Home SOC reports SOC 1
SOC 1 · SSAE 18 · Type I & Type II

Your client's auditor is asking about your controls.

A SOC 1 report answers them once, in the form they are required to accept. It covers the controls at your organization that affect your clients' financial reporting — issued under SSAE 18 by a licensed CPA firm.

A Assurion
Independent service auditor's report
SOC 1 Type II
Controls relevant to user entities' internal control over financial reporting.
Period covered1 Jan – 31 Dec
Subservice methodCarve-out
OpinionUnqualified
Issued in the firm's name
AT-C 320
SSAE 18
Do you need one

If your work lands in someone else's ledger, you probably do.

SOC 1 exists because your client's auditor cannot sign off on financial statements without understanding the controls at the service organizations that process those numbers. Any of these usually triggers a request:

You run payroll or benefits

Wages, withholding and accruals land directly in your client's compensation expense.

You move or hold money

Payment processing, collections, treasury or lockbox services affecting cash and receivables.

You service loans or leases

Balances, interest calculations and delinquency status feed the carrying value on their books.

You administer claims

Claims handling drives reserves and incurred loss, which auditors and regulators both test.

You keep their books

Outsourced accounting, close support or billing operations that produce the ledger itself.

You host the system of record

An ERP, billing or subledger platform where the data itself is financially significant.

SOC 1 or SOC 2

Two different reports, two different readers.

Plenty of organizations need both, and a request for "your SOC report" often means the sender has not checked which. The distinction is who relies on it.

SOC 1
Subject
Controls over financial reporting
Who reads it
Your client's external auditor, their controller and CFO
What triggers it
Their audit — so timing follows their year end
Control criteria
You define the control objectives; we assess whether they are suitably stated
Distribution
Restricted to you, your clients and their auditors
SOC 2
Subject
Security, availability, confidentiality, processing integrity, privacy
Who reads it
Security teams, procurement and vendor-risk reviewers
What triggers it
A deal, a renewal or a diligence deadline
Control criteria
Fixed AICPA trust services criteria
Distribution
Restricted, though SOC 3 gives you a public version

Where both apply, we scope them together: shared controls are tested once and reported into each engagement separately.

See the SOC 2 page →
Type I and Type II

Design, or design and operation.

Type I

A point in time.

Whether your controls are suitably designed as at one date.

Useful when a client asks mid-year, or when this is your first report and you want the design confirmed before committing to a period. It does not tell the reader that the controls worked, only that they are capable of working.

Typical duration: 6–8 weeks from kickoff.
Type II What auditors want

A period of time.

Whether they were designed properly and operated effectively across a stated period.

This is the one your clients' auditors can actually place reliance on, because it includes our tests of operating effectiveness and the results. Most organizations settle into an annual cycle with a period that lines up with their clients' year ends.

Typical period: 6 or 12 months, plus 8–10 weeks of fieldwork and reporting.

On bridge letters. When a client's year end falls after your report period closes, they will ask you to cover the gap. We issue a bridge letter as part of the engagement — but it is a statement from management, not an audit opinion, and a gap longer than about three months usually means the period needs moving rather than bridging.

How it runs

Scoped backwards from your clients’ year ends.

A SOC 1 is not driven by your sales cycle. We plan the period so the report lands before the auditors who need it start their fieldwork.

01 · Week 1

Scoping call

Which services are in scope, which of your clients are asking, and when their auditors need it.

02 · Weeks 2–4

Control objectives

You state what your controls are meant to achieve. We draft with you and assess whether it is complete.

03 · Before testing

Assertion & period

Management signs its written assertion, the description is finalized and the reporting period is fixed.

04 · 8–10 weeks

Testing

Samples selected and tested against each objective, in batched requests on a published schedule.

05 · Issued

Report & next period

Signed report, a description you can reuse, and next year's period agreed at close-out.

What you receive

A report their auditor can rely on, and reuse next year.

All included in a standard engagement.

The signed report

Our opinion, your system description, and the tests performed with results — the full four-section report.

