Compyl
GRC Your Way

SOC 1 vs SOC 2 vs SOC 3: What’s the Difference?

Compyl Research

SOC 1 vs SOC 2 vs SOC 3: What’s the Difference?

By Compyl ResearchLast updated: August 11, 20266 min read

SOC 1, SOC 2, and SOC 3 are AICPA attestation reports that differ by subject matter and audience. SOC 1 examines controls relevant to customers’ internal control over financial reporting (ICFR). SOC 2 evaluates security and related Trust Services Criteria in a detailed, restricted-use report. SOC 3 summarizes a SOC 2 examination in a short, general-use report anyone can read.

Key takeaways
  • SOC 1 addresses controls likely to affect user entities’ internal control over financial reporting (ICFR) and is written for customers and their financial statement auditors.
  • SOC 2 evaluates controls against the AICPA Trust Services Criteria — Security (mandatory), plus optional Availability, Processing Integrity, Confidentiality, and Privacy — in a detailed, restricted-use report.
  • SOC 3 covers the same Trust Services Criteria but omits control-level test detail, is always a Type 2 examination, and can be distributed publicly — making it a marketing asset.
  • SOC 1 and SOC 2 both come in Type 1 (design at a point in time) and Type 2 (operating effectiveness over a period, typically 3-12 months) versions.
  • Many service organizations need both SOC 1 and SOC 2 — for example, a payroll platform whose service affects customers’ financials and whose buyers also demand security assurance.

What Are SOC Reports?

System and Organization Controls (SOC) reports are independent attestation reports issued by licensed CPA firms under standards set by the American Institute of Certified Public Accountants (AICPA). The AICPA describes SOC as a suite of offerings CPAs provide “in connection with system-level controls of a service organization,” giving customers the information they need to assess the risks of outsourcing.

The suite exists because outsourcing concentrates risk. When a company hands payroll, claims processing, or cloud hosting to a vendor, that vendor’s control failures become the company’s problem. SOC reports let one independent examination serve many customers instead of every customer auditing the vendor separately.

All three service-organization reports — SOC 1, SOC 2, and SOC 3 — are performed under the AICPA’s attestation standards (SSAE No. 18 and its successors). SOC 1 engagements follow AT-C section 320, while SOC 2 and SOC 3 fall under AT-C sections 105 and 205. Note that these are attestation engagements governed by AICPA standards, not audits of public-company financial statements — a distinction we cover in our comparison of the PCAOB vs. the AICPA.

The numbering is not a maturity ladder. SOC 2 is not “harder” than SOC 1, and SOC 3 is not the top tier. Each report answers a different question for a different reader.

What Is a SOC 1 Report?

A SOC 1 report addresses financial reporting risk. Per the AICPA’s definition, SOC 1 is “an examination of controls at a service organization that are likely to be relevant to user entities’ internal control over financial reporting” (ICFR). Its intended readers are the customer organizations (user entities) and the CPAs who audit those customers’ financial statements (user auditors).

In practice, a SOC 1 matters when your service touches numbers that flow into customers’ financial statements. Classic examples include payroll processors, medical claims administrators, fund administrators, loan servicers, and trust departments. A public company’s external auditor will often ask for the SOC 1 Type 2 reports of such vendors during the annual audit, because those vendors’ controls sit inside the audit scope.

Instead of a fixed criteria set, management defines control objectives — for example, that transactions are processed completely, accurately, and timely — and the service auditor tests the controls that support them. SOC 1 comes in two flavors:

  • Type 1: The auditor opines on whether controls are suitably designed and implemented as of a specific date.
  • Type 2: The auditor also tests operating effectiveness over a period, typically 3 to 12 months, and reports the tests performed and their results.

SOC 1 reports are restricted-use documents: they are intended for management, existing customers, and their auditors, and are normally shared under NDA rather than published.

What Is a SOC 2 Report?

A SOC 2 report addresses operational and security risk rather than financial reporting risk. The examination measures a service organization’s controls against the AICPA’s Trust Services Criteria — the 2017 Trust Services Criteria (with revised points of focus, 2022) — organized into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Only Security (the “common criteria,” aligned to the COSO 2013 internal control framework) is mandatory; the other four categories are added based on the commitments the organization makes to customers. Our breakdown of the SOC 2 trust principles explains how to choose which categories to include.

Like SOC 1, SOC 2 offers a Type 1 (design at a point in time) and a Type 2 (operating effectiveness over a review period, with detailed test procedures and results). Buyers overwhelmingly prefer Type 2 because it proves controls actually operated, not just that they existed on paper.

SOC 2 has become the default trust currency for SaaS, cloud, and managed service providers: security teams, procurement, and vendor risk managers read the full report — system description, control matrix, test results, and exceptions — before signing or renewing contracts. It remains a restricted-use report, typically shared under NDA. For a full walkthrough of scoping, readiness, and the audit itself, see our complete guide to SOC 2 compliance.

What Is a SOC 3 Report?

A SOC 3 report is the public-facing sibling of SOC 2. The AICPA titles it “Trust Services Criteria for General Use Report”: it covers the same Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria as SOC 2, but as the AICPA notes, SOC 3 reports “do not provide the same level of detail,” so “they are considered general use reports and can be freely distributed.”

Three practical consequences follow from that design:

  • No test detail. A SOC 3 contains the auditor’s opinion, management’s assertion, and an abbreviated system description — but not the control-by-control test procedures and results that make a SOC 2 useful for vendor due diligence, as Linford & Co explains.
  • Always Type 2. A SOC 3 is derived from a Type 2 examination over a period; there is no SOC 3 Type 1.
  • Marketing-friendly. Because it is unrestricted, you can post it on your website or trust center. AWS, for example, publishes its SOC 3 as a freely downloadable whitepaper while keeping SOC 1 and SOC 2 behind an NDA in AWS Artifact.

A SOC 3 is almost never produced on its own — it is an inexpensive add-on to a SOC 2 Type 2 engagement. If you are wondering what you can share publicly from your SOC program, see our post on whether SOC 2 reports are public information.

SOC 1 vs SOC 2 vs SOC 3: Side-by-Side Comparison

Here is how the three reports compare across the dimensions that matter when a customer or auditor asks for one.

Dimension SOC 1 SOC 2 SOC 3
Core question Could this vendor’s controls affect our financial statements? Does this vendor protect the systems and data we entrust to it? Same as SOC 2, answered at a summary level for the public
Control focus Internal control over financial reporting (ICFR); management-defined control objectives Trust Services Criteria: Security (required) + optional Availability, Processing Integrity, Confidentiality, Privacy Same Trust Services Criteria as the underlying SOC 2
Governing standard AT-C section 320 (SSAE 18) AT-C sections 105 & 205; TSP section 100 AT-C sections 105 & 205; TSP section 100
Primary audience Customer management and their financial statement auditors Customer security, procurement, and vendor risk teams; regulators; management General public, prospects, marketing use
Distribution Restricted use (NDA) Restricted use (NDA) General use — freely distributable
Report types Type 1 or Type 2 Type 1 or Type 2 Always based on a Type 2 examination
Detail level Full system description, controls, and (Type 2) test results Full system description, controls, and (Type 2) test results Opinion and short description only; no test detail
Typical organizations Payroll, claims, and payment processors; fund administrators; loan servicers SaaS, cloud, data centers, MSPs/MSSPs, any data-handling vendor SOC 2-audited organizations that want public proof

Which SOC Report Do You Need?

Let your customers’ questions decide. If their auditors ask how your service affects their financial statements, you need a SOC 1. If their security and vendor risk teams send questionnaires about encryption, access control, and incident response, you need a SOC 2 — our post on who needs SOC 2 compliance walks through the common triggers. If sales wants public proof of the SOC 2 without NDAs, add a SOC 3.

Many organizations need more than one. A payroll SaaS provider is the textbook case: its calculations flow into customers’ financial statements (SOC 1) and it stores sensitive employee data in the cloud (SOC 2). The two examinations can be run by the same firm on aligned timelines, and a SOC 3 can be issued off the back of the SOC 2 Type 2.

The commercial stakes keep rising. Third-party involvement in breaches doubled to 30% of cases in the past year, according to Verizon’s 2025 Data Breach Investigations Report, and IBM’s 2025 Cost of a Data Breach Report puts the average breach at $4.44 million globally and $10.22 million in the United States. Buyers respond by demanding audited evidence — not questionnaire answers — before trusting a vendor.

Whichever report you pursue, the work underneath is the same discipline: defined controls, assigned owners, and evidence that controls operate all year, not just during audit fieldwork. Type 2 examinations in particular reward organizations that collect evidence continuously instead of scrambling each audit season.

Frequently asked questions

Is SOC 2 better than SOC 1?
Neither is better; they answer different questions. SOC 1 addresses controls relevant to customers’ internal control over financial reporting, while SOC 2 addresses security and related Trust Services Criteria. A payroll processor may need SOC 1, a SaaS vendor SOC 2, and some organizations legitimately need both reports.
Can a company have both a SOC 1 and a SOC 2 report?
Yes. Organizations whose services affect customers’ financial statements and also handle sensitive data often maintain both. A payroll or payment processor, for example, typically issues a SOC 1 for customers’ financial auditors and a SOC 2 for security and vendor risk teams, often on aligned audit timelines.
Is a SOC 3 report the same as a SOC 2 report?
No. A SOC 3 is a summary derived from a SOC 2 Type 2 examination against the same Trust Services Criteria, but it omits the detailed system description and control test results. Because of that reduced detail, the AICPA designates it a general-use report that can be freely distributed.
Does a SOC 3 report come in Type 1 and Type 2?
No. A SOC 3 is always based on a Type 2 examination covering a period of time; there is no point-in-time SOC 3 Type 1. If an organization wants a design-only assessment, it would obtain a SOC 1 or SOC 2 Type 1 report instead.
Are SOC reports certifications?
No. SOC 1, SOC 2, and SOC 3 are attestation reports containing an independent CPA’s opinion under AICPA standards, not pass/fail certificates. There is no badge issued by the AICPA; the deliverable is the report itself, which readers evaluate, including any noted exceptions or qualified opinions.
Who can perform a SOC audit?
Only a licensed CPA firm can perform a SOC examination and issue a SOC 1, SOC 2, or SOC 3 report, following AICPA attestation standards (SSAE 18, AT-C sections 320, 105, and 205). Consultants can help you prepare, but the attestation opinion must come from an independent CPA firm.

Get SOC 1, SOC 2, and SOC 3 Ready with Compyl

Compyl’s agentic GRC platform maps your controls to the Trust Services Criteria and SOC 1 control objectives, automates evidence collection year-round, and keeps you audit-ready for Type 2 examinations. Book a demo to see how teams cut SOC prep time dramatically.

Request a demo →

About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies