Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In current AICPA usage, SOC stands for System and Organization Controls. “Service Organization Control” is the older expansion, which is why both phrases still appear. SOC refers to a suite of CPA services and reports—not a blanket certification that a company is compliant in every context.

What does SOC mean?

The AICPA describes SOC as “a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations.” The AICPA introduced the broader name System and Organization Controls in 2017; older material may use Service Organization Control.

A service organization provides a service that can affect another organization’s financial reporting, systems, data, or risk management. A CPA examination report gives intended users information and assurance about relevant controls so they can assess risks associated with that outsourced service. The report addresses its defined subject matter and scope; it is not a universal approval of the provider.

AICPA & CIMA’s SOC resource page describes the suite and links to reporting resources. The terminology change is also noted in the AICPA’s peer-review standards materials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do SOC 1, SOC 2, and SOC 3 differ?

Report What it covers Typical reader or use Level of detail
SOC 1 Controls at a service organization relevant to user entities’ internal control over financial reporting. User-entity management and auditors evaluating financial-reporting controls. Consult the report for its specific scope and information.
SOC 2 Controls assessed against applicable Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A given report need not cover all five. Readers assessing system controls against the criteria included in the report. Detailed description and test results.
SOC 3 Assurance related to Trust Services Criteria. Readers who do not need the detailed SOC 2 report; the AICPA notes SOC 3 can be used in marketing. Less detailed than SOC 2.

The distinctions and intended uses are described in AICPA & CIMA’s SOC materials and its SOC suite flyer.

Which SOC report should you look for?

  • If your question concerns how a provider’s controls affect financial reporting, start with SOC 1.
  • If you need system-control assurance against Trust Services Criteria, look for SOC 2 or SOC 3. SOC 2 is the more detailed option; SOC 3 is less detailed and intended for readers who do not need that fuller report.

These are starting points, not substitutes for checking a particular report. Read its scope and intended users to confirm that it addresses the service and risks you care about.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you check in a SOC report?

The SOC label alone does not tell you exactly what was examined. In the report, identify the report type, the system or service boundaries, the applicable criteria, the period covered, and the intended users. For SOC 2, check which Trust Services Criteria categories are included rather than assuming all five apply. A report’s conclusions should be understood in light of those boundaries and its stated subject matter.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.