A drafted system description

The hardest part of a first SOC 1. We work through it with you rather than sending a template.

Complementary user entity controls

The controls your clients must run at their end, stated clearly so responsibility is unambiguous.

A control matrix you keep

Objectives, controls and evidence sources in a spreadsheet you own and reuse each cycle.

Bridge letter

Issued on request to cover the gap between your period end and a client's year end.

Next period's calendar

Period and fieldwork dates agreed at close-out, planned around your clients' year ends.

Why us for a SOC 1

We are accountants first.

SOC 1 is a financial-reporting engagement. It rewards a firm that already understands close processes, journal entries and where misstatement actually comes from — not one that treats it as SOC 2 with different headings.

The same firm keeps books

Our accounting practice works in US GAAP close cycles daily, so control objectives get written in language a controller recognizes.

Your lead signs the report

You meet the practitioner before the engagement letter, and they stay on it until issue.

Independence held properly

Where we already provide accounting services, we set out in writing what we can and cannot examine before you sign.

Questions

What controllers ask us.

Email if yours is not here. We reply within one business day, and we will say so if we are not the right firm for the work.

contact@assurionservices.com
Our client just asks for "a SOC report". Which one?

Ask who wants it. If the request came from their finance team or their external auditor, it is almost always SOC 1. If it came from security or procurement, it is SOC 2. If nobody is sure, send us the request and we will tell you which one satisfies it.

Who writes the control objectives?

You do — that is how SOC 1 works, and it is also its advantage over a fixed-criteria report. In practice we draft alongside you, because a first-time description tends to be either too broad to test or too narrow to satisfy an auditor. Our role is then to assess whether the objectives are suitably stated and complete.

Can you audit us if you also do our bookkeeping?

Sometimes, and sometimes not — it depends on which processes are in scope. We will not test a control we operate for you. Where the overlap is limited we can carve it out; where it is central, the honest answer is that you need a different firm for the examination, and we will say so before you spend money with us.

What if we use subservice organizations?

You choose the inclusive method, where their controls sit inside your report and get tested, or the carve-out method, where they are excluded and identified. Carve-out is more common and cheaper; inclusive is stronger for the reader. We decide with you at scoping, since it changes both cost and what your clients' auditors have to do.

Is a qualified opinion the end of the world?

No, though it needs explaining. Exceptions get described with context and with management’s response alongside them, which is usually what a reader needs. You will hear about anything we find during walkthroughs or testing, not for the first time in the draft report.

Fees

What a SOC 1 costs.

Quoted individually, in writing, before anything is payable. There is no rate card — a SOC 1 for a two-process payroll bureau and one for a multi-platform loan servicer are not the same engagement.

What determines your fee

Control objectives

How many objectives your description states, and how many controls sit under each.

Processes in scope

Which services your clients rely on, and how many systems carry them.

Type I or Type II

A point-in-time opinion is materially less work than testing across a 6 or 12 month period.

Subservice organizations

Carve-out is the cheaper default; the inclusive method adds testing.

Number of user entities

How many clients and auditors will rely on the report.

First cycle or renewal

Renewals cost materially less; the matrix and evidence sources carry over.

Submitting a request and the scoping call are both free, and no card details are taken at either point. You receive a written fixed-fee proposal within three business days of the call — a single amount in US dollars, exclusive of applicable taxes, covering a stated scope and timeline. You are invoiced only after signing an engagement letter, and only for the fee stated in it. No subscriptions, no automatic renewals.

See how we price, our fees, payment, refunds and cancellation policy and terms of service. Please read both before submitting a request or making a payment.

Get started

Send us the request you received.

A call with the practitioner who would lead the work, for as long as it takes. Bring your client's request and their year end, and you will leave with a scope, a period and a written fixed-fee proposal.

Phone · Mon–Fri, 9–6 ET
+1 (307) 393-9419
Corporate office
Suite 413, 1603 Capitol Ave
Cheyenne, WY 82001
SOC 1