Skip to content
Clearpoint Advisory
Important. Clearpoint Advisory is not a CPA firm, so we provide SOC 2 readiness and preparation consulting only. The formal examination and report are performed by a separate, licensed, independent CPA firm.

Guide

The SOC 1 Type 2 report, and when you need one instead of SOC 2

A SOC 1 Type 2 report shows how well a service organisation's controls over financial reporting worked across a period. So it serves your customers' auditors, rather than their security teams.

  • Preparation, not the examination
  • A licensed CPA firm signs the report
  • Plain-English guidance
Soc 1 type 2 report: confirm the need, define objectives and run the period

What a SOC 1 Type 2 report covers

SOC 1 focuses on controls relevant to your customers' financial statements. For example, payroll processing, claims handling or billing services.

The Type 2 version tests whether those controls operated effectively over a period. Therefore it carries more weight than a point-in-time Type 1.

SOC 1 Type 2 report compared with SOC 2

The two reports answer different questions. However, buyers sometimes ask for the wrong one.

TopicSOC 1SOC 2
FocusFinancial reporting controlsSecurity and related criteria
Main readersCustomers' financial auditorsCustomers' security and vendor teams
FrameworkControl objectives you defineAICPA Trust Services Criteria

SOC 1 Type 2 report readiness check

Tick what applies to your service.

Your result appears here as you tick, so you can see what is still open.

Who needs a SOC 1 Type 2 report

If your service affects how customers record money, their auditors may ask for one. Also, public company customers often need it for their own control obligations.

  • Payroll and benefits providers
  • Billing and payments processors
  • Loan or claims servicers
  • Fund administrators

How the process runs

You define control objectives and the controls that meet them. Then a licensed CPA firm tests them across the period. As a result, the report describes both design and operating effectiveness.

In addition, many companies need both SOC 1 and SOC 2. Shared controls, such as access management, can serve both examinations.

Where Clearpoint helps

Our focus is SOC 2 preparation. However, we help clients decide whether SOC 1 is the right report, and we prepare shared controls. We are not a CPA firm, so a licensed firm issues any report. Background is on the AICPA guidance on SOC 2 page.

Also confirm the request in writing. Because customers sometimes say SOC 1 when they mean SOC 2, a short email to their auditor or vendor team avoids months of wasted work. So the report you commission answers the question they actually asked. In addition, ask which period they need covered, because it decides when testing can start.

SOC 1 Type 2 report questions

Who issues a SOC 1 Type 2 report?

A licensed, independent CPA firm.

Can a SOC 1 Type 2 report replace SOC 2?

Usually not. Security teams generally want SOC 2.

How long is a SOC 1 Type 2 report period?

Commonly six to twelve months, as agreed with the CPA firm.

Do we need both reports?

Some providers do, when customers need both financial and security assurance.

Related guides

Decide whether you need a SOC 1 Type 2 report

Tell us what your customers asked for. We reply with a written view and, where it fits, a fixed preparation fee.

Scope your preparation