SOC 1 (SSAE 18 / ISAE 3402)
A SOC 1 report is a service auditor's report on the controls at a service organization relevant to user entities' internal control over financial reporting, issued under AT-C section 320 of the AICPA's SSAE 18 (as amended by SSAE 21 and 23) in the United States and under the IAASB's ISAE 3402 internationally, as a Type 1 (design at a point in time) or Type 2 (design and operating effectiveness over a period) report. The graph models the 37 report elements the two standards fix, each citing its AT-C 320 and ISAE 3402 paragraphs, with the objective areas a service organization commonly reports on as an index.
SOC 1 (SSAE 18 / ISAE 3402) is a compliance framework from United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities with 4 domains and 37 controls that map to 6 other frameworks. The largest domains are The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402) (12 controls), The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402) (10 controls), Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402) (8 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)
| Code | Title |
|---|---|
| soc-1-ssae-18::C.1 | SOC 1 C.1 Control objectives that are reasonable in the circumstances and relevant to user entities' financial reporting |
| soc-1-ssae-18::C.2 | SOC 1 C.2 Controls suitably designed: risks identified and the controls, if operating effectively, giving reasonable assurance the objectives are achieved |
| soc-1-ssae-18::C.3 | SOC 1 C.3 Controls implemented and, in a type 2 report, operating effectively throughout the period |
| soc-1-ssae-18::C.4 | SOC 1 C.4 Deviations investigated, explained and remediated, with fraud and noncompliance assessed for their effect |
| soc-1-ssae-18::C.5 | SOC 1 C.5 Information produced by the service organisation that the auditor relies on is accurate, complete and sufficiently precise |
| soc-1-ssae-18::C.6 | SOC 1 C.6 Internal audit reports and regulatory examination reports relating to the services made available |
| soc-1-ssae-18::C.7 | SOC 1 C.7 Changes to controls during the period managed so that superseded controls can be tested and the changes described |
Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402)
| Code | Title |
|---|---|
| soc-1-ssae-18::A.1 | SOC 1 A.1 Engage an independent service auditor under AT-C 320 or ISAE 3402, choose type 1 or type 2, and define the system, the services and the period or date |
| soc-1-ssae-18::A.2 | SOC 1 A.2 Accept responsibility for the description and the assertion, including their completeness, accuracy and method of presentation |
| soc-1-ssae-18::A.3 | SOC 1 A.3 Have a reasonable basis for the assertion |
| soc-1-ssae-18::A.4 | SOC 1 A.4 Select the criteria and state them in the assertion |
| soc-1-ssae-18::A.5 | SOC 1 A.5 Specify the control objectives in the description and name any party that specified them |
| soc-1-ssae-18::A.6 | SOC 1 A.6 Identify the risks that threaten the control objectives and design, implement and document controls that achieve them |
| soc-1-ssae-18::A.7 | SOC 1 A.7 Provide the written assertion with the description to user entities |
| soc-1-ssae-18::A.8 | SOC 1 A.8 Give the service auditor all relevant information and unrestricted access to people |
The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402)
| Code | Title |
|---|---|
| soc-1-ssae-18::D.1 | SOC 1 D.1 Management's written assertion in the form Exhibit B illustrates |
| soc-1-ssae-18::D.10 | SOC 1 D.10 Use of the report by user entities and their auditors, and the user entity's own complementary controls |
| soc-1-ssae-18::D.2 | SOC 1 D.2 Written representations, including disclosure of noncompliance, fraud, design deficiencies and subsequent events; refusal is a scope limitation |
| soc-1-ssae-18::D.3 | SOC 1 D.3 Subsequent events up to the report date disclosed |
| soc-1-ssae-18::D.4 | SOC 1 D.4 Other information provided by the service organisation kept consistent with the description and clearly outside the opinion |
| soc-1-ssae-18::D.5 | SOC 1 D.5 The report package: the service auditor's report, management's assertion, the description, the objectives with the controls, tests and results, and other information |
| soc-1-ssae-18::D.6 | SOC 1 D.6 Restricted use: the report is intended solely for user entities, their auditors and the service organisation's management |
