Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
SOC 1 vs SOC 2

SOC 1 vs SOC 2: which report do your customers need?

SOC 1 covers controls relevant to customers' financial reporting; SOC 2 covers security, availability, processing integrity, confidentiality and privacy. Who needs which, and how both run on one evidence base.

The short answer

A SOC 1 report covers the controls at a service organization that affect its customers' financial statements, and it is read by the customers' financial auditors. A SOC 2 report covers controls against the Trust Services Criteria, security first, and it is read by customers' security and procurement teams. If your service touches your customers' numbers, payroll, billing, payments, claims, you need SOC 1; if customers ask how you protect their data, you need SOC 2; financial SaaS usually needs both.

Side by side

SOC 1 and SOC 2, row by row

SOC 1SOC 2
SubjectControls relevant to customers' internal control over financial reportingControls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, privacy
StandardSSAE 18, AT-C section 320 (ISAE 3402 internationally)SSAE 18, AT-C section 205, with the AICPA Trust Services Criteria
Who reads itCustomers' financial auditors and finance teamsCustomers' security, procurement and risk teams
Typical providersPayroll, billing, payments, claims, fund administration, financial SaaSAny SaaS or service provider handling customer data
TypesType 1 and Type 2Type 1 and Type 2
With ViglynControl objectives defined with our practitioners; the examination in the platformContinuous checks against the criteria; the examination in the platform
Straight answers

The questions that decide it

Can one report cover both?

No; they are different reports with different criteria and readers, though the same CPA firm can issue both and the security evidence overlaps heavily. In Viglyn one evidence base feeds both examinations.

Which should a financial SaaS company get first?

Whichever your customers are asking for first. Their auditors drive SOC 1 requests, usually around their year end; their security teams drive SOC 2 requests, usually during procurement. Many start with SOC 2 for sales and add SOC 1 when the first auditor asks.

Are the audits very different?

The SOC 1 auditor tests the control objectives you set for financial reporting, often around processing, reconciliation and change; the SOC 2 auditor tests against the Trust Services Criteria. Access, change management and logging evidence serves both, which is where the saving is.

FAQ

More questions

What is SOC 3?
A short, general-use summary of a SOC 2 examination that can be published openly, without the detailed description and test results. It is useful for a trust center; the SOC 2 itself stays under NDA.
Do SOC 1 reports expire?
Customers' auditors want a report covering their fiscal period, so a Type 2 is typically issued annually with a bridge letter covering the gap to the customer's year end.
How much do they cost with Viglyn?
Both count as frameworks included in your plan, from $2,699 a year with implementation by our practitioners. The CPA firm's fees are separate and paid by you directly; we take no commission.

Find out which one you are closer to

A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.