HomeFAQ
Licensed CPA Firm · SSAE 18 · AICPA

Everything you need to know about SOC 1, SOC 2, and SOC 3

Clear answers about the audit process, timelines, required documentation, and how to choose the right report for your organization in the U.S. and Latin America.

SOC 1 SOC 2 SOC 3 SSAE 18 AICPA
Frequently Asked Questions

Everything you need to know about SOC reports

We answer the most common questions about SOC 1, SOC 2, and SOC 3 attestation audits under SSAE 18.

A SOC report (System and Organization Controls) is an attestation report issued by a CPA firm under the AICPA's SSAE 18 standard. It evaluates a service organization's internal controls so that its clients and their external auditors can rely on the security and integrity of the processes that organization manages on their behalf.

SOC 1 evaluates a service organization's internal controls over financial reporting (ICFR). SOC 2 evaluates the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). SOC 3 is a public, simplified version of SOC 2, designed to be shared without exposing sensitive technical detail. All three are issued under the AICPA's SSAE 18 standard.

A Type I report evaluates the design of controls at a specific point in time. A Type II report also evaluates the effective operation of those controls over an observation period, typically 6 to 12 months, offering a higher level of assurance to clients and external auditors.

It depends on the scope, the complexity of the environment, and the type of report required. A Type I report can typically be issued within 1 to 1.5 months. A Type II report, in addition to the observation period (commonly 6 to 12 months), usually takes an additional 1.5 to 2.5 months for execution and issuance of the report once that period ends.

Any organization that processes, stores, or manages financial or third-party data typically requires a SOC report. It's common among accounting BPOs, payroll processors, SaaS providers, cybersecurity companies, and data centers, among others.

Only a certified public accounting firm (CPA firm), registered and with an active license from a State Board of Accountancy, in compliance with AICPA attestation standards, can issue a valid SOC report under SSAE 18.

Yes. Although SOC standards are defined by the AICPA in the United States, they are widely recognized and requested internationally. We serve service and technology companies across the United States and all of Latin America, in both English and Spanish.

SOC 1 evaluates a service organization's internal controls relevant to financial reporting (ICFR), demonstrating the reliability of your processes when they affect your clients' financial statements. Their external auditors typically require it when your service impacts the accounting or financial records they report on.

SOC 1 Type I evaluates the design and implementation of controls as of a specific date. SOC 1 Type II evaluates the design, implementation, and operation of controls over a defined period (typically 6 to 12 months), making it the most requested by clients and auditors.

It's common among accounting BPOs, payroll processors, fund administrators, e-invoicing providers, and financial or accounting SaaS companies — in general, any organization whose service impacts its clients' financial records or statements.

It builds trust and credibility with your clients, strengthens your competitive edge, helps you meet contractual and audit requirements, reduces financial and operational risk, and promotes continuous improvement of your internal processes.

Yes. SOC 1 under SSAE 18 is widely recognized and requested internationally. Its approach is consistent with the international ISAE 3402 standard, so when a client requires it, we can structure the engagement to meet both standards with a dual-use report.

SOC 2 is an attestation audit that evaluates internal controls over the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy, over a defined period.

SOC 2 Type I evaluates the design of controls at a specific point in time. SOC 2 Type II also evaluates their effective operation over an observation period (typically 6 to 12 months), and is the most requested by enterprise clients.

It's common among SaaS providers, data centers, cybersecurity companies, and cloud services — any organization that manages or stores its clients' data and needs to demonstrate reliable security and privacy controls.

These are the five criteria defined by the AICPA that a SOC 2 report evaluates: security, availability, processing integrity, confidentiality, and privacy. Security is mandatory; the others are included based on the scope your organization needs.

The SOC 2 report has restricted distribution, generally to clients and their auditors, because it includes sensitive technical detail. If you want to publicly communicate your security posture, the right option is a SOC 3 report.

SOC 3 evaluates the same Trust Services Criteria as SOC 2, but it's a public, simplified version, suitable for unrestricted distribution without exposing sensitive technical detail about your controls.

When you want to communicate your commitment to security and privacy to prospective clients and the general market — for example, on your website — without needing to share the restricted technical detail of the full SOC 2 report.

The process follows four main stages: scope definition, planning and evaluation of control design, operating effectiveness testing over the defined period (for Type II reports), and issuance of the final report with our independent opinion.

It depends on the controls in scope, but typically includes policies and procedures, control matrices, transaction samples, reconciliations, system reports, access and segregation of duties, and evidence of control monitoring and operation.

SOC reports are generally valid for one year and tend to align with your organization's fiscal or reporting periods, so it's recommended to renew the audit each year to maintain the trust of your clients and auditors.

If your company processes, stores, or manages third-party, financial, or any other type of data, your clients are likely to request a SOC report. Our team can review your service structure and recommend the most appropriate standard and scope in an initial consultation.