SOC 1: the controls your customers' auditors rely on
Run the controls relevant to your customers' financial reporting with automated checks and sealed evidence, and take the SOC 1 Type 1 or Type 2 examination inside Viglyn, with the same auditor workflow as SOC 2.
What is SOC 1?
SOC 1 is an attestation report on the controls at a service organization that are relevant to its customers' internal control over financial reporting, examined by an independent CPA firm under the AICPA's attestation standards (SSAE 18, AT-C section 320). It exists because a customer's financial auditor must understand every system that feeds the customer's accounts, including the ones a vendor runs: payroll, billing, payment processing, claims, fund administration, financial SaaS. The service organization describes its system and the control objectives it has set; the auditor tests the controls against those objectives. A Type 1 report opines on whether the controls were suitably designed at a point in time; a Type 2 tests whether they operated effectively over a period, usually six to twelve months, and is what customers' auditors want. Where SOC 2 is about the Trust Services Criteria, SOC 1 is about the controls a customer's auditor relies on, and the two share most of their underlying evidence.
A SOC 1 report is an independent CPA's examination of the controls at a service organization that are relevant to its customers' internal control over financial reporting, performed under the AICPA's attestation standards. Customers' financial auditors rely on it when the service affects the numbers in the customer's accounts: payroll, billing, payments, claims processing, loan servicing, financial SaaS. Like SOC 2 it comes as a Type 1, controls designed at a point in time, or a Type 2, controls operating over a review period.
Payroll, billing, payments, fund administration, claims and financial SaaS providers whose customers' auditors ask how the service could affect their financial statements.
How Viglyn runs SOC 1
- Control objectives and the controls under them defined with our practitioners, with automated checks where the evidence lives in your systems and structured evidence requests where it does not
- Change management, access, processing and reconciliation evidence collected as the actual system response, hashed at capture
- The system description and the complementary user entity controls held as controlled documents with a full audit trail
- Shared evidence with SOC 2: the security controls are evidenced once and reported twice
- The examination run inside Viglyn, with your CPA firm working through scoped access and workpapers that export with integrity hashes
The SOC 1 questions that decide it
Do we need SOC 1 or SOC 2?
SOC 1 if your service affects your customers' financial statements and their auditors ask about it; SOC 2 if customers ask about security, availability and privacy. Many financial SaaS companies need both, and in Viglyn the shared security controls are evidenced once for the two reports.
How long does SOC 1 take?
A Type 1 is achievable in weeks once the control objectives are defined and the controls exist. A Type 2 reports on a review period, usually six to twelve months, so the real timeline is the period plus the examination. We tell you the honest timeline for your starting point before you commit.
How much does SOC 1 cost with Viglyn?
SOC 1 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The CPA firm's fee is separate and paid by you directly; we take no commission.
SOC 1 against the standards it is weighed with
More SOC 1 questions
What are complementary user entity controls?
Who reads a SOC 1 report?
Is SOC 1 the same as SSAE 18?
See SOC 1 run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
