The quickest way to tell them apart: SOC 1 is for your customer's auditors, SOC 2 is for your customer's security team, and SOC 3 is for your website. They are produced under related professional standards but answer completely different questions.
SOC 1 - internal control over financial reporting
Scope is controls at a service organisation that could affect a customer's financial statements. If your service processes payroll, payments, billing or anything that flows into a customer's accounts, their external auditors need assurance over your controls to complete their own audit.
- Audience: your customers' financial auditors.
- Criteria: control objectives you define, relevant to financial reporting.
- Distribution: restricted.
Security controls appear only where they touch financial reporting integrity. A SOC 1 is not evidence that you are secure, and offering one when a buyer asked about security is a common and revealing mistake.
SOC 2 - security and the Trust Services Criteria
Scope is controls relevant to Security (mandatory) plus optionally Availability, Confidentiality, Processing Integrity and Privacy. This is what enterprise security teams mean when they ask for "your SOC report".
- Audience: customers' security, risk and procurement functions.
- Criteria: AICPA Trust Services Criteria.
- Distribution: restricted - typically shared under NDA.
The report contains your system description, the controls tested, the tests performed and any exceptions. That detail is the point, and it is why distribution is controlled.
SOC 3 - the public version
A general-use summary derived from a SOC 2 engagement. It states the auditor's opinion without the detailed testing, system description or exceptions.
- Audience: anyone - it can sit on your website.
- Criteria: same Trust Services Criteria as SOC 2.
- Distribution: unrestricted.
Useful as a trust signal for prospects who are not yet in a security review, but it will not satisfy a serious buyer - they will ask for the SOC 2.
Get SOC 2 ready without the scramble
GRC Copilot runs your readiness assessment against the Trust Services Criteria and tracks evidence continuously through the observation window.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Type I vs Type II - a different axis
This applies to SOC 1 and SOC 2 alike, and is frequently conflated with the report number:
- Type I - are the controls suitably designed at a point in time? Faster to obtain; useful to unblock a deal.
- Type II - did they operate effectively across a period, typically three to twelve months? This is what enterprise buyers expect.
So "SOC 2 Type II" means: security criteria, tested over a period. If a customer says only "SOC 2", assume they mean Type II and confirm.
Which do you need?
- Your service affects customers' financial statements - SOC 1, usually alongside SOC 2 rather than instead of it.
- You are a SaaS or hosting provider selling to US enterprises - SOC 2 Type II.
- You want a public trust artefact - SOC 3, derived from your SOC 2.
- Your buyers are outside the US - they are more likely to ask for ISO 27001. Check before investing.
Ask the buyer which report and which type, in writing. "We need your SOC report" is ambiguous, and producing the wrong one wastes a full audit cycle.
Frequently asked questions
Is SOC 2 a certification?
No. It is an attestation report containing an auditor's opinion. There is no certificate or public registry - which is why buyers ask you to send the report.
Can we have SOC 1 and SOC 2 together?
Yes, and organisations processing financial data commonly do. They are separate engagements, though evidence overlaps.
Who can issue these reports?
A licensed CPA firm. That is a firm requirement, not a preference.
Does SOC 2 replace ISO 27001?
They serve different markets. SOC 2 is a report US buyers read; ISO 27001 is a certificate international buyers verify. Many organisations pursue both from one control set.
Key takeaways
- SOC 1 = financial reporting, SOC 2 = security, SOC 3 = public summary.
- Type I is design at a point in time; Type II is operation over a period.
- SOC 2 reports show exceptions - which is why distribution is restricted.
- Confirm in writing which report and type the buyer actually needs.