A European customer asking for an ISAE 3402 report and a US customer asking for SOC 1 are usually asking for the same thing under different standards. The confusion is common and occasionally expensive, because organisations commission the wrong report.
| Report | Standard | Covers | Typical asker |
|---|---|---|---|
| SOC 1 | US attestation standards | Controls relevant to customers' financial reporting | US customers and their auditors |
| ISAE 3402 | International | Controls relevant to customers' financial reporting | European and international customers |
| SOC 2 | US attestation standards | Security, availability, confidentiality, processing integrity, privacy | US enterprise buyers |
| ISAE 3000 | International | Broad - any subject matter other than financial history, including security | European buyers wanting security assurance |
The two questions that resolve most confusion
- Is the customer asking about their financial statements, or about your security? Financial reporting means SOC 1 or ISAE 3402. Security means SOC 2 or an ISAE 3000 engagement.
- Which standard does their auditor work to? That usually decides between the US and international variants for the same subject matter.
If a customer asks for "an ISAE report" without specifying, ask which. ISAE 3402 and ISAE 3000 answer completely different questions, and producing the wrong one wastes an audit cycle.
Type 1 and Type 2 mean the same thing across all of them
- Type 1 - suitability of design at a point in time.
- Type 2 - design and operating effectiveness across a period.
Enterprise buyers almost always mean Type 2, and the observation period is what sets the timeline in every case. That period cannot be compressed with budget - it requires evidence that already exists.
One control set, several reports
GRC Copilot maps a single control library across the frameworks and assurance regimes you report against, so evidence is gathered once.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Do you need more than one?
Frequently the underlying control work is largely shared, so the marginal cost of a second report is the audit fee plus a modest delta rather than a second programme. Common combinations:
- SOC 1 or ISAE 3402 plus SOC 2 - where you affect customers' financial reporting and hold their data. Payroll, payments and financial platforms typically need both.
- SOC 2 plus ISO 27001 - the most common pairing for software vendors selling internationally.
Where a customer will accept either, ISO 27001 is often the cheaper answer internationally because the certificate is reusable across every customer rather than being a report each one reads.
Practical differences worth knowing
- Reports circulate; certificates do not. SOC and ISAE reports are shared under NDA and read in detail, including any exceptions. An ISO certificate is a single page.
- Complementary user entity controls. Every one of these reports transfers obligations back to the reader. If you consume such reports, that section is the one to read.
- Carve-out versus inclusive treatment of subservice organisations affects what your report actually covers, and readers should check which was used.
Frequently asked questions
Is ISAE 3402 equivalent to SOC 1?
Substantively yes - same subject matter under a different standard. Some customers accept either; some auditors have a preference.
Which do European customers want for security?
Often ISO 27001, sometimes an ISAE 3000 engagement, increasingly SOC 2 as it becomes familiar internationally. Ask rather than assume.
Can one audit produce several reports?
The control work overlaps heavily and evidence is reusable, but each report is a separate engagement with its own opinion.
What if we only sell in Europe?
ISO 27001 is usually the efficient choice, with an ISAE engagement where a customer specifically requires an assurance report.
Key takeaways
- Financial reporting means SOC 1 or ISAE 3402; security means SOC 2 or ISAE 3000.
- Ask which ISAE standard - they answer different questions.
- Type 2 needs an observation period that budget cannot shorten.
- Reports are read in detail; certificates are not.