SOC 1 frequently asked questions
Straight answers about the SOC 1 paths -- Type 1, readiness, Type 2 -- and how to navigate them.
Is SOC 1 actually a certification?
Strictly speaking, no -- it’s an independent examination: a licensed CPA firm issues a SOC 1 report (Type 1 or Type 2) under AICPA SSAE 18, renewed on a cycle your customers dictate. In practice the market treats it like a certification: ‘SOC 1 certified’ means ‘we hold a current SOC 1 report.’ This site uses the industry’s language while staying precise about what each path produces.
Which report do I need -- Type 1 or Type 2?
Your customers -- and their auditors, who rely on your report for their own ICFR audits -- decide what they will accept. Most enterprise customers require a Type 2 (operating effectiveness over 6–12 months). A Type 1 (design at a point in time) is faster and cheaper, and a common stepping stone. Anyone facing a first Type 2 should consider a readiness assessment first. See our path comparison.
What does the Type 1 path involve, step by step?
One: confirm with your customers that a point-in-time report is acceptable. Two: define your system and control objectives with your CPA firm. Three: the firm evaluates control design as of a specific date. Four: you receive the signed SOC 1 Type 1 report. Typical: 4–12 weeks. Type 1 vs Type 2 in detail.
What does the readiness path involve?
A CPA firm reviews your control design against your objectives, tests your evidence, and delivers a gap report with a remediation roadmap -- no pass/fail, no signed report. Typical: 2–6 weeks. Its product is a fix list that makes the subsequent examination dramatically smoother and cheaper.
What does the Type 2 path involve, step by step?
One: scoping with your CPA firm (services, systems, control objectives, subservice organizations). Two: readiness and remediation. Three: the 6–12 month observation period, during which controls must operate effectively. Four: fieldwork -- the firm tests controls and samples evidence across the period. Five: the signed SOC 1 Type 2 report. Expect 8–14 months end to end for a first Type 2. Full timeline.
How much does each path cost?
Planning estimates (September 2026): Type 1 $10K–$30K; readiness assessments $5K–$25K; Type 2 $20K–$100K+ depending on scope and company size. Remediation typically adds 40–60% on top of the examination fee in year one. See the cost guide.
How long does each path take?
Type 1: 4–12 weeks. Readiness: 2–6 weeks. Type 2: a 6–12 month observation period plus 4–8 weeks of fieldwork and reporting -- 8–14 months end to end for a first-timer.
Who can issue a SOC 1 report?
Only a licensed CPA firm, under AICPA SSAE 18 standards. Neither a security vendor, a consultant, nor this directory can issue one -- and any ‘SOC 1 certification’ not signed by a licensed CPA firm isn’t a SOC 1 report. Confirm each firm’s credentials before engaging.
What is SSAE 18?
SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the AICPA standard governing SOC examinations, including SOC 1. It defines how the CPA firm plans, performs, and reports on the examination -- including the Type 1 vs Type 2 distinction. The standard explained.
What happens if the examination finds problems?
You don’t ‘fail’ permanently. For a Type 2, control failures during the observation period become exceptions in the report -- or, if severe, a qualified opinion. You can remediate and, in many cases, extend or restart the period. This is exactly why readiness assessments exist: finding gaps early is far cheaper than exceptions in a signed report.
Can we do a Type 1 first and upgrade to Type 2 later?
Yes -- it’s one of the most common journeys. The Type 1 validates your control design, which becomes the foundation for the Type 2 observation period. Just make sure your customers will accept a Type 1 in the interim.
What is ICFR and why does it matter for SOC 1?
ICFR -- internal control over financial reporting -- is the reason SOC 1 exists. Your customers’ auditors rely on your SOC 1 report as evidence about the controls at your organization that affect their financial statements. If your service touches payroll, billing, claims, or transaction processing, you’re in ICFR territory. Who needs a SOC 1?
SOC 1 vs SOC 2 -- which do we need?
SOC 1 covers controls relevant to financial reporting (ICFR); SOC 2 covers security, availability, and confidentiality under the Trust Services Criteria. Many service organizations need both -- and combined examinations share one evidence set. SOC 1 vs SOC 2 explained.
How do we choose a SOC 1 CPA firm?
Confirm the firm is a licensed CPA practice, ask who your examination team is, whether the fee is fixed and what breaks it, how the observation period is managed, and whether you can speak to two reference clients your size. Our readiness checklist walks through selection.
Can one firm handle SOC 1 plus SOC 2 or ISO 27001?
Yes -- firms like Schellman, A-LIGN, 360 Advanced, BARR Advisory, and KirkpatrickPrice run combined programs where one evidence set feeds multiple reports, often at lower total cost than separate engagements.
How often must the report be renewed?
Type 2 reports cover a defined period (usually 12 months) and are renewed annually -- most programs run on a continuous yearly cycle. Type 1 reports are point-in-time; customers typically expect a fresh one each year until you move to Type 2. Treat it as a program, not a project.
We were told we need SOC 1 for an enterprise deal -- where do we start?
First, get the exact requirement in writing: Type 1 or Type 2, and by when. Second, take our path quiz. Third, if it’s a Type 2 and your first, budget a readiness assessment before the observation period starts. Then get competing quotes -- we’ll match you with CPA firms.
Does this site perform examinations?
No. We are an independent directory and quote-matching service -- not an auditor or certification body. SOC 1 reports can only be issued by licensed CPA firms under AICPA standards.
Still have questions?
Talk to matched CPA firms directly -- describe your situation once, get path-appropriate quotes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.