SOC 1 vs SOC 2: which report do your customers need?
SOC 1 covers controls relevant to customers' financial reporting; SOC 2 covers security, availability, processing integrity, confidentiality and privacy. Who needs which, and how both run on one evidence base.
The short answer
A SOC 1 report covers the controls at a service organization that affect its customers' financial statements, and it is read by the customers' financial auditors. A SOC 2 report covers controls against the Trust Services Criteria, security first, and it is read by customers' security and procurement teams. If your service touches your customers' numbers, payroll, billing, payments, claims, you need SOC 1; if customers ask how you protect their data, you need SOC 2; financial SaaS usually needs both.
SOC 1 and SOC 2, row by row
| SOC 1 | SOC 2 | |
|---|---|---|
| Subject | Controls relevant to customers' internal control over financial reporting | Controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, privacy |
| Standard | SSAE 18, AT-C section 320 (ISAE 3402 internationally) | SSAE 18, AT-C section 205, with the AICPA Trust Services Criteria |
| Who reads it | Customers' financial auditors and finance teams | Customers' security, procurement and risk teams |
| Typical providers | Payroll, billing, payments, claims, fund administration, financial SaaS | Any SaaS or service provider handling customer data |
| Types | Type 1 and Type 2 | Type 1 and Type 2 |
| With Viglyn | Control objectives defined with our practitioners; the examination in the platform | Continuous checks against the criteria; the examination in the platform |
The questions that decide it
Can one report cover both?
No; they are different reports with different criteria and readers, though the same CPA firm can issue both and the security evidence overlaps heavily. In Viglyn one evidence base feeds both examinations.
Which should a financial SaaS company get first?
Whichever your customers are asking for first. Their auditors drive SOC 1 requests, usually around their year end; their security teams drive SOC 2 requests, usually during procurement. Many start with SOC 2 for sales and add SOC 1 when the first auditor asks.
Are the audits very different?
The SOC 1 auditor tests the control objectives you set for financial reporting, often around processing, reconciliation and change; the SOC 2 auditor tests against the Trust Services Criteria. Access, change management and logging evidence serves both, which is where the saving is.
More questions
What is SOC 3?
Do SOC 1 reports expire?
How much do they cost with Viglyn?
Standards buyers weigh against each other
Find out which one you are closer to
A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.
