HomeFrameworksAssurance ReportsSOC 1

Framework  Assurance Reports

SOC 1

SOC 1 is the AICPA's report on controls at a service organization that are relevant to its customers' internal control over financial reporting. It is performed under the attestation standards (SSAE No. 18, AT-C section 320) and is meant for two audiences: the customer organizations that outsource a process, and the CPA firms that audit those customers' financial statements.

Payroll, claims processing, fund accounting, transaction processing and hosting of financial systems are the usual subjects.

To get one, the service organization must write a description of its system, define control objectives, map the controls that achieve them, and sign a management assertion. A Type 1 report covers design at a point in time; a Type 2 report also covers operating effectiveness across a period.

Because the auditor tests exactly what is described, the written procedures, approval chains and control owners have to be current and evidenced.

AI-compiled
Share
Sponsored
SOC
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with SOC 1
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary and contractual. Any service organization whose service affects a customer's financial statements will be asked for it by customers or by the customer's financial statement auditor, especially where the customer is publicly traded or regulated.

What the assessor asks to see

System description and management assertion; control objectives and control matrix; organization chart with control owners; policies and procedures for the in-scope processes; population lists (transactions, changes, access grants, terminations); sampled evidence per control (approvals, reconciliations, tickets, logs, access reviews); subservice organization SOC reports and complementary user entity controls; management review and exception handling records.

Assessors

Who assesses SOC 1

A licensed CPA firm (a firm of independent certified public accountants) that performs the examination and issues the service auditor's report. Accredited by AICPA membership and state board CPA licensure; firms performing attestation engagements are subject to the AICPA peer review program. No separate scheme accreditor.

No firm has claimed a SOC 1 assessor listing yet. Claim yours →

Consultants

Who helps with SOC 1

Yes. Readiness consultants (advisory firms, the consulting arms of CPA firms, GRC platform vendors) help write the system description, set control objectives, build the control matrix, and rehearse evidence collection. Typical engagement is a readiness assessment, remediation, then the examination, with the readiness firm kept independent from the signing firm.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TruvantisSan Francisco, CA, USANot yet verified
What they do
Full-service GRC + vCISO
Who they help
Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
vCISO.comPittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IsecurionBangalore, IndiaNot yet verified
What they do
ISO 27001 / SOC 2
Who they help
Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Illume IntelligenceCalicut, Kerala, IndiaNot yet verified
What they do
Pentest + SOC 2 readiness
Who they help
Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Precursor SecurityLeeds, UKNot yet verified
What they do
ISO 27001 + CREST pentest
Who they help
Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. What is a SOC 1 report and who needs one?A CPA firm explains control objectives, Type 1 versus Type 2, and the complementary user entity controls that trip clients up.Linford & Co
  2. SOC reports explained: building trust in the services you provideSets SOC 1 next to the other SOC reports so you can tell which one a customer's finance auditor is actually asking for.Warren Averett

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for SOC 1

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with SOC 1

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.