CPA Exam · 14 min read Updated

CPA SOC Reports Guide: SOC 1 vs SOC 2 vs SOC 3 Explained

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CPA SOC Reports Guide: SOC 1 vs SOC 2 vs SOC 3 Explained

Key Takeaways

  • Official Standard: AT-C Section 320, Reporting on an Examination of Controls at a Service Organization.
  • SOC 1 Focus: Internal Controls over Financial Reporting (ICFR) for user entities.
  • SOC 2 Focus: The five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
  • Report Users (SOC 2): Restricted to knowledgeable stakeholders (customers, partners, regulators) under an NDA.
  • Report Users (SOC 3): General use; can be freely distributed for marketing.

What trips up even the sharpest CPA candidates on SOC reports isn't memorizing the definitions. It's a fundamental misunderstanding of perspective. You can recite the differences between a SOC 1 and SOC 2 report, but then the exam asks which one a user entity's financial statement auditor needs to assess the risk of material misstatement. Suddenly, the definitions aren't enough. The exam is designed to test if you know which lens to look through—the financial auditor's, the customer's, or the public's—under pressure.

Quick answer

A SOC 1 report addresses controls relevant to a user's financial reporting (ICFR), used by financial auditors. A SOC 2 report addresses controls based on the Trust Services Criteria (e.g., security, privacy), used by customers and partners. A SOC 3 report is a general-use summary of the SOC 2 findings.

Key facts

  • Official Standard: AT-C Section 320, Reporting on an Examination of Controls at a Service Organization.
  • SOC 1 Focus: Internal Controls over Financial Reporting (ICFR) for user entities.
  • SOC 2 Focus: The five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
  • Report Users (SOC 1): Restricted to user entities and their financial auditors.
  • Report Users (SOC 2): Restricted to knowledgeable stakeholders (customers, partners, regulators) under an NDA.
  • Report Users (SOC 3): General use; can be freely distributed for marketing.

What Are SOC Reports and Why Do They Matter for the ISC Exam?

A System and Organization Controls (SOC) report provides an independent CPA's opinion on the controls at a service organization. This is a critical concept because modern companies constantly outsource key functions. When your company (the user entity) hires a payroll processor or cloud provider (the service organization), your auditors still need assurance over the controls at that vendor. SOC reports, issued under AICPA attestation standard AT-C 320, are the mechanism for providing that assurance.

Think of the players:

Free 5-Min Diagnostic

Studying for CPA ISC? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

  • User Entity: Your company, "Innovate Inc."
  • Service Organization: The cloud data host you use, "SecureCloud LLC."
  • The Problem: Innovate Inc.'s auditor, Deloitte, needs to know if SecureCloud's systems will protect data that impacts Innovate's financial statements.

Instead of Deloitte auditing SecureCloud directly—which would be wildly inefficient—SecureCloud hires its own CPA firm to perform a SOC examination. Deloitte can then rely on that report. The ISC exam will hit you with scenarios to see if you can pinpoint the right report for the right user.

SOC 1 Reports: The Financial Auditor's Toolkit

A SOC 1 report is exclusively focused on a service organization's controls that could impact a user entity’s internal control over financial reporting (ICFR). This is the report a user entity's financial statement auditor needs to do their job. Its entire purpose is to help that auditor assess the risk of material misstatement in the user's financial statements.

The criteria for a SOC 1 report are based on the service organization's own control objectives. For example, a payroll processor's objective might be: "Controls provide reasonable assurance that payroll calculations are accurate and complete." The auditor then opines on whether the controls are suitably designed and operating effectively to meet that objective.

Type 1 vs. Type 2: The Most Tested Distinction

The difference between a Type 1 and Type 2 report is about a snapshot versus a video. This distinction is a favorite of exam writers.

