SOC 1 vs SOC 2 is not a contest between a weaker report and a stronger one. The two examinations were written to answer different questions, and which one is relevant to you is decided by the work leaving your firm.
Hand over close work, reconciliations or prepared returns and you are standing in financial reporting territory. Hand over client records and you are standing in security territory. An engagement that hands over both the close and the client files sits in both at once, which is why partners keep receiving an answer that does not fit the question they asked.
What a SOC 1 Report Is, and Who It Was Written For
Start with the audience, because it explains everything else about the document.
The AICPA describes SOC 1 as an examination of controls at a service organization likely to be relevant to user entities' internal control over financial reporting, and it names the readers without ambiguity. SOC 1 reports "are specifically intended to meet the needs of entities that use service organizations (user entities) and the CPAs that audit the user entities' financial statements (user auditors), in evaluating the effect of the controls at the service organization on the user entities' financial statements" (AICPA, SOC 1 for Service Organizations: ICFR).
Three terms of art sit in that sentence, so take them one at a time. AU-C section 402 defines a user entity as an entity that uses a service organization and whose financial statements are being audited, and a service organization as an organization or segment of an organization that provides services to user entities that are relevant to those user entities' internal control over financial reporting, shortened throughout the standards to ICFR (AICPA, AU-C section 9402, Interpretation No. 1). The third is the user auditor, which AT-C section 320 defines as an auditor who audits and reports on the financial statements of a user entity (AICPA, U.S. Attestation Standards, AT-C section 320).
Read plainly, a SOC 1 report exists so that whoever audits a set of financial statements can decide how much of the work done outside those walls they are able to rely on. That is why the request usually arrives from an auditor rather than from a procurement team.
Why the AICPA Calls a SOC 1 the Preferred Report Here
The preference is not a matter of taste. It is written down.
A SOC 1 report "addresses the risks related to a financial statement audit and is intended to complement AU-C section 402", and the AICPA states that such a report or an equivalent "is the preferred report for use in an audit of a user entity's financial statements" (AICPA, AU-C section 9402, Interpretation No. 1). The examination behind it is performed under AT-C section 320, the attestation standard built for exactly this purpose.
What a SOC 2 Report Covers, and the Five Trust Services Categories
A SOC 2 engagement points somewhere else, at the system rather than at the ledger.
It is an examination of controls over the security, availability or processing integrity of a system, or the confidentiality or privacy of the information that system processes, and it is performed under AT-C section 205 rather than AT-C section 320 (AICPA, AU-C section 9402, Interpretation No. 1).
Those five headings have a proper name. They are the trust services categories of criteria, commonly called the trust services criteria, and the AICPA lists them as security, availability, processing integrity, confidentiality and privacy (AICPA, AU-C section 9402, Interpretation No. 1). A provider whose report covers security alone has a narrower report than one covering several of the categories, and the report's stated scope tells you which.
How to read such a report once it is in front of you, and why a badge on a website is not that report, is covered in whether outsourcing accounting is safe.
Type 1 vs Type 2, the Distinction That Decides What You Learn
It is a small distinction on the page and a large one in practice.
AT-C section 320 defines a type 1 report as management's description of a service organization's system together with a service auditor's report on that description and on the suitability of the design of controls, and a type 2 report as the same description with a service auditor's report on the suitability of the design and operating effectiveness of controls (AICPA, U.S. Attestation Standards, AT-C section 320). The service auditor in both is the practitioner who reports on controls at a service organization, which means the provider's examiner rather than anyone on your side.
The timing follows from that. A type 1 opinion speaks as of a specified date, so it tells you the controls looked sensibly designed on one day. A type 2 opinion speaks to whether those controls operated effectively throughout the specified period, which is the only version that tells you anything about how a provider held up over time.
The labels travel across both families. A SOC 2 report also comes in a type 2 form, and the AICPA describes the restricted-use paragraph in a type 2 SOC 2 report as naming its intended users, who include user entities of the system during some or all of the period covered and practitioners providing services to those user entities (AICPA, AU-C section 9402, Interpretation No. 1). A user auditor qualifies as one of those practitioners, so a report restricted to named users still reaches the auditor of a user entity's financial statements.
If you are handing over a busy season, a design opinion taken on a single date is not evidence about a season.
SOC 1 vs SOC 2: The Decision Rule You Can Actually Apply
Stop asking which report a provider has and start with what you are about to send them.
Work that feeds the financial statements raises the SOC 1 question. That is the close, the reconciliations, the payables run, the prepared return that becomes a number in someone's books. Work that is mostly about holding, transmitting and accessing client records raises the SOC 2 question. An engagement raises both when one team touches the ledger and the files in the same week.
Here is what each report answers, side by side.
| Comparison point | SOC 1 report | SOC 2 report |
|---|---|---|
| What it examines | Controls likely to be relevant to a user entity's internal control over financial reporting | Controls over the security, availability or processing integrity of a system, or the confidentiality or privacy of the information it processes |
| Performed under | AT-C section 320 | AT-C section 205 |
| Written to be read by | User entities and the CPAs auditing their financial statements | User entities of the system during some or all of the period covered, and practitioners providing services to them |
| What the type 2 version adds | Operating effectiveness of controls across a stated period | Operating effectiveness of controls across a stated period |
Sources: AICPA, SOC 1 for Service Organizations: ICFR and AICPA, AU-C section 9402, Interpretation No. 1.
