What is the difference between SOC 1 and SOC 2?
SOC 1 and SOC 2 are both AICPA attestation reports, but they cover different things. SOC 1 covers controls at a service organization that are relevant to its customers financial reporting (ICFR). SOC 2 covers controls relevant to security and the other Trust Services Criteria (availability, processing integrity, confidentiality, and privacy). If customers care about how you affect their financial statements, that is SOC 1; if they care about how you protect their data, that is SOC 2.
SOC 1 is about financial reporting
A SOC 1 report (under SSAE 18) addresses controls at a service organization that could affect its customers internal control over financial reporting. Payroll processors and payment platforms are common examples.
SOC 2 is about security and data
A SOC 2 report addresses the Trust Services Criteria, with Security (the Common Criteria) always in scope and Availability, Processing Integrity, Confidentiality, and Privacy added as they fit your commitments to customers.
Both come in Type I and Type II
Like SOC 2, SOC 1 has a Type I (design at a point in time) and a Type II (operating effectiveness over a period). Which report and which type you need depends on what your customers rely on you for.
FAQ
Do most SaaS companies need SOC 1 or SOC 2?
Usually SOC 2, because buyers are concerned with how you secure their data. SOC 1 matters when your service affects customers financial reporting, such as processing transactions that flow into their books.
What about SOC 3?
A SOC 3 is a short, public-facing summary of a SOC 2 examination. It carries less detail and can be shared freely, for example on a website, without an NDA.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free