What trips up even the sharpest CPA candidates on SOC reports isn't memorizing the definitions. It's a fundamental misunderstanding of perspective. You can recite the differences between a SOC 1 and SOC 2 report, but then the exam asks which one a user entity's financial statement auditor needs to assess the risk of material misstatement. Suddenly, the definitions aren't enough. The exam is designed to test if you know which lens to look through—the financial auditor's, the customer's, or the public's—under pressure.
A SOC 1 report addresses controls relevant to a user's financial reporting (ICFR), used by financial auditors. A SOC 2 report addresses controls based on the Trust Services Criteria (e.g., security, privacy), used by customers and partners. A SOC 3 report is a general-use summary of the SOC 2 findings.
Key facts
- Official Standard: AT-C Section 320, Reporting on an Examination of Controls at a Service Organization.
- SOC 1 Focus: Internal Controls over Financial Reporting (ICFR) for user entities.
- SOC 2 Focus: The five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy).
- Report Users (SOC 1): Restricted to user entities and their financial auditors.
- Report Users (SOC 2): Restricted to knowledgeable stakeholders (customers, partners, regulators) under an NDA.
- Report Users (SOC 3): General use; can be freely distributed for marketing.
What Are SOC Reports and Why Do They Matter for the ISC Exam?
A System and Organization Controls (SOC) report provides an independent CPA's opinion on the controls at a service organization. This is a critical concept because modern companies constantly outsource key functions. When your company (the user entity) hires a payroll processor or cloud provider (the service organization), your auditors still need assurance over the controls at that vendor. SOC reports, issued under AICPA attestation standard AT-C 320, are the mechanism for providing that assurance.
Think of the players:
Studying for CPA ISC? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
- User Entity: Your company, "Innovate Inc."
- Service Organization: The cloud data host you use, "SecureCloud LLC."
- The Problem: Innovate Inc.'s auditor, Deloitte, needs to know if SecureCloud's systems will protect data that impacts Innovate's financial statements.
Instead of Deloitte auditing SecureCloud directly—which would be wildly inefficient—SecureCloud hires its own CPA firm to perform a SOC examination. Deloitte can then rely on that report. The ISC exam will hit you with scenarios to see if you can pinpoint the right report for the right user.
SOC 1 Reports: The Financial Auditor's Toolkit
A SOC 1 report is exclusively focused on a service organization's controls that could impact a user entity’s internal control over financial reporting (ICFR). This is the report a user entity's financial statement auditor needs to do their job. Its entire purpose is to help that auditor assess the risk of material misstatement in the user's financial statements.
The criteria for a SOC 1 report are based on the service organization's own control objectives. For example, a payroll processor's objective might be: "Controls provide reasonable assurance that payroll calculations are accurate and complete." The auditor then opines on whether the controls are suitably designed and operating effectively to meet that objective.
Type 1 vs. Type 2: The Most Tested Distinction
The difference between a Type 1 and Type 2 report is about a snapshot versus a video. This distinction is a favorite of exam writers.
- A SOC 1, Type 1 report gives an opinion on the fairness of the presentation of the system description and the suitability of the design of controls as of a specified date. It's a blueprint. It tells you if the controls look good on paper at one moment in time.
- A SOC 1, Type 2 report includes everything in a Type 1, but adds a crucial third piece: an opinion on the operating effectiveness of those controls throughout a specified period (usually 6-12 months). It's a performance review. It tells you if the controls actually worked over time.
| Feature | SOC 1, Type 1 | SOC 1, Type 2 |
|---|---|---|
| Focus | Design of controls | Design and Operating Effectiveness |
| Timeframe | As of a specific date (e.g., Dec 31, 2026) | Over a period of time (e.g., Jan 1 - Dec 31, 2026) |
| Auditor's Work | Inquiry, observation, inspection | Type 1 procedures plus tests of controls |
| Level of Assurance | Lower | Higher |
| Use by User Auditor | Helps understand controls | Allows potential reduction of substantive testing |
- The Tempting Wrong Answer: Yes, if they obtain a SOC 1 report.
