What is SOC 1?
A Service Organization Control 1 or SOC 1 report is documentation of the internal controls that are likely to be relevant to an audit of a customer