SOC 1
Report on controls at a service organization relevant to user entities’ internal control over financial reporting. Updated: September 29, 2026.
SOC 1 exists for a narrow and specific reason: your customers' auditors need to rely on your controls in order to audit your customers' financial statements. If what you operate affects the numbers in someone else's accounts, their auditor either tests your controls themselves — which nobody wants — or reads your SOC 1 report.
How It Differs From SOC 2
The distinction is what the controls are being measured against. SOC 2 tests against a published framework, the Trust Services Criteria. SOC 1 has no equivalent list: the control objectives are defined by you, based on what is relevant to your customers' financial reporting. The auditor then tests whether those objectives were met.
That makes SOC 1 reports genuinely different from one another, and it makes the control objectives section the one to read. It also means SOC 1 says nothing about security beyond what happens to touch financial accuracy — a clean SOC 1 is not a security assurance, and the two reports are not substitutes.
Who Needs One
- Payroll providers — the classic case.
- Payment processors and billing platforms.
- Claims processing and benefits administration.
- Financial systems hosting, where availability and change control affect the integrity of the customer's records.
- Fund administration, loan servicing and similar outsourced financial operations.
You will usually know you need one because a customer's auditor asks, often at year end and often with little notice. If your service does not touch anyone's financial reporting, you do not need SOC 1 and should not buy one.
Type I and Type II, and the Period
The same distinction as SOC 2: Type I tests design at a date, Type II tests operation across a period. For SOC 1 the period matters more than usual, because it has to align with your customers' financial year. A report covering January to September is of limited use to an auditor examining a December year end, and the gap has to be covered by a bridge letter or by additional procedures. Agreeing the period with your significant customers before you commission the audit saves a great deal of friction.
The International Equivalent
SOC 1 is issued under the American attestation standards. The international equivalent, used widely in Europe, is ISAE 3402, and reports are frequently issued under both. If your customers are European, ask your audit firm about a dual-standard report rather than assuming a SOC 1 will be accepted.
Getting One
Engage a licensed audit firm, define the control objectives with them in light of what customers actually rely on, run the period, and have it tested. The process mirrors SOC 2, and the same points apply about generating evidence throughout the period rather than assembling it at the end.
Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.