Glossary · Frameworks & standards
What is SOC 1?
Also known as: SOC 1 report, Service Organization Control 1, SSAE 18 SOC 1
SOC 1 is an attestation report, defined by the AICPA under SSAE 18, that evaluates a service organization's controls relevant to its customers' internal control over financial reporting (ICFR). It is requested by customers whose financial statements are affected by the services they buy - such as payroll, payments, or billing platforms - and their auditors.
Key takeaways
- SOC 1 covers controls relevant to customers' financial reporting (ICFR), not general security.
- Issued by a licensed CPA firm under SSAE 18 (AT-C 320).
- Comes in Type I (design at a point in time) and Type II (operating effectiveness over a period).
- Its audience is restricted to customer organizations (user entities) and their auditors.
- Common for payroll, payments, billing, and other financial-data processors; many fintechs need both SOC 1 and SOC 2.
When do you need a SOC 1 report?
You need SOC 1 when the service you provide could affect your customers' financial statements. Classic examples are payroll processors, payment and billing platforms, and other systems whose output flows into a customer's books. In those cases the customer's financial auditor will often request your SOC 1 to rely on your controls.
If instead your buyers are concerned with how you secure their data, the report they want is SOC 2. Many financial-technology companies end up needing both.
SOC 1 vs SOC 2
SOC 1 and SOC 2 use the same audit machinery - SSAE 18, Type I/II, and a licensed CPA firm - and share much of the same underlying control evidence around access, change management, and monitoring. The difference is scope: SOC 1 is about financial-reporting controls, while SOC 2 is about the Trust Services Criteria for security and data protection.
Frequently asked questions
- What is the difference between SOC 1 and SOC 2?
- SOC 1 covers controls relevant to your customers' financial reporting; SOC 2 covers security and data-protection controls. SOC 1 answers 'could your service distort our books?', while SOC 2 answers 'can we trust you with our data?'.
- Is SOC 1 a certification?
- No. Like SOC 2, SOC 1 is an attestation report with an auditor's opinion issued by a licensed CPA firm - not a certificate from a standards body.
- Can SOC 1 and SOC 2 be done together?
- Yes. They share the SSAE 18 framework and much of the same control evidence, so organizations that need both commonly run them together to reduce cost and duplicate effort.