  • A SOC 1, Type 1 report gives an opinion on the fairness of the presentation of the system description and the suitability of the design of controls as of a specified date. It's a blueprint. It tells you if the controls look good on paper at one moment in time.
  • A SOC 1, Type 2 report includes everything in a Type 1, but adds a crucial third piece: an opinion on the operating effectiveness of those controls throughout a specified period (usually 6-12 months). It's a performance review. It tells you if the controls actually worked over time.
FeatureSOC 1, Type 1SOC 1, Type 2
FocusDesign of controlsDesign and Operating Effectiveness
TimeframeAs of a specific date (e.g., Dec 31, 2026)Over a period of time (e.g., Jan 1 - Dec 31, 2026)
Auditor's WorkInquiry, observation, inspectionType 1 procedures plus tests of controls
Level of AssuranceLowerHigher
Use by User AuditorHelps understand controlsAllows potential reduction of substantive testing
The Examiner's Trap: An exam question asks if a user auditor can reduce their own substantive testing based on a service organization's SOC 1 report.
  • The Tempting Wrong Answer: Yes, if they obtain a SOC 1 report.
  • Why It's Wrong: A user auditor can only consider reducing substantive testing if they obtain a SOC 1, Type 2 report. A Type 1 only speaks to design; it provides zero assurance that the controls actually worked.
  • The High-Scorer Nuance: Even with a "clean" Type 2 report, the user auditor isn't done. They must also evaluate the service auditor's competence and independence and assess whether the report's scope and findings are adequate for their audit. They can't just take it at face value.

SOC 2 Reports: The Deep Dive into Security, Privacy, and Operations

A SOC 2 report addresses a service organization's controls related to a much broader set of principles: the five Trust Services Criteria (TSC). This report is for users who need assurance about data security, system availability, processing integrity, confidentiality, or privacy. It's not focused on ICFR. Think of customers, business partners, and regulators who need to know if they can trust the service organization with their data and operations.

The Five Trust Services Criteria (TSC)

You must know these. A SOC 2 report can cover any combination, and the ISC exam will test your ability to map a scenario to the correct criterion.

  1. Security (Common Criteria): The system is protected against unauthorized access, use, or modification. This is the foundation and is included in almost every SOC 2 report.
  2. Availability: The system is available for operation and use as committed or agreed. Think disaster recovery and uptime.
  3. Processing Integrity: System processing is complete, valid, accurate, timely, and authorized. Think quality control for transactions.
  4. Confidentiality: Information designated as confidential is protected as committed or agreed. Think business secrets, intellectual property.
  5. Privacy: Personal information is collected, used, retained, disclosed, and disposed of in conformity with the entity’s privacy notice. This applies specifically to Personally Identifiable Information (PII).
A quick note on TSC selection: While the AICPA standard only requires a SOC 2 to address at least one TSC, for exam purposes, you should assume Security is the baseline for any robust report.

SOC 2: Type 1 vs. Type 2

Just like with a SOC 1, a SOC 2 report can be a Type 1 (design as of a date) or a Type 2 (design and operating effectiveness over a period). For any customer performing serious due diligence or vendor risk management, a Type 2 report is the only one that provides meaningful assurance.

The SOC 2 report is a restricted-use document. This is because it contains a detailed description of the service organization's systems, controls, the auditor's tests, and the results. The restriction is due to this detailed subject matter, which is intended only for specified parties (like customers) who have a valid need to know and typically sign an NDA.

SOC 3 Reports: The Public-Facing Handshake

A SOC 3 report is a general-use report based on a SOC 2 examination. It covers the same Trust Services Criteria but omits the detailed description of controls, tests, and results. Because the sensitive details are removed, it can be freely distributed.

✨ Free Interactive Tool

Check Your State’s Exact CPA Exam Requirements

Every state has different credit hour, ethics, and residency rules. Use our 55-jurisdiction checker to verify your eligibility before applying.

Check State Requirements →

Think of it as a certificate of achievement. Companies post their SOC 3 report on their website as a marketing tool to show potential customers they've successfully completed a SOC 2 audit. If you see a logo that says "SOC 2 Certified," they are almost always referring to a SOC 3 report that they can share publicly.

