SOC standards

Choose the report your customers actually need.

SOC reports answer different buyer questions. The right starting point depends on the service you provide, the risks your customers evaluate, and who needs to read the final report.

At a glance

SOC 1, SOC 2 and SOC 3 are not interchangeable.

ReportPrimary focusTypical audienceDistributionFormat
SOC 1Controls relevant to customers’ financial reportingCustomer finance teams, auditors and controllersRestricted useType I or Type II
SOC 2Security, availability, processing integrity, confidentiality and privacySecurity, procurement, risk and enterprise buyersRestricted useType I or Type II
SOC 3High-level assurance using the Trust Services CriteriaPublic audiences and early buyer educationGeneral useNo detailed control testing disclosed
SOC 1

Financial reporting controls

SOC 1 applies when a service organization can affect a customer’s financial statements. Payroll processors, claims administrators, transaction processors and fund administrators are common examples.

Ask for SOC 1 when

  • The service feeds a customer’s financial reporting process.
  • Customer auditors need evidence for internal control over financial reporting.
  • The contract or risk assessment names financial reporting controls.
SOC 2

Trust Services Criteria

SOC 2 is the common procurement report for technology and data service providers. Security is mandatory. Availability, processing integrity, confidentiality and privacy are added when they match the service and customer commitments.

Ask for SOC 2 when

  • The provider stores, processes or transmits sensitive customer data.
  • Security and operational reliability drive the risk review.
  • Enterprise buyers need detailed controls, tests and exceptions.
SOC 3

Public assurance summary

SOC 3 uses the Trust Services Criteria but omits the detailed control descriptions and test results found in SOC 2. It can support public trust, but it does not replace the detailed report during serious diligence.

Use SOC 3 for

  • Public trust and security pages.
  • Early-stage buyer education before an NDA.
  • A general-use assurance statement backed by an examination.
Type I and Type II

Design at a date versus operation over a period

A Type I report evaluates control design at a specified date. A Type II report also evaluates whether controls operated over a review period. Procurement teams often prefer Type II because it includes operating evidence across time.

Before engaging an auditor

  • Confirm the report family and intended audience.
  • Define in-scope systems, services and entities.
  • Agree the criteria, observation period and target delivery date.
  • Ask how exceptions and complementary controls will be handled.
Procurement rule

Match evidence to the risk question.

A logo is not a report, and one SOC report does not automatically answer every diligence question. SOC2Market tracks the report named by a public source, the evidence date, the provider relationship and the confidence of each observation.

SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement