them directly.
If instead your buyers are concerned with how you secure their data, the report they want is SOC 2. Many financial-technology companies end up needing both, and can pursue them together.
What controls does a SOC 1 report cover?
SOC 1 is scoped to controls relevant to internal control over financial reporting (ICFR) - the control objectives you define around the service you provide. Unlike SOC 2, there is no fixed criteria set; you assert the control objectives that matter for your customers' financial statements, and the CPA firm tests them. Typical objectives include:
- Completeness and accuracy of transaction processing (nothing lost, nothing duplicated).
- Authorization - transactions are valid and approved before they are processed.
- Access controls over the systems and data that drive financial outputs.
- Change management over the applications that process customer transactions.
- Reconciliations and monitoring that would catch and correct errors.
The report also documents 'complementary user entity controls' - the things your customers must do on their side for the control environment to work end to end.
SOC 1 Type I vs Type II
Like SOC 2, SOC 1 comes in two types. A Type I report opines on whether your controls are suitably designed at a single point in time. A Type II report goes further and tests whether those controls operated effectively across a period - usually 6 to 12 months - which is what most customers and their auditors ultimately want, because it is evidence the controls actually ran, not just that they existed on paper.
The mechanics mirror SOC 2 Type II: the more of your evidence that is collected continuously and timestamped, the smoother the Type II window is to survive.
SOC 1 vs SOC 2
SOC 1 and SOC 2 use the same audit machinery - SSAE 18, Type I/II, and a licensed CPA firm - and share much of the same underlying control evidence around access, change management, and monitoring. The difference is scope and audience. SOC 1 is about financial-reporting controls and is read by your customers and their financial auditors; SOC 2 is about the Trust Services Criteria for security and data protection and is read by your customers' security and procurement teams.
Because they overlap heavily, running them together is efficient - see the full SOC 1 vs SOC 2 comparison.
How to prepare for a SOC 1 audit
Preparation looks a lot like SOC 2 readiness: define the control objectives for the service in scope, map each to concrete controls, close the gaps, then collect evidence across the Type II window. The two accelerators are automating evidence collection so controls prove themselves continuously, and cross-mapping one control to both SOC 1 and SOC 2 so you do not run two separate programmes.
CATAAM does both - and because the underlying controls are shared, it treats SOC 1 readiness as part of the same subscription as SOC 2 rather than a separate purchase, so financial-data processors can prepare for both from one control set.
Frequently asked questions
- What is the difference between SOC 1 and SOC 2?
- SOC 1 covers controls relevant to your customers' financial reporting; SOC 2 covers security and data-protection controls. SOC 1 answers 'could your service distort our books?', while SOC 2 answers 'can we trust you with our data?'. They share the same SSAE 18 audit machinery, so many companies pursue both together.
- What is the difference between SOC 1 Type I and Type II?
- Type I opines on whether controls are suitably designed at a point in time; Type II tests whether they operated effectively over a period (typically 6-12 months). Most customers and their auditors want Type II, because it is evidence the controls actually ran throughout the period, not just that they existed on one day.
- Is SOC 1 a certification?
- No. Like SOC 2, SOC 1 is an attestation report with an auditor's opinion issued by a licensed CPA firm - not a certificate from a standards body. There is no 'SOC 1 certificate'; there is a report.
- Who reads a SOC 1 report?
- SOC 1 has a restricted audience: your customers (the user entities) and their financial auditors (the user auditors). It is not a public marketing document - that restriction is part of what distinguishes it from a SOC 3.
- Can SOC 1 and SOC 2 be done together?
- Yes. They share the SSAE 18 framework and much of the same control evidence, so organizations that need both commonly run them together to reduce cost and duplicate effort. CATAAM includes SOC 1 readiness alongside SOC 2 on the same control set rather than as a separate purchase.