Skip to content
deveca GRC
Compliance & standards9 min read

What are SOC 1, SOC 2 and SOC 3 — and how do Type 1 and Type 2 differ?

SOC 2 is not a certification. It is an examination report. Here is the difference between SOC 1, 2 and 3, Type 1 versus Type 2, and how a service provider becomes audit-ready.

Author:
  • SOC 2
  • SOC 1
  • SOC 3
  • Trust Services Criteria
  • Audit

Customers, especially in the US, ask service providers for a SOC report. The names are easy to mix up. SOC 2 is an examination report from an AICPA auditor, not a certificate you hang on the wall.

What a SOC report is

A SOC report is an independent auditor’s opinion on a service organisation’s controls. It describes the system, the criteria, the tests, and the exceptions. It is point-in-time or over a period, depending on the type. It is not a product badge and it does not replace ISO 27001.

SOC 1, SOC 2 and SOC 3

  • SOC 1 covers controls relevant to a customer’s financial reporting. It is the report auditors of your customers ask for when your service affects their books.
  • SOC 2 covers the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality, and privacy. This is the report most SaaS buyers mean.
  • SOC 3 is a short public summary of a SOC 2 examination. It has no detailed test results, so procurement teams usually still want the SOC 2.

Type 1 versus Type 2

Type 1 asks whether the controls are suitably designed at a point in time. Type 2 asks whether those controls operated effectively over a period, often six to twelve months. Buyers who have been through a few vendor reviews ask for Type 2. Type 1 is a reasonable first examination when the control set is new.

Which report you need

If the buyer’s question is about their financial statements, start with SOC 1. If the question is about security and privacy of a cloud service, start with SOC 2 and the criteria the contract actually names. Publishing a SOC 3 only helps after a SOC 2 exists.

SOC 2 and ISO 27001

The two are not alternatives. ISO 27001 is a management-system certificate. SOC 2 is an attestation about specific criteria. Many controls and the same evidence serve both, if the mapping is explicit.

Becoming audit-ready

  • Write the system description in the language of the service you actually sell.
  • Pick the Trust Services Criteria in scope and map controls to them.
  • Collect evidence for the period, not a screenshot from the week before the auditor arrives.
  • Track exceptions with an owner and a date.

How deveca GRC helps

Controls, evidence, and the audit trail live next to the ISO 27001 work, so a SOC request does not start a second documentation project.

Common questions

SOC 2 is not a certification. Type 2 is not “better ISO”. A report for one system does not automatically cover a second product. Read the scope paragraph before you rely on a vendor’s PDF.

Conclusion

Ask which report the customer needs, which criteria, and which period. Then keep the evidence where the rest of the control work already lives.

Keep controls and evidence for ISO 27001 and SOC in deveca GRC

GRC in practice

See how deveca supports your ISMS and compliance programme.