The standard

The SOC 1 standard (SSAE 18), in plain English

SOC 1 isn’t a checklist of requirements -- it’s an examination framework. Here’s what the standard actually covers, what your report contains, and what your CPA firm tests.

What SOC 1 actually is

SOC 1 is a report on the controls at a service organization that are relevant to its customers’ internal control over financial reporting (ICFR), examined by a licensed CPA firm under AICPA SSAE 18. Unlike checklist standards, there’s no fixed list of controls: you define your system and control objectives, and the CPA firm opines on whether your controls are suitably designed (Type 1) and operating effectively (Type 2) to meet them.

Anatomy of a SOC 1 report

1. The opinion

The CPA firm’s formal opinion: whether your system description is fairly presented, controls were suitably designed (Type 1), and operated effectively throughout the period (Type 2).

2. System description

Your written description of the services, system boundaries, and controls. The firm opines on its fairness -- inaccuracies here are findings.

3. Control objectives

The outcomes your controls are designed to achieve, mapped to your customers’ ICFR needs. You define them; the firm tests against them.

4. Tests of controls

For each control: what the firm tested, how, the sample sizes, and the results -- including any exceptions found during the period.

5. CUECs

Complementary user entity controls: what your customers must do for your controls to work. Their auditors need these spelled out.

6. Subservice organizations

Vendors your controls depend on. Carve-out excludes their controls; inclusive includes them in the examination.

What the CPA firm actually tests

Typical control areas in a SOC 1 examination: logical access (provisioning, deprovisioning, periodic access reviews, privileged access), change management (approval, testing, deployment), processing controls (completeness and accuracy of transaction processing, reconciliations, exception handling -- the ICFR heart), data backup and recovery, incident response, and vendor management. The exact controls are yours to design; the firm tests whether they meet your stated objectives.

Know the standard. Now find your CPA firm. Tell us your environment once -- matched firms send scoped quotes. Free · 2 minutes.

Get matched quotes

Standard questions

Who writes the control objectives -- us or the CPA firm?

You do. Control objectives describe what your controls are designed to achieve for your customers’ ICFR. The CPA firm tests whether your controls meet them -- but defining objectives that match what your customers’ auditors actually need is your job, ideally with the firm’s input during scoping.

What’s the difference between carve-out and inclusive?

Carve-out excludes a subservice organization’s controls from your report (your customers’ auditors must get assurance on those controls separately). Inclusive brings the subservice org’s controls into your examination. Inclusive gives your customers a complete reliance story but costs more and requires the subservice org’s cooperation.

Do we need a Type 2, or is Type 1 enough?

It depends what your customers’ auditors will accept. Most enterprise customers require a Type 2 because only it opines on operating effectiveness. A Type 1 is a legitimate stepping stone -- confirm acceptance in writing. See our Type 1 vs Type 2 guide.

→ Type 1 vs Type 2 in detail  ·  The 3 SOC 1 paths  ·  Readiness quiz

Ready to get examined?

Get scoped quotes from licensed CPA firms that fit your environment.

Get a free quote