Which SOC 1 report do your customers need?
Your customers’ auditors want assurance over the controls that touch their financial reporting. That assurance is a SOC 1 report -- Type 1 (point-in-time) or Type 2 (6–12 month period). Picking the wrong report wastes months and tens of thousands of dollars. We’ll help you pick the right one -- then match you with licensed CPA firms that issue SOC 1 reports under SSAE 18. Free. Two minutes. No obligation.
Free · 2 minutes · No obligation
How quote matching works
- Tell us once — 4 questions, 2 minutes, free.
- We match you — licensed CPA firms filtered to your size, scope, and timeline.
- Auditors quote you — they send scoped quotes directly; you pick.
We are a quote-matching service, not an audit firm, and listings are not endorsements. How we vet firms and label prices →
Type 1, readiness, or full Type 2
Every SOC 1 journey follows one of these paths. What your customers and their auditors will accept decides -- not your preference.
1. SOC 1 Type 1
A CPA firm examines whether your controls are designed suitably at a point in time. Fastest and cheapest -- and a common first step before a Type 2.
2. Readiness assessment
A CPA firm runs a pre-examination: control design review, gap analysis, remediation plan. No signed report -- but the examination that follows goes dramatically smoother.
3. SOC 1 Type 2
A licensed CPA firm tests operating effectiveness over a 6–12 month period and issues your SOC 1 Type 2 report. This is what most enterprise customers require.
SOC 1 CPA firms for every path
18 verified SOC 1 CPA firms -- from SMB-friendly Type 1 practices to Big Four and national examination teams. Independent directory: listings are not endorsements, and firms can’t pay for placement.
Zero Day CPA
Zero Day CPA is a Michigan-based boutique licensed CPA firm focused on SOC examinations for B2B SaaS and service organizations. Its SOC 1 practice cov…
Prescient Assurance
Prescient Assurance is an AICPA-accredited SOC audit firm that pairs audit teams with security-testing experience. Its SOC 1 practice serves SaaS comp…
MJD Advisors
MJD Advisors is a SOC-focused licensed CPA firm offering SOC 1 and SOC 2 examinations. Its focused practice model suits service organizations that wan…
Johanson Group, LLP
Johanson Group, LLP is a licensed CPA firm focused on security compliance audits, operating as a remote-first practice. Its SOC 1 examinations cover T…
SOC 1 guides
The 3 SOC 1 Paths
Type 1 point-in-time, readiness assessment, or full Type 2 examination -- which report your customers actually need.
SOC 1 Cost Guide
What each path costs: planning-estimate Type 1, readiness, and Type 2 fee ranges plus an estimator.
SOC 1 Timeline
How long each path takes, from scoping call to signed report -- including the 6–12 month Type 2 observation period.
Which Path Fits You?
A 2-minute quiz that points you at the right SOC 1 report.
The SOC 1 Standard (SSAE 18)
What auditors test: control objectives, ICFR relevance, and the anatomy of a SOC 1 report.
Type 1 vs Type 2 Explained
Point-in-time vs period-of-time -- cost, effort, and when each one satisfies your customers.
2026 SOC 1 Pricing Report
Planning-estimate SOC 1 fee bands by path and company size, each labeled by source.
SOC 1 Guides
Step-by-step explainers for the whole examination journey.
Best SOC 1 Firms by Use Case
Buyer-matched picks for each report path.
Our Methodology
How we vet firms, label every price, and keep rankings unbought.
SOC 1 basics
What is SOC 1 certification?
Strictly speaking there is no ‘SOC 1 certificate’ -- SOC 1 is an independent examination of the controls at a service organization that are relevant to its customers’ internal control over financial reporting (ICFR), performed under AICPA SSAE 18. ‘SOC 1 certification’ is the industry’s shorthand for completing that examination and receiving the report. Only a licensed CPA firm can issue it.
Which SOC 1 report do I need -- Type 1 or Type 2?
A Type 1 reports on the design of your controls at a point in time; a Type 2 reports on design and operating effectiveness over a 6–12 month period. Most enterprise customers and their auditors require a Type 2. A Type 1 is a common stepping stone for a first examination. Our paths guide and 2-minute quiz sort it out.
How much does a SOC 1 examination cost?
Planning estimates (September 2026): a Type 1 typically runs $10K–$30K, a readiness assessment $5K–$25K, and a Type 2 $20K–$100K+, depending on scope and company size. See the cost guide.
How long does SOC 1 take?
A Type 1 takes 4 to 12 weeks from scoping to signed report. A readiness assessment takes 2 to 6 weeks. A Type 2 requires a 6–12 month observation period plus 4 to 8 weeks of fieldwork and reporting. Details on the timeline page.
Get quotes from SOC 1 CPA firms
Tell us your path and timeline once. We’ll match you with licensed CPA firms that fit -- no obligation, no spam.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.