Glossary

SOC 1

A SOC 1 report examines controls at a service organization that are relevant to its customers’ financial reporting — not security in general. If your product processes payroll, billing, payments, fund transfers, or anything your customers’ auditors rely on when signing financial statements, SOC 1 is the report their finance teams ask for.

SOC 1 vs SOC 2

Same audit machinery (CPA firms, Type I and Type II variants, observation windows), different subject matter. SOC 2 tests against the trust services criteria — security, availability, confidentiality. SOC 1 tests control objectives you define around financial data integrity. A SaaS company selling project management software needs SOC 2 only; a payments processor frequently needs both, requested by different departments of the same customer.

How to decide

Follow the requester. Security teams ask for SOC 2; controllers and external auditors ask for SOC 1. If nobody has asked for SOC 1, don’t buy one preemptively — the demand signal is reliable, and the two reports share enough control substance that adding SOC 1 later onto a running SOC 2 program is an increment, not a restart.

Related Terms

SOC 3 — A SOC 3 is the public, general-use version of a SOC 2 Type II report — same audit, no confidential detail, freely publishable on your website.

SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.

Trust Services Criteria — The five Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and how they define your SOC 2 scope.