Skip to content
SOC 1SOC 2SSAE 18
Resilience & Assurance

SOC 1 & SOC 2 (SSAE 18) Audit Readiness

Commitment to excellence.

Independent reporting on the controls at service organisations, giving your customers assurance around security, availability, processing integrity, confidentiality and privacy.

Resilience & Assurance

Overview

SSAE reporting covers third-party service providers such as cloud service providers, payroll processors and data centres. This is crucial for the user entities, the clients of these service organisations.

It provides a recognised benchmark for assessing an organisation's controls and practices related to security, availability, processing integrity, confidentiality and privacy.

The scope of SSAE compliance typically depends on your services and the areas covered by the Trust Service Criteria. You can choose the specific criteria that align with your business. For example, a technology company may prioritise security and availability, while a healthcare organisation may focus on privacy, confidentiality and processing integrity.

What it delivers

  • Independent assurance that wins customer trust.
  • A recognised benchmark across five trust criteria.
  • A scope tailored to your services and priorities.
  • Credibility with the clients who rely on your services.

What Are SOC Reports and SSAE 18?

SOC, System and Organization Controls, reports are independent attestations about the controls at a service organisation, carried out under the AICPA's SSAE 18 standard. They give your customers assurance about how you manage their data and operations. SOC 1 focuses on controls relevant to financial reporting; SOC 2 focuses on security, availability, processing integrity, confidentiality and privacy.

A SOC 2 report is especially common for technology and SaaS companies, and is often requested by enterprise customers before they will trust you with their data. It is an attestation performed by a licensed CPA firm, not a certification, and demonstrates that your controls are properly designed and, in a Type II report, operating effectively over time.

Why SOC Reports Matter

For service providers, a SOC 2 report has become a standard requirement in enterprise sales. It provides independent evidence that you handle customer data securely, and often replaces lengthy security questionnaires and repeated due-diligence checks.

Achieving a clean SOC report builds significant trust and can shorten sales cycles, removing a major barrier to winning larger customers who cannot take security on faith.

How Conformite Assist Helps

  • Determining the right report and scope (SOC 1, SOC 2, Type I or Type II).
  • Gap assessment against the relevant trust criteria.
  • Designing and implementing the required controls.
  • Building evidence-collection routines that satisfy auditors.
  • Policies, procedures and documentation.
  • Liaison support with your CPA audit firm through the audit.

Key benefits

  • Independent assurance that wins enterprise trust.
  • Fewer security questionnaires and shorter sales cycles.
  • Well-designed controls that pass audit first time.
  • Clear ownership of evidence and readiness.
  • A framework that reuses much of your ISO 27001 work.

Frequently asked questions

What is the difference between SOC 1 and SOC 2?

SOC 1 covers controls relevant to a client's financial reporting. SOC 2 covers controls related to security, availability, processing integrity, confidentiality and privacy. SOC 2 is the report most technology and SaaS companies need.

What is the difference between SOC 2 Type I and Type II?

A Type I report assesses whether controls are suitably designed at a point in time. A Type II report assesses whether they also operated effectively over a period (typically several months). Type II provides stronger assurance and is more commonly requested.

Is SOC 2 a certification?

No. SOC 2 is an attestation performed by a licensed CPA firm under SSAE 18, not a certification. We prepare you for the attestation; an independent CPA firm performs the audit and issues the report.

How does SOC 2 relate to ISO 27001?

SOC 2 and ISO 27001 share a large proportion of underlying controls. If you have done one, much of the work carries over to the other, so we can help you pursue both efficiently using a unified set of controls and evidence.

Can we choose what the report covers?

Yes. You can select the Trust Service Criteria that align with your business and the services you provide.

Contact us

Comply more, complain less

Talk to us about SOC reporting and trust services readiness.

Tell us the certification or compliance goal in front of you, and we’ll show you the clearest path to reach it, and stay there.