| soc-1-ssae-18::D.7 | SOC 1 D.7 Modified opinions: their grounds and what a qualified, adverse or disclaimed opinion means for the service organisation and its user entities |
| soc-1-ssae-18::D.8 | SOC 1 D.8 Communication of noncompliance, fraud or uncorrected misstatements that may affect user entities |
| soc-1-ssae-18::D.9 | SOC 1 D.9 Bridge letters between report periods |
The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402)
| Code | Title |
|---|---|
| soc-1-ssae-18::B.1 | SOC 1 B.1 Describe the types of services provided and the classes of transactions processed |
| soc-1-ssae-18::B.10 | SOC 1 B.10 Describe the other relevant aspects of the control environment, risk assessment, information and communication, control activities and monitoring |
| soc-1-ssae-18::B.11 | SOC 1 B.11 In a type 2 report, describe the relevant changes to the system during the period |
| soc-1-ssae-18::B.12 | SOC 1 B.12 Omit and distort nothing relevant, while writing for the common needs of a broad range of user entities |
| soc-1-ssae-18::B.2 | SOC 1 B.2 Describe the procedures by which transactions are initiated, authorised, recorded, processed, corrected and reported |
| soc-1-ssae-18::B.3 | SOC 1 B.3 Describe the information and records used in performing the procedures |
| soc-1-ssae-18::B.4 | SOC 1 B.4 Describe how the system captures and addresses significant events and conditions other than transactions |
| soc-1-ssae-18::B.5 | SOC 1 B.5 Describe the process used to prepare reports and other information for user entities |
| soc-1-ssae-18::B.6 | SOC 1 B.6 Describe the subservice organisations used and whether the carve-out or the inclusive method applies |
| soc-1-ssae-18::B.7 | SOC 1 B.7 State the control objectives and the controls designed to achieve them |
| soc-1-ssae-18::B.8 | SOC 1 B.8 Identify the complementary user entity controls assumed in the design of the service organisation's controls |
| soc-1-ssae-18::B.9 | SOC 1 B.9 Identify the complementary subservice organisation controls assumed under the carve-out method |
Your Compliance Coverage
If you comply with SOC 1 (SSAE 18 / ISAE 3402), you already cover:
ISO 27018:2019
6%
4 controls mapped
Compare →ISO 27002:2022
4%
3 controls mapped
Compare →ISO 22000:2018
1%
1 controls mapped
Compare →+ 3 more: ISO 9001:2015 (1%), ISO 13485:2016 (1%)
See all 6 mapped frameworks ↓Maps to 6 other frameworks
Coverage is not the same as your position
This page shows what SOC 1 (SSAE 18 / ISAE 3402) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is SOC 1 (SSAE 18 / ISAE 3402) and who does it apply to?
SOC 1 (SSAE 18 / ISAE 3402) is a compliance framework from United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities with 4 domains and 37 controls. A SOC 1 report is a service auditor's report on the controls at a service organization relevant to user entities' internal control over financial reporting, issued under AT-C section 320 of the AICPA's SSAE 18 (as amended by SSAE 21 and 23) in the United States and under the IAASB's ISAE 3402 internationally, as a Type 1 (design at a point in time) or Type 2 (design and operating effectiveness over a period) report. The graph models the 37 report elements the two standards fix, each citing its AT-C 320 and ISAE 3402 paragraphs, with the objective areas a service organization commonly reports on as an index. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does SOC 1 (SSAE 18 / ISAE 3402) actually require?
SOC 1 (SSAE 18 / ISAE 3402) has 37 controls organised across 4 domains. The largest domains are The description of the system (the description criteria) – SOC 1 (SSAE 18 / ISAE 3402) (12 controls), The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402) (10 controls), Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402) (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of SOC 1 (SSAE 18 / ISAE 3402) do I already cover?
SOC 1 (SSAE 18 / ISAE 3402) maps to 6 other compliance frameworks. The top mapping partners are ISO 27018:2019 (6% coverage), ISO 27002:2022 (4% coverage), ISO 22000:2018 (1% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement SOC 1 (SSAE 18 / ISAE 3402)?
Start your SOC 1 (SSAE 18 / ISAE 3402) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SOC 1 (SSAE 18 / ISAE 3402) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required