The Missing Piece: Complementary User Entity Controls (CUECs)

Here's a concept that trips up candidates because it's about shared responsibility. A SOC report will almost always include a section on Complementary User Entity Controls (CUECs). These are controls that the service organization assumes the user entity will have in place for the overall system to function as intended.

Example: A cloud provider (service organization) has controls to secure their data centers and servers. Their SOC report might list a CUEC that states: "The user entity is responsible for implementing and managing strong password policies for its own employees who access the cloud platform."

The service organization's controls can't work in a vacuum. The user entity has a part to play. The exam will test if you understand that the user auditor must not only review the service organization's controls but also evaluate whether their own client (the user entity) has implemented the required CUECs.

SOC 1 vs. SOC 2 vs. SOC 3: The High-Scorer Comparison

Internalize this table. It's your decision matrix for any scenario-based question.

FeatureSOC 1 ReportSOC 2 ReportSOC 3 Report
Primary Subject MatterControls relevant to user entity's ICFRControls relevant to Security, Availability, Processing Integrity, Confidentiality, or PrivacySame as SOC 2, but a high-level summary
CriteriaService organization's control objectivesAICPA's Trust Services Criteria (TSC)AICPA's Trust Services Criteria (TSC)
Primary AudienceUser entities and their financial auditorsManagement, customers, partners, regulatorsGeneral public, anyone
Report UseRestricted Use. For planning and performing a financial statement audit.Restricted Use. For vendor management, due diligence, and governance.General Use. For marketing and building public trust.
Level of DetailHigh. Detailed description of system, controls, tests, and results.High. Detailed description of system, controls, tests, and results.Low. Auditor's opinion and summary assertion only. No detailed tests.
Key Question it Answers"Can I rely on your controls for my financial statement audit?""Can I trust you to protect my data and keep your system running?""Can you give me a public confirmation that you have good controls?"

Worked Example: Thinking Like an Examiner

Let's apply this with a real exam-style scenario.

Scenario: HealthData Solutions (HDS) provides cloud-based electronic health record (EHR) hosting for hospitals. One of its clients, Mercy General Hospital, is undergoing its annual financial statement audit by PwC. Separately, a potential new client, Vista Health System, is performing due diligence and is deeply concerned about patient data privacy and system availability during emergencies. HDS also wants to place a compliance seal on its website to attract new hospitals. Question: Which report is most appropriate for each party's needs? High-Scorer Thought Process:
  1. Identify the Parties & Needs:
  • PwC (User Auditor): Needs to audit Mercy General's financials. The accuracy of EHR data impacts revenue recognition and accounts receivable. This is an ICFR concern.
  • Vista Health (Prospective Customer): Concerned with "patient data privacy" and "system availability." These map directly to the Privacy and Availability Trust Services Criteria.
  • HDS (Service Organization): Wants a "compliance seal" for its website. This is a marketing need.
  1. Analyze PwC's Need:
  • Objective: Financial statement audit.
  • Conclusion: PwC needs a SOC 1 report. To rely on the controls and potentially reduce their testing, they need assurance on operating effectiveness over the audit period. Therefore, they need a SOC 1, Type 2 report. They would also review the CUECs to ensure Mercy General is doing its part.
  1. Analyze Vista Health's Need:
  • Objective: Due diligence on operational and privacy controls.
  • Conclusion: Vista Health needs a SOC 2 report. They need assurance that controls have been working, so they would request a SOC 2, Type 2 report covering, at a minimum, the Privacy, Confidentiality, Security, and Availability criteria. They would sign an NDA to get it.
  1. Analyze HDS's Need:
  • Objective: Public marketing.
  • Conclusion: HDS needs a SOC 3 report. It's derived from their SOC 2 examination and provides that public seal of approval without revealing sensitive internal control details.