Why One Cannot Simply Stand In for the Other
Providers offer the report they have. The AICPA has already answered whether it does the job.
A SOC 2 report "is not specifically designed to address controls at a service organization relevant to a user entity's ICFR and therefore is unlikely to achieve the intent of the requirements in AU-C section 402" (AICPA, AU-C section 9402, Interpretation No. 1). Areas such as logical access and change management may overlap, but in a SOC 2 engagement the service auditor's tests of those controls may be designed to address a different set of risks and are "unlikely to provide sufficient appropriate audit evidence regarding controls at a service organization relevant to a user entity's ICFR".
That does not make a SOC 2 report useless to you. It makes the report the wrong instrument for one specific job, and that is exactly the job it gets handed when a firm accepts a security report as cover for outsourced close work.
The Two Reports Do Not Assign You the Same Duties
Complementary user entity controls are the things a provider assumes you will keep doing so that its own controls work at all, and reports in both families describe them.
The lists are scoped differently. In a SOC 2 report they support the provider's service commitments and system requirements, while in a SOC 1 report they support control objectives relevant to your ICFR, so "it is unlikely that a SOC 2 report will include the same set of CUECs that would be included in a SOC 1 report addressing similar services" (AICPA, AU-C section 9402, Interpretation No. 1). The same guidance leaves open that a SOC 2 report names none of the ones that matter to financial reporting, because it tells a user auditor to identify the CUECs in a SOC 2 report, if any, that would need to be implemented to achieve control objectives relevant to the user entity's ICFR. Reading one list and assuming it covers the other leaves duties sitting on your side of the arrangement with nobody assigned to them.
The payables version of that list, the one that decides whether a payment can be redirected, is worked through in the accounts payable outsourcing case study.
When Your Firm Is the Service Organization
The definition runs in both directions, and firms rarely notice the second one.
If your practice keeps a client's books or runs its close, and that client's financial statements are audited, your firm can meet the standards' definition of a service organization to that client (AICPA, AU-C section 9402, Interpretation No. 1). Whether that ever turns into a request for a report of your own depends on the auditor and on how significant your work is to those statements.
It is worth knowing before the call comes, because the answer shapes how you document what you do. What a client accounting practice takes on in the first place is set out in client accounting services, and one everyday example of an outside party sitting inside a client's numbers is the plan recordkeeper in employee benefit plan audits.
SOC 3, and What a Freely Published Report Is Worth
SOC 3 is the version built to be handed out, which is why a provider can publish one in full while its SOC 2 report stays restricted to named users.
Like SOC 2, SOC 3 reports address controls relevant to security, availability, processing integrity, confidentiality and privacy. The AICPA adds the limitation in the same breath: "they do not provide the same level of detail" and "therefore, they are considered general use reports and can be freely distributed" (AICPA, SOC 3 for Service Organizations: Trust Services Criteria for General Use Report).
Treat it as a summary you may keep. It is not the document your assessment runs on, and asking for the detailed report is a reasonable next request rather than an aggressive one.
What Covers the Gap After the Period Ends
Every type 2 opinion has an end date, and the calendar keeps moving after it.
Between that period end and the day you are reading it sits an interval that nobody examined, and it grows every month until the next report lands. So ask what covers the time since the period ended. If the answer is a letter from the provider's management about the interval, read it as exactly that, a statement by management, because the service auditor's opinion still speaks only to the period inside the report. The cost of running the assessment yourself when no examination sits behind the answer is priced out in the hidden costs of outsourcing.
Questions Firms Ask
What Does SOC 1 Stand For?
SOC is system and organization controls, the AICPA's term for the suite of services practitioners may provide relating to system-level controls of a service organization and system or entity-level controls of other organizations (AICPA, AU-C section 9402, Interpretation No. 1). The number marks which question the report was written to answer, not a ranking.
Is SOC 2 Legally Required?
No. What binds a US firm sending client data outside its walls is a set of its own duties, selecting and contracting for safeguards and then reassessing the provider periodically, plus a client's consent, which stays the client's to give when return information is disclosed. None of that names a SOC report, and what each duty asks of you is set out in whether outsourcing accounting is safe. A SOC report is evidence you can use while discharging them, not a filing anyone submits.
What Is SOC 1, SOC 2 and SOC 3?
SOC 1 reports on controls relevant to a user entity's financial reporting, and its reader is the auditor of those financial statements. SOC 2 reports on controls over a system, judged against the trust services criteria. SOC 3 covers the same subject matter as SOC 2 in less detail, in a form built to be given out.
Ask the Question That Matches the Work
Which report matters is a question about the work, not about the vendor's marketing.
Write down what you are actually handing over before the next engagement starts. If any of it lands in the path to the financial statements, the SOC 1 question is live, and the reader who cares is whoever audits those statements, which is usually a client's auditor rather than your own. If client records are moving, the SOC 2 question is live. Then ask each provider which report covers that work, whether it is a type 2, and what period it covers.
Apply the same test to us. Accountably's controls are SOC 2-aligned, so a firm assessing us runs that assessment itself rather than reading a report, and we would rather say so than let a badge imply more.
What we can put on your desk is the half of the question no attestation reaches, which is whether the work is any good. Don't trust us. Test us. The Free 40-Hour Proof Pilot puts a block of your own representative work through the full review chain on your software and your procedures, so your reviewer grades real output before a client file is committed.
