SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?

When a prospect asks for your “SOC report,” it's worth pausing to figure out which one they mean. SOC 1, SOC 2, and SOC 3 are three distinct reports from the AICPA, each built for a different audience and purpose. Pick the wrong one and you'll either over-invest in an audit you don't need, or hand over a report that doesn't answer your customer's question.
The short version
All three reports are issued under the AICPA's System and Organization Controls framework. Where they differ is what they evaluate and who they're written for.
- SOC 1 — Controls relevant to your customers' financial reporting. Restricted-use report.
- SOC 2 — Controls relevant to security, availability, processing integrity, confidentiality, and privacy. Restricted-use report.
- SOC 3 — A public-facing summary of your SOC 2. General-use report.
If your customers care about how you handle their data, you're looking at SOC 2 (and possibly SOC 3). If they care about how you affect their financial statements, you're looking at SOC 1.
SOC 1: built for financial reporting
A SOC 1 report exists for one reason: to give your customer's auditors the comfort they need when your services impact your customer's financial statements.
Classic examples of who needs SOC 1:
- Payroll processors
- Loan servicing platforms
- Medical claims processing
- Fund administrators
- SaaS platforms that handle billing, revenue recognition, or accounting workflows on behalf of customers
The controls in scope are the ones that, if they failed, could cause a misstatement in your customer's books. Think: change management for billing logic, access controls around financial data, completeness and accuracy of transaction processing.
SOC 1 reports come in two flavors:
- Type 1 — Design of controls at a point in time.
- Type 2 — Design and operating effectiveness over a period (usually 6–12 months).
SOC 1 is a restricted-use report. It's written for your customers and their auditors — not for marketing.
SOC 2: the one most SaaS companies need
SOC 2 is the report procurement teams ask for when they're evaluating a vendor that touches their data. It evaluates your controls against the AICPA's Trust Services Criteria:
- Security (required in every SOC 2)
- Availability (optional)
- Processing Integrity (optional)
- Confidentiality (optional)
- Privacy (optional)
Most SaaS companies start with Security only and add Availability or Confidentiality based on customer pressure or contractual commitments.
Like SOC 1, SOC 2 has a Type 1 and a Type 2 version. Type 1 covers a point in time; Type 2 covers a period — typically a minimum of three months for a first audit, then twelve months going forward. Most enterprise customers will eventually want a Type 2.
SOC 2 is also a restricted-use report. You can share it with prospects under NDA — and you absolutely should — but you can't post it on your website.
Which is exactly the gap SOC 3 fills.
SOC 3: the public version of SOC 2
SOC 3 is essentially a marketing-friendly version of your SOC 2. It uses the same Trust Services Criteria and is based on the same audit work, but it strips out the detailed control descriptions and test results. What's left is a high-level attestation you can publish on your website, hand out at trade shows, or include in sales decks without an NDA.
A few things worth knowing:
- You can only get a SOC 3 if a SOC 2 Type 2 has been (or is being) performed. SOC 3 isn't a standalone audit — it's a derivative report.
- SOC 3 is general-use. Anyone can read it.
- SOC 3 doesn't replace SOC 2. Enterprise procurement teams still want the full SOC 2 Type 2.
Think of SOC 3 as the trust badge on the homepage and SOC 2 as the document you send when a security questionnaire lands in your inbox.
Side-by-side comparison
How to choose
The decision usually comes down to three questions:
1. What do your customers' contracts and security questionnaires actually ask for?
Ninety percent of the time, this answers it for you. Read the requests instead of guessing.
2. Does your service affect your customers' financial statements?
If yes — payroll, billing, accounting, claims, fund services — you likely need SOC 1. If your customers' auditors are calling you, that's a strong signal.
3. Do your customers care about how you handle their data?
If yes, you need SOC 2. This covers most SaaS, hosting, managed services, and infrastructure providers.
Some companies need both SOC 1 and SOC 2 — for example, a billing SaaS that processes financial transactions and stores sensitive customer data. That's not unusual, just more work.
SOC 3 is rarely a starting point. It's something you add once your SOC 2 Type 2 is in place and marketing wants something they can publish.
What about ISO 27001, HIPAA, or PCI?
These often come up in the same conversation, but they're separate frameworks with their own audits and certifications. SOC reports don't replace them and they don't replace SOC reports. If you're juggling multiple frameworks, a good auditor can help you map overlapping controls so you're not doing the same work three times.
Bottom line
SOC 1 is for financial reporting. SOC 2 is for everything else customers worry about — security, uptime, data handling. SOC 3 is the public-facing version of SOC 2 you can share without an NDA.
The cleanest path for most SaaS companies: start with SOC 2 Type 1 to validate your control design, move into a SOC 2 Type 2 audit period, and add SOC 3 once you want a public-facing trust signal. If you process financial transactions on behalf of customers, layer in SOC 1.
Not sure which path fits your business? That's the kind of conversation a 30-minute call with a specialized auditor can resolve faster than another week of internal debate.

Not sure which SOC report you need?
Get a proposal in 48 hours. Start your compliance journey today.

.avif)