The #1 Trap: Confusing the Data with the User's Objective

The most common mistake is focusing on the type of data instead of the user's goal.

Tempting Wrong Answer: A question describes a cloud provider that stores financial data for a bank. You immediately think, "Financial data means SOC 1." Why it's wrong: The purpose of the report dictates the choice.
  • If the bank's financial auditor needs the report to audit the bank's financial statements, they need a SOC 1.
  • If the bank's Chief Information Security Officer (CISO) needs the report to satisfy regulators that the cloud provider meets the bank's cybersecurity standards, they need a SOC 2 (focused on the Security and Confidentiality TSC).
The Right Way to Think: Always start with the user of the report. Ask yourself: "What is this person trying to achieve? What risk are they trying to mitigate?"
  • Financial Statement Audit Risk → SOC 1
  • Security, Operational, or Privacy Risk → SOC 2
  • Marketing or Public Trust → SOC 3

Mastering this perspective-based approach is far more valuable than rote memorization. VoraPrep's adaptive learning engine, with over 9,500+ questions, is designed to drill you on these judgment calls, and our Vory tutor is available 24/7 to explain the "why" behind any question you miss.

--- Ready to Pass Your CPA Exam? Don't just memorize rules; learn to think like the examiner. VoraPrep's adaptive platform, 9,500+ practice questions with detailed explanations, and 24/7 Vory AI tutor are designed to build your judgment and confidence. We teach you how to pass. Visit voraprep.com to get started.

Start Your Free 14-Day Trial at voraprep.com →
⚡ Instant Knowledge Check · 1-Click Test Drive
ISC-I & ISC-II: Information Systems, Security & SOC Controls

An independent auditor evaluating an enterprise service organization under AICPA Trust Services Criteria notes that management restricts logical access to source code using role-based access control (RBAC) and mandatory pull-request approvals. Which trust services category is PRIMARILY addressed by these controls?

Official resources and references

Frequently asked questions

1. What is the core difference between a SOC 1 and SOC 2 report? The core difference is the user's objective. A SOC 1 report is for a client's financial auditors and focuses on controls impacting financial reporting (ICFR). A SOC 2 report is for customers and partners and focuses on controls related to security, availability, privacy, and other operational criteria (the TSCs). 2. Why would a company need both a SOC 1 and a SOC 2 report? They serve different audiences and purposes. A payroll processor needs a SOC 1 for its clients' financial auditors. It also needs a SOC 2 to assure those same clients that it is properly securing sensitive employee PII, addressing the Security and Privacy criteria for the client's operational and compliance needs. 3. Is a Type 1 report ever enough? A Type 1 report is useful for a company's first SOC audit to establish a baseline of control design. However, for a user to actually rely on the controls to reduce their own testing or manage risk, they almost always require a Type 2 report, which proves the controls worked over a period of time. 4. Does a "clean" SOC report mean there are no control issues? No. An "unqualified" or "clean" opinion means the auditor found no material weaknesses in the design or operation of controls. The report may still list less severe deficiencies, management's response to issues, or other descriptive matters. It provides reasonable, not absolute, assurance. 5. Who can perform a SOC examination? Only a licensed, independent Certified Public Accountant (CPA) or a CPA firm can perform a SOC examination and issue the report. The engagement must follow the AICPA's attestation standards. 6. What are Complementary User Entity Controls (CUECs)? CUECs are controls that the service organization requires its clients (the user entities) to implement for the overall control environment to be effective. For example, a cloud provider manages server security, but the client is responsible for managing its own user passwords. 7. How long is a SOC report considered valid? A SOC report is generally considered current for about 12 months after the end of the period covered by the report. Most users will not accept a Type 2 report that covers a period ending more than a year ago. A Type 1 report is only valid as of the specific date on the report.
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CPA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CPA diagnostic + 12-week plan PDF

Start →
CPA 1:1 Prometric Simulator

9,500+ practice questions with instant Socratic feedback