SOC 1 vs SOC 2 vs SOC 3: which report
Three reports, three audiences. Your customer almost certainly means SOC 2, but the exceptions are worth knowing before you commission the wrong engagement.
SOC 1 reports on controls that affect a customer's financial statements. SOC 2 reports on security, availability, processing integrity, confidentiality and privacy. SOC 3 is a short public version of a SOC 2 with the test results stripped out. If a software buyer asked you for "a SOC report" without saying more, they mean a SOC 2 Type 2, and that is what you should scope.
SOC 2 Type 2 What a software buyer means by "SOC report"
$0 Extra audit fee for a SOC 3, if you already have the SOC 2
The three reports side by side
| SOC 1 | SOC 2 | SOC 3 | |
|---|---|---|---|
| Subject | Controls relevant to a user's financial reporting | Controls over security and the other Trust Services categories | The same controls as the SOC 2 |
| Who reads it | Your customer's external auditor | Your customer's security and procurement team | Anyone, including prospects who have not signed an NDA |
| Criteria used | Control objectives you write yourself | The AICPA Trust Services Criteria | The AICPA Trust Services Criteria |
| Contains test results | Yes | Yes | No |
| Contains a system description | Yes, detailed | Yes, detailed | A short summary only |
| Distribution | Restricted | Restricted, usually under NDA | Public, put it on your website |
| Type 1 and Type 2 exist | Yes | Yes | Type 2 only |
| Typical Canadian fee, CAD | $25,000 to $70,000 | $20,000 to $100,000 | $0 to $5,000 as an add-on |
Which one your customer actually wants
Ask them, then read what they wrote rather than what they said on the call. The words in the contract schedule are the ones that decide your scope.
- Your buyer is a software company, a bank buying software, or an enterprise IT department. They want SOC 2 Type 2.
- Your buyer's external auditor is asking, and your product touches payroll, billing, payments processing, claims adjudication or the general ledger. They want SOC 1, and they may want SOC 2 as well.
- Your buyer will not sign an NDA and just wants something to file. SOC 3 satisfies them, and you can only produce one if you already did the SOC 2.
- Nobody has asked and you are doing this pre-emptively. Do SOC 2 Security only, and read whether you need it yet before you spend anything.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
SOC 1, and when a Canadian company genuinely needs one
Your customer's auditor has to form an opinion on your customer's financial statements, and part of the process that produces those statements runs inside your systems. Rather than being audited twenty times for twenty customers, you get audited once and hand out the report.
The distinguishing feature is that you write the control objectives. There is no fixed criteria set, so a SOC 1 is only as useful as the objectives it names. Canadian firms perform SOC 1 engagements under the AICPA standards, and there is a parallel Canadian standard, CSAE 3416, that covers the same ground for Canadian user auditors. Ask which one your customer's auditor will accept before the engagement letter is signed. Reissuing under the other standard is a second engagement.
Products that usually trigger a SOC 1 request
- Payroll and benefits administration
- You calculate amounts that land in a customer's payroll expense.
- Billing, invoicing and revenue recognition
- Your system determines what the customer books as revenue.
- Payment processing and treasury
- Money moves through you and the movement is recorded from your data.
- Claims, loans and lending servicing
- You calculate balances the customer reports.
- Expense management and procurement
- Approvals in your system are the approval control the auditor tests.
If none of those describe you, a SOC 1 request is usually a procurement template written for a different kind of vendor. Push back once, in writing, and ask which financial statement assertion your system affects. That question resolves most misdirected SOC 1 requests.
SOC 3, and why almost nobody bothers
A SOC 3 is a general use report. It carries the auditor's opinion and a brief system description. It omits the control descriptions and test results, so it can be published without exposing your control design. Companies put the seal on a trust page and hand the file to anyone who asks.
It is cheap because it is a byproduct. If your auditor is already issuing a SOC 2 Type 2, adding a SOC 3 over the same period is a small incremental fee, in the $0 to $5,000 CAD range depending on the firm, and some include it. It is not a substitute. No security reviewer accepts a SOC 3 in place of a SOC 2: the part they need to read is the part a SOC 3 removes. It is a marketing asset and a way to answer early-stage prospects without an NDA.
The one time SOC 3 earns its fee
Self-serve and product-led companies get asked for a report by hundreds of small prospects who will never sign an NDA and will never read past the opinion. Publishing a SOC 3 removes that queue from your sales team. If your deals are all enterprise and all under NDA anyway, skip it.
When you need SOC 1 and SOC 2
Fintech and payments companies routinely need both, and the two engagements share a large amount of work. The system description, the change management controls, the access controls and the vendor management program are tested once and used in both reports. What does not overlap is the financial control objectives in the SOC 1 and the criteria-specific controls in the SOC 2.
| Route | Audit fee | Note |
|---|---|---|
| SOC 2 Type 2 alone | $30,000 to $60,000 | The normal starting point |
| SOC 1 Type 2 alone | $30,000 to $55,000 | Only if a user auditor is asking |
| Both, same firm, same period | $50,000 to $90,000 | Cheaper than two engagements because the fieldwork overlaps |
| Both, different firms | $60,000 to $115,000 | Two sets of walkthroughs, two request lists |
| Saving from running both with one firm over one period | Roughly $10,000 to $25,000 | |
If you think both are coming, say so in the request for proposal. The quote drivers page covers what else moves an audit fee, and the full cost page covers the three lines beyond the auditor.
Reports people confuse with these
SOC for Cybersecurity is a separate AICPA report aimed at boards and insurers rather than customers, and no software buyer has ever accepted it in place of a SOC 2. ISO 27001 is a certification against a management system standard, not an attestation, and it is what buyers in the UK and Europe usually ask for instead. The SOC 2 versus ISO 27001 page works through that decision for a Canadian company, and ISO27K covers it from the certification side.
Get the right report quoted
Tell us what your customer asked for in their own words and we will point you at Canadian firms that issue that report.
Get matchedCommon questions
Is SOC 2 better than SOC 1?
Neither is better. They answer different questions for different readers. A SOC 1 tells your customer's financial auditor that the numbers coming out of your system can be relied on. A SOC 2 tells your customer's security team that their data is protected. A company whose product affects financial reporting can need both.
Can we publish our SOC 2 report on our website?
No. A SOC 2 is a restricted use report and the AICPA standards limit its distribution to parties who understand the criteria, which in practice means customers and prospects under an NDA. If you want something public, ask your auditor to issue a SOC 3 over the same period.
Does a SOC 3 cost extra?
Usually between nothing and about $5,000 CAD as an add-on to a SOC 2 Type 2 that the same firm is already performing. It is priced as a byproduct because the audit work is already done. Commissioning a standalone SOC 3 with no SOC 2 behind it is not a thing auditors do.
What is CSAE 3416 and do we need it instead of SOC 1?
CSAE 3416 is the Canadian assurance standard covering controls at a service organization, the counterpart to the AICPA's SSAE 18 SOC 1. Which one you need depends on the standards your customer's auditor works under. Canadian customers with Canadian auditors may want CSAE 3416, American customers will want SOC 1. Ask before the engagement letter is signed.
Our customer asked for "SOC 2 Type 3". What is that?
It does not exist. There is no Type 3 report. The person is either thinking of SOC 3, or they have combined SOC 2 and Type 2 in their head. Reply asking whether they need the restricted Type 2 report or a public summary, and the answer is nearly always the Type 2.