SOC 1 vs SOC 2 vs SOC 3: What’s the Difference?
SOC 1, SOC 2, and SOC 3 are AICPA attestation reports that differ by subject matter and audience. SOC 1 examines controls relevant to customers’ internal control over financial reporting (ICFR). SOC 2 evaluates security and related Trust Services Criteria in a detailed, restricted-use report. SOC 3 summarizes a SOC 2 examination in a short, general-use report anyone can read.
- SOC 1 addresses controls likely to affect user entities’ internal control over financial reporting (ICFR) and is written for customers and their financial statement auditors.
- SOC 2 evaluates controls against the AICPA Trust Services Criteria — Security (mandatory), plus optional Availability, Processing Integrity, Confidentiality, and Privacy — in a detailed, restricted-use report.
- SOC 3 covers the same Trust Services Criteria but omits control-level test detail, is always a Type 2 examination, and can be distributed publicly — making it a marketing asset.
- SOC 1 and SOC 2 both come in Type 1 (design at a point in time) and Type 2 (operating effectiveness over a period, typically 3-12 months) versions.
- Many service organizations need both SOC 1 and SOC 2 — for example, a payroll platform whose service affects customers’ financials and whose buyers also demand security assurance.
What Are SOC Reports?
System and Organization Controls (SOC) reports are independent attestation reports issued by licensed CPA firms under standards set by the American Institute of Certified Public Accountants (AICPA). The AICPA describes SOC as a suite of offerings CPAs provide “in connection with system-level controls of a service organization,” giving customers the information they need to assess the risks of outsourcing.
The suite exists because outsourcing concentrates risk. When a company hands payroll, claims processing, or cloud hosting to a vendor, that vendor’s control failures become the company’s problem. SOC reports let one independent examination serve many customers instead of every customer auditing the vendor separately.
All three service-organization reports — SOC 1, SOC 2, and SOC 3 — are performed under the AICPA’s attestation standards (SSAE No. 18 and its successors). SOC 1 engagements follow AT-C section 320, while SOC 2 and SOC 3 fall under AT-C sections 105 and 205. Note that these are attestation engagements governed by AICPA standards, not audits of public-company financial statements — a distinction we cover in our comparison of the PCAOB vs. the AICPA.
The numbering is not a maturity ladder. SOC 2 is not “harder” than SOC 1, and SOC 3 is not the top tier. Each report answers a different question for a different reader.
What Is a SOC 1 Report?
A SOC 1 report addresses financial reporting risk. Per the AICPA’s definition, SOC 1 is “an examination of controls at a service organization that are likely to be relevant to user entities’ internal control over financial reporting” (ICFR). Its intended readers are the customer organizations (user entities) and the CPAs who audit those customers’ financial statements (user auditors).
In practice, a SOC 1 matters when your service touches numbers that flow into customers’ financial statements. Classic examples include payroll processors, medical claims administrators, fund administrators, loan servicers, and trust departments. A public company’s external auditor will often ask for the SOC 1 Type 2 reports of such vendors during the annual audit, because those vendors’ controls sit inside the audit scope.
Instead of a fixed criteria set, management defines control objectives — for example, that transactions are processed completely, accurately, and timely — and the service auditor tests the controls that support them. SOC 1 comes in two flavors:
- Type 1: The auditor opines on whether controls are suitably designed and implemented as of a specific date.
- Type 2: The auditor also tests operating effectiveness over a period, typically 3 to 12 months, and reports the tests performed and their results.
SOC 1 reports are restricted-use documents: they are intended for management, existing customers, and their auditors, and are normally shared under NDA rather than published.
What Is a SOC 2 Report?
A SOC 2 report addresses operational and security risk rather than financial reporting risk. The examination measures a service organization’s controls against the AICPA’s Trust Services Criteria — the 2017 Trust Services Criteria (with revised points of focus, 2022) — organized into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Only Security (the “common criteria,” aligned to the COSO 2013 internal control framework) is mandatory; the other four categories are added based on the commitments the organization makes to customers. Our breakdown of the SOC 2 trust principles explains how to choose which categories to include.
Like SOC 1, SOC 2 offers a Type 1 (design at a point in time) and a Type 2 (operating effectiveness over a review period, with detailed test procedures and results). Buyers overwhelmingly prefer Type 2 because it proves controls actually operated, not just that they existed on paper.
SOC 2 has become the default trust currency for SaaS, cloud, and managed service providers: security teams, procurement, and vendor risk managers read the full report — system description, control matrix, test results, and exceptions — before signing or renewing contracts. It remains a restricted-use report, typically shared under NDA. For a full walkthrough of scoping, readiness, and the audit itself, see our complete guide to SOC 2 compliance.
What Is a SOC 3 Report?
A SOC 3 report is the public-facing sibling of SOC 2. The AICPA titles it “Trust Services Criteria for General Use Report”: it covers the same Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria as SOC 2, but as the AICPA notes, SOC 3 reports “do not provide the same level of detail,” so “they are considered general use reports and can be freely distributed.”