- Why It's Wrong: A user auditor can only consider reducing substantive testing if they obtain a SOC 1, Type 2 report. A Type 1 only speaks to design; it provides zero assurance that the controls actually worked.
- The High-Scorer Nuance: Even with a "clean" Type 2 report, the user auditor isn't done. They must also evaluate the service auditor's competence and independence and assess whether the report's scope and findings are adequate for their audit. They can't just take it at face value.
SOC 2 Reports: The Deep Dive into Security, Privacy, and Operations
A SOC 2 report addresses a service organization's controls related to a much broader set of principles: the five Trust Services Criteria (TSC). This report is for users who need assurance about data security, system availability, processing integrity, confidentiality, or privacy. It's not focused on ICFR. Think of customers, business partners, and regulators who need to know if they can trust the service organization with their data and operations.
The Five Trust Services Criteria (TSC)
You must know these. A SOC 2 report can cover any combination, and the ISC exam will test your ability to map a scenario to the correct criterion.
- Security (Common Criteria): The system is protected against unauthorized access, use, or modification. This is the foundation and is included in almost every SOC 2 report.
- Availability: The system is available for operation and use as committed or agreed. Think disaster recovery and uptime.
- Processing Integrity: System processing is complete, valid, accurate, timely, and authorized. Think quality control for transactions.
- Confidentiality: Information designated as confidential is protected as committed or agreed. Think business secrets, intellectual property.
- Privacy: Personal information is collected, used, retained, disclosed, and disposed of in conformity with the entity’s privacy notice. This applies specifically to Personally Identifiable Information (PII).
SOC 2: Type 1 vs. Type 2
Just like with a SOC 1, a SOC 2 report can be a Type 1 (design as of a date) or a Type 2 (design and operating effectiveness over a period). For any customer performing serious due diligence or vendor risk management, a Type 2 report is the only one that provides meaningful assurance.
The SOC 2 report is a restricted-use document. This is because it contains a detailed description of the service organization's systems, controls, the auditor's tests, and the results. The restriction is due to this detailed subject matter, which is intended only for specified parties (like customers) who have a valid need to know and typically sign an NDA.
SOC 3 Reports: The Public-Facing Handshake
A SOC 3 report is a general-use report based on a SOC 2 examination. It covers the same Trust Services Criteria but omits the detailed description of controls, tests, and results. Because the sensitive details are removed, it can be freely distributed.
Check Your State’s Exact CPA Exam Requirements
Every state has different credit hour, ethics, and residency rules. Use our 55-jurisdiction checker to verify your eligibility before applying.
Think of it as a certificate of achievement. Companies post their SOC 3 report on their website as a marketing tool to show potential customers they've successfully completed a SOC 2 audit. If you see a logo that says "SOC 2 Certified," they are almost always referring to a SOC 3 report that they can share publicly.
The Missing Piece: Complementary User Entity Controls (CUECs)
Here's a concept that trips up candidates because it's about shared responsibility. A SOC report will almost always include a section on Complementary User Entity Controls (CUECs). These are controls that the service organization assumes the user entity will have in place for the overall system to function as intended.
Example: A cloud provider (service organization) has controls to secure their data centers and servers. Their SOC report might list a CUEC that states: "The user entity is responsible for implementing and managing strong password policies for its own employees who access the cloud platform."The service organization's controls can't work in a vacuum. The user entity has a part to play. The exam will test if you understand that the user auditor must not only review the service organization's controls but also evaluate whether their own client (the user entity) has implemented the required CUECs.
