Back to Frameworks

SOC 1 (SSAE 18 / ISAE 3402)

United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities
vSSAE 18 AT-C 320 (reports dated on or after 1 May 2017) and ISAE 3402 (periods ending on or after 15 June 2011)
4 domains
37 controls

A SOC 1 report is a service auditor's report on the controls at a service organization relevant to user entities' internal control over financial reporting, issued under AT-C section 320 of the AICPA's SSAE 18 (as amended by SSAE 21 and 23) in the United States and under the IAASB's ISAE 3402 internationally, as a Type 1 (design at a point in time) or Type 2 (design and operating effectiveness over a period) report. The graph models the 37 report elements the two standards fix, each citing its AT-C 320 and ISAE 3402 paragraphs, with the objective areas a service organization commonly reports on as an index.

Verified

SOC 1 (SSAE 18 / ISAE 3402) is a compliance framework from United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities with 4 domains and 37 controls that map to 6 other frameworks. The largest domains are The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402) (12 controls), The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402) (10 controls), Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402) (8 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

7 controls
Controls in the Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402) domain of SOC 1 (SSAE 18 / ISAE 3402) — 7 controls
CodeTitle
soc-1-ssae-18::C.1SOC 1 C.1 Control objectives that are reasonable in the circumstances and relevant to user entities' financial reporting
soc-1-ssae-18::C.2SOC 1 C.2 Controls suitably designed: risks identified and the controls, if operating effectively, giving reasonable assurance the objectives are achieved
soc-1-ssae-18::C.3SOC 1 C.3 Controls implemented and, in a type 2 report, operating effectively throughout the period
soc-1-ssae-18::C.4SOC 1 C.4 Deviations investigated, explained and remediated, with fraud and noncompliance assessed for their effect
soc-1-ssae-18::C.5SOC 1 C.5 Information produced by the service organisation that the auditor relies on is accurate, complete and sufficiently precise
soc-1-ssae-18::C.6SOC 1 C.6 Internal audit reports and regulatory examination reports relating to the services made available
soc-1-ssae-18::C.7SOC 1 C.7 Changes to controls during the period managed so that superseded controls can be tested and the changes described

Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402)

8 controls
Controls in the Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402) domain of SOC 1 (SSAE 18 / ISAE 3402) — 8 controls
CodeTitle
soc-1-ssae-18::A.1SOC 1 A.1 Engage an independent service auditor under AT-C 320 or ISAE 3402, choose type 1 or type 2, and define the system, the services and the period or date
soc-1-ssae-18::A.2SOC 1 A.2 Accept responsibility for the description and the assertion, including their completeness, accuracy and method of presentation
soc-1-ssae-18::A.3SOC 1 A.3 Have a reasonable basis for the assertion
soc-1-ssae-18::A.4SOC 1 A.4 Select the criteria and state them in the assertion
soc-1-ssae-18::A.5SOC 1 A.5 Specify the control objectives in the description and name any party that specified them
soc-1-ssae-18::A.6SOC 1 A.6 Identify the risks that threaten the control objectives and design, implement and document controls that achieve them
soc-1-ssae-18::A.7SOC 1 A.7 Provide the written assertion with the description to user entities
soc-1-ssae-18::A.8SOC 1 A.8 Give the service auditor all relevant information and unrestricted access to people

The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402)

10 controls
Controls in the The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402) domain of SOC 1 (SSAE 18 / ISAE 3402) — 10 controls
CodeTitle
soc-1-ssae-18::D.1SOC 1 D.1 Management's written assertion in the form Exhibit B illustrates
soc-1-ssae-18::D.10SOC 1 D.10 Use of the report by user entities and their auditors, and the user entity's own complementary controls
soc-1-ssae-18::D.2SOC 1 D.2 Written representations, including disclosure of noncompliance, fraud, design deficiencies and subsequent events; refusal is a scope limitation
soc-1-ssae-18::D.3SOC 1 D.3 Subsequent events up to the report date disclosed
soc-1-ssae-18::D.4SOC 1 D.4 Other information provided by the service organisation kept consistent with the description and clearly outside the opinion
soc-1-ssae-18::D.5SOC 1 D.5 The report package: the service auditor's report, management's assertion, the description, the objectives with the controls, tests and results, and other information
soc-1-ssae-18::D.6SOC 1 D.6 Restricted use: the report is intended solely for user entities, their auditors and the service organisation's management
soc-1-ssae-18::D.7SOC 1 D.7 Modified opinions: their grounds and what a qualified, adverse or disclaimed opinion means for the service organisation and its user entities
soc-1-ssae-18::D.8SOC 1 D.8 Communication of noncompliance, fraud or uncorrected misstatements that may affect user entities
soc-1-ssae-18::D.9SOC 1 D.9 Bridge letters between report periods

The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402)

12 controls
Controls in the The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402) domain of SOC 1 (SSAE 18 / ISAE 3402) — 12 controls
CodeTitle
soc-1-ssae-18::B.1SOC 1 B.1 Describe the types of services provided and the classes of transactions processed
soc-1-ssae-18::B.10SOC 1 B.10 Describe the other relevant aspects of the control environment, risk assessment, information and communication, control activities and monitoring
soc-1-ssae-18::B.11SOC 1 B.11 In a type 2 report, describe the relevant changes to the system during the period
soc-1-ssae-18::B.12SOC 1 B.12 Omit and distort nothing relevant, while writing for the common needs of a broad range of user entities
soc-1-ssae-18::B.2SOC 1 B.2 Describe the procedures by which transactions are initiated, authorised, recorded, processed, corrected and reported
soc-1-ssae-18::B.3SOC 1 B.3 Describe the information and records used in performing the procedures
soc-1-ssae-18::B.4SOC 1 B.4 Describe how the system captures and addresses significant events and conditions other than transactions
soc-1-ssae-18::B.5SOC 1 B.5 Describe the process used to prepare reports and other information for user entities
soc-1-ssae-18::B.6SOC 1 B.6 Describe the subservice organisations used and whether the carve-out or the inclusive method applies
soc-1-ssae-18::B.7SOC 1 B.7 State the control objectives and the controls designed to achieve them
soc-1-ssae-18::B.8SOC 1 B.8 Identify the complementary user entity controls assumed in the design of the service organisation's controls
soc-1-ssae-18::B.9SOC 1 B.9 Identify the complementary subservice organisation controls assumed under the carve-out method

Your Compliance Coverage

If you comply with SOC 1 (SSAE 18 / ISAE 3402), you already cover:

Maps to 6 other frameworks

69 total controls
ISO 27018:2019
4 source controls mapped|3 target controls covered
6%
ISO 27002:2022
3 source controls mapped|2 target controls covered
4%
ISO 22000:2018
1 source controls mapped|1 target controls covered
1%
ISO 9001:2015
1 source controls mapped|1 target controls covered
1%
ISO 13485:2016
1 source controls mapped|1 target controls covered
1%
ISO 22301:2019
1 source controls mapped|2 target controls covered
1%

Coverage is not the same as your position

This page shows what SOC 1 (SSAE 18 / ISAE 3402) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is SOC 1 (SSAE 18 / ISAE 3402) and who does it apply to?

SOC 1 (SSAE 18 / ISAE 3402) is a compliance framework from United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities with 4 domains and 37 controls. A SOC 1 report is a service auditor's report on the controls at a service organization relevant to user entities' internal control over financial reporting, issued under AT-C section 320 of the AICPA's SSAE 18 (as amended by SSAE 21 and 23) in the United States and under the IAASB's ISAE 3402 internationally, as a Type 1 (design at a point in time) or Type 2 (design and operating effectiveness over a period) report. The graph models the 37 report elements the two standards fix, each citing its AT-C 320 and ISAE 3402 paragraphs, with the objective areas a service organization commonly reports on as an index. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does SOC 1 (SSAE 18 / ISAE 3402) actually require?

SOC 1 (SSAE 18 / ISAE 3402) has 37 controls organised across 4 domains. The largest domains are The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402) (12 controls), The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402) (10 controls), Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402) (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of SOC 1 (SSAE 18 / ISAE 3402) do I already cover?

SOC 1 (SSAE 18 / ISAE 3402) maps to 6 other compliance frameworks. The top mapping partners are ISO 27018:2019 (6% coverage), ISO 27002:2022 (4% coverage), ISO 22000:2018 (1% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement SOC 1 (SSAE 18 / ISAE 3402)?

Start your SOC 1 (SSAE 18 / ISAE 3402) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SOC 1 (SSAE 18 / ISAE 3402) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required