Three practical consequences follow from that design:
- No test detail. A SOC 3 contains the auditor’s opinion, management’s assertion, and an abbreviated system description — but not the control-by-control test procedures and results that make a SOC 2 useful for vendor due diligence, as Linford & Co explains.
- Always Type 2. A SOC 3 is derived from a Type 2 examination over a period; there is no SOC 3 Type 1.
- Marketing-friendly. Because it is unrestricted, you can post it on your website or trust center. AWS, for example, publishes its SOC 3 as a freely downloadable whitepaper while keeping SOC 1 and SOC 2 behind an NDA in AWS Artifact.
A SOC 3 is almost never produced on its own — it is an inexpensive add-on to a SOC 2 Type 2 engagement. If you are wondering what you can share publicly from your SOC program, see our post on whether SOC 2 reports are public information.
SOC 1 vs SOC 2 vs SOC 3: Side-by-Side Comparison
Here is how the three reports compare across the dimensions that matter when a customer or auditor asks for one.
| Dimension | SOC 1 | SOC 2 | SOC 3 |
|---|---|---|---|
| Core question | Could this vendor’s controls affect our financial statements? | Does this vendor protect the systems and data we entrust to it? | Same as SOC 2, answered at a summary level for the public |
| Control focus | Internal control over financial reporting (ICFR); management-defined control objectives | Trust Services Criteria: Security (required) + optional Availability, Processing Integrity, Confidentiality, Privacy | Same Trust Services Criteria as the underlying SOC 2 |
| Governing standard | AT-C section 320 (SSAE 18) | AT-C sections 105 & 205; TSP section 100 | AT-C sections 105 & 205; TSP section 100 |
| Primary audience | Customer management and their financial statement auditors | Customer security, procurement, and vendor risk teams; regulators; management | General public, prospects, marketing use |
| Distribution | Restricted use (NDA) | Restricted use (NDA) | General use — freely distributable |
| Report types | Type 1 or Type 2 | Type 1 or Type 2 | Always based on a Type 2 examination |
| Detail level | Full system description, controls, and (Type 2) test results | Full system description, controls, and (Type 2) test results | Opinion and short description only; no test detail |
| Typical organizations | Payroll, claims, and payment processors; fund administrators; loan servicers | SaaS, cloud, data centers, MSPs/MSSPs, any data-handling vendor | SOC 2-audited organizations that want public proof |
Which SOC Report Do You Need?
Let your customers’ questions decide. If their auditors ask how your service affects their financial statements, you need a SOC 1. If their security and vendor risk teams send questionnaires about encryption, access control, and incident response, you need a SOC 2 — our post on who needs SOC 2 compliance walks through the common triggers. If sales wants public proof of the SOC 2 without NDAs, add a SOC 3.
Many organizations need more than one. A payroll SaaS provider is the textbook case: its calculations flow into customers’ financial statements (SOC 1) and it stores sensitive employee data in the cloud (SOC 2). The two examinations can be run by the same firm on aligned timelines, and a SOC 3 can be issued off the back of the SOC 2 Type 2.
The commercial stakes keep rising. Third-party involvement in breaches doubled to 30% of cases in the past year, according to Verizon’s 2025 Data Breach Investigations Report, and IBM’s 2025 Cost of a Data Breach Report puts the average breach at $4.44 million globally and $10.22 million in the United States. Buyers respond by demanding audited evidence — not questionnaire answers — before trusting a vendor.
Whichever report you pursue, the work underneath is the same discipline: defined controls, assigned owners, and evidence that controls operate all year, not just during audit fieldwork. Type 2 examinations in particular reward organizations that collect evidence continuously instead of scrambling each audit season.
Frequently asked questions
Is SOC 2 better than SOC 1?
Can a company have both a SOC 1 and a SOC 2 report?
Is a SOC 3 report the same as a SOC 2 report?
Does a SOC 3 report come in Type 1 and Type 2?
Are SOC reports certifications?
Who can perform a SOC audit?
- AICPA & CIMA — SOC 1: SOC for Service Organizations: ICFR
- AICPA & CIMA — SOC 3: Trust Services Criteria for General Use Report
- AICPA & CIMA — System and Organization Controls: SOC Suite of Services
- AICPA & CIMA — 2017 Trust Services Criteria (With Revised Points of Focus — 2022)
- AICPA & CIMA — SOC for Service Organizations Engagements: Overview
- AWS — SOC Compliance FAQs
- Verizon — 2025 Data Breach Investigations Report
- IBM — 2025 Cost of a Data Breach Report
- Linford & Co — SOC 2 vs SOC 3 Reports: What Is the Difference?
Get SOC 1, SOC 2, and SOC 3 Ready with Compyl
Compyl’s agentic GRC platform maps your controls to the Trust Services Criteria and SOC 1 control objectives, automates evidence collection year-round, and keeps you audit-ready for Type 2 examinations. Book a demo to see how teams cut SOC prep time dramatically.
About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.