SOC 1 vs. SOC 2 vs. SOC 3: The High-Scorer Comparison
Internalize this table. It's your decision matrix for any scenario-based question.
| Feature | SOC 1 Report | SOC 2 Report | SOC 3 Report |
|---|---|---|---|
| Primary Subject Matter | Controls relevant to user entity's ICFR | Controls relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy | Same as SOC 2, but a high-level summary |
| Criteria | Service organization's control objectives | AICPA's Trust Services Criteria (TSC) | AICPA's Trust Services Criteria (TSC) |
| Primary Audience | User entities and their financial auditors | Management, customers, partners, regulators | General public, anyone |
| Report Use | Restricted Use. For planning and performing a financial statement audit. | Restricted Use. For vendor management, due diligence, and governance. | General Use. For marketing and building public trust. |
| Level of Detail | High. Detailed description of system, controls, tests, and results. | High. Detailed description of system, controls, tests, and results. | Low. Auditor's opinion and summary assertion only. No detailed tests. |
| Key Question it Answers | "Can I rely on your controls for my financial statement audit?" | "Can I trust you to protect my data and keep your system running?" | "Can you give me a public confirmation that you have good controls?" |
Worked Example: Thinking Like an Examiner
Let's apply this with a real exam-style scenario.
Scenario: HealthData Solutions (HDS) provides cloud-based electronic health record (EHR) hosting for hospitals. One of its clients, Mercy General Hospital, is undergoing its annual financial statement audit by PwC. Separately, a potential new client, Vista Health System, is performing due diligence and is deeply concerned about patient data privacy and system availability during emergencies. HDS also wants to place a compliance seal on its website to attract new hospitals. Question: Which report is most appropriate for each party's needs? High-Scorer Thought Process:- Identify the Parties & Needs:
- PwC (User Auditor): Needs to audit Mercy General's financials. The accuracy of EHR data impacts revenue recognition and accounts receivable. This is an ICFR concern.
- Vista Health (Prospective Customer): Concerned with "patient data privacy" and "system availability." These map directly to the Privacy and Availability Trust Services Criteria.
- HDS (Service Organization): Wants a "compliance seal" for its website. This is a marketing need.
- Analyze PwC's Need:
- Objective: Financial statement audit.
- Conclusion: PwC needs a SOC 1 report. To rely on the controls and potentially reduce their testing, they need assurance on operating effectiveness over the audit period. Therefore, they need a SOC 1, Type 2 report. They would also review the CUECs to ensure Mercy General is doing its part.
- Analyze Vista Health's Need:
- Objective: Due diligence on operational and privacy controls.
- Conclusion: Vista Health needs a SOC 2 report. They need assurance that controls have been working, so they would request a SOC 2, Type 2 report covering, at a minimum, the Privacy, Confidentiality, Security, and Availability criteria. They would sign an NDA to get it.
- Analyze HDS's Need:
- Objective: Public marketing.
- Conclusion: HDS needs a SOC 3 report. It's derived from their SOC 2 examination and provides that public seal of approval without revealing sensitive internal control details.
The #1 Trap: Confusing the Data with the User's Objective
The most common mistake is focusing on the type of data instead of the user's goal.
Tempting Wrong Answer: A question describes a cloud provider that stores financial data for a bank. You immediately think, "Financial data means SOC 1." Why it's wrong: The purpose of the report dictates the choice.- If the bank's financial auditor needs the report to audit the bank's financial statements, they need a SOC 1.
- If the bank's Chief Information Security Officer (CISO) needs the report to satisfy regulators that the cloud provider meets the bank's cybersecurity standards, they need a SOC 2 (focused on the Security and Confidentiality TSC).
- Financial Statement Audit Risk → SOC 1
- Security, Operational, or Privacy Risk → SOC 2
- Marketing or Public Trust → SOC 3
Mastering this perspective-based approach is far more valuable than rote memorization. VoraPrep's adaptive learning engine, with over 9,500+ questions, is designed to drill you on these judgment calls, and our Vory tutor is available 24/7 to explain the "why" behind any question you miss.
--- Ready to Pass Your CPA Exam? Don't just memorize rules; learn to think like the examiner. VoraPrep's adaptive platform, 9,500+ practice questions with detailed explanations, and 24/7 Vory AI tutor are designed to build your judgment and confidence. We teach you how to pass. Visit voraprep.com to get started.
Start Your Free 14-Day Trial at voraprep.com →