Three AICPA reports, three different jobs. Here is what SOC 1, SOC 2 and SOC 3 each prove, and the one your buyers actually want.
SOC 1, SOC 2 and SOC 3 are three reporting standards from the American Institute of CPAs, and they answer different questions. SOC 1 reports on controls that affect your customers' financial reporting, and it is governed by SSAE 18. SOC 2 reports on controls relevant to security, availability, confidentiality, processing integrity and privacy, using the Trust Services Criteria. SOC 3 is a short, public summary of a SOC 2 that you can publish on your website. Most software companies need SOC 2. Here is how the three differ and which one your buyers are actually asking for.
A SOC 1 report covers the controls at a service organisation that could affect its customers' financial statements. It exists for the case where you process something, such as payroll or payments, that flows into a customer's books, and that customer's own auditors need assurance over how you handle it. SOC 1 is performed under the AICPA's SSAE 18 standard and comes in Type I and Type II forms. If your service does not touch customers' financial reporting, you almost certainly do not need SOC 1.
A SOC 2 report covers the controls at a service organisation relevant to security and, optionally, availability, confidentiality, processing integrity and privacy. It is built on the AICPA's Trust Services Criteria, with Security as the mandatory core. SOC 2 is the report that technology buyers, security teams and procurement functions ask for before trusting you with their data. It is restricted-use, meaning it is shared under NDA rather than published, and it comes in Type I and Type II. For most SaaS and technology companies, SOC 2 is the report that unblocks deals.
A SOC 3 report is a general-use, public summary derived from a SOC 2 Type II examination. It confirms that you hold a SOC 2 without disclosing the detailed control descriptions and test results, which is why you can put it on your website or hand it to anyone. A SOC 3 does not replace a SOC 2; you produce it in addition, when you want a public marketing-friendly proof point. It is always based on a period of operation, so there is no Type I version of SOC 3.
The difference between SOC 1 and SOC 2 is subject matter. SOC 1 is about financial reporting controls and is aimed at your customers' auditors; SOC 2 is about security and data-protection controls and is aimed at your customers' security and procurement teams. They are not tiers of the same thing, and a higher number does not mean a stronger report. Some organisations need both because they are relevant to different customer concerns, but a typical SaaS company that does not process customers' financial data needs SOC 2 alone.
No, there is no SOC 2 Type 3 report. SOC 2 comes in Type I and Type II only. People searching for a SOC 2 Type 3 usually mean one of two things: SOC 3, which is the public summary of a SOC 2, or a SOC 2 Type II, which is the period-based report most buyers want. If a customer asks you for a Type 3, clarify whether they want a shareable SOC 3 or the full SOC 2 Type II under NDA, because those are different documents.
Most technology companies need a SOC 2, usually a Type II, because that is what customers request before trusting you with their data. Add a SOC 3 only if you want a public proof point to display. Consider SOC 1 only if your service affects customers' financial reporting, such as payments or payroll processing. If in doubt, ask the customer who raised it exactly which report and type they require, since the request often arrives worded loosely.
CertAssist lays out the SOC 2 Trust Services Criteria on a clear board, gives you editable policy and evidence templates, and provides read-only access for your auditor, so you can work toward a Type I or Type II report without an enterprise budget or any system integrations. Because CertAssist does not connect to your systems, there is nothing to set up and nothing to breach. The independent CPA examination is always separate, but getting your controls and evidence organised is most of the work, and that is what CertAssist handles for a published US$225 per month during its launch.
SOC 1 covers controls that affect your customers' financial reporting and is read by their auditors, under the SSAE 18 standard. SOC 2 covers security and data-protection controls under the Trust Services Criteria and is read by security and procurement teams. They serve different concerns; a higher number is not a stronger report, and many companies need only SOC 2.
No. SOC 2 exists as Type I and Type II only. People asking for a SOC 2 Type 3 usually mean SOC 3, the public general-use summary of a SOC 2, or a SOC 2 Type II. If a customer requests a Type 3, confirm whether they want a shareable SOC 3 or the full SOC 2 Type II report under NDA.
A SOC 3 is a short, public summary of a SOC 2 Type II examination. Because it omits the detailed control tests, you can publish it on your website or share it freely as a proof point. It does not replace a SOC 2; you produce it in addition when you want a marketing-friendly confirmation that you hold a SOC 2.
Most technology companies need SOC 2, because it addresses security and is what customers request before sharing data. You need SOC 1 only if your service affects customers' financial reporting, such as payroll or payment processing. When a customer raises it, ask exactly which report they require, since requests are often worded loosely.
Yes. Some organisations produce both because they are relevant to different customer concerns: SOC 1 for financial-reporting impact and SOC 2 for security. They are separate examinations with separate scopes and fees. A typical SaaS company that does not process customers' financial data needs only SOC 2, often with a SOC 3 summary added for public use.
CertAssist lays out the Trust Services Criteria, gives you editable templates, and hands your auditor a tidy workspace, for a published $225 a month during the launch.
See pricing FrameworksFlat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.