SOC 1 guides & explainers
Practical, source-backed guides to SOC 1 costs, scoping, Type 1 vs Type 2, CPA firm selection, and examination readiness -- written for the person who has to get it done.
SOC 1 vs SOC 2: What’s the Difference?
SOC 1 covers controls relevant to financial reporting (ICFR); SOC 2 covers security and availability under the Trust Services Criteria. Different audiences, different reports -- many companies need both.
SSAE 18 Explained: The Standard Behind SOC 1
SSAE 18 is the AICPA attestation standard that governs SOC 1 examinations: what the CPA firm must do, what Type 1 vs Type 2 means, and the key terms in your report.
The SOC 1 Readiness Checklist
Everything to have in place before your SOC 1 examination starts: system description, control objectives, evidence, subservice organizations, and the observation period decision.
How Long Does SOC 1 Take?
Realistic SOC 1 timelines: 4-12 weeks for a Type 1, 8-14 months for a first Type 2 including the observation period -- and what compresses or stretches each phase.
SOC 1 Cost Breakdown: What You’re Actually Paying For
SOC 1 fees by path with planning estimates, plus the five cost drivers that move quotes -- and the hidden costs (remediation, evidence labor) buyers forget to budget.
Who Needs a SOC 1 Report?
If your services affect your customers’ financial reporting -- payroll, billing, claims, transaction processing, hosting -- you’re in SOC 1 territory. How to tell, and who decides.
Reading is step one. Quotes are step two.
When you're ready, get scoped quotes from CPA firms matched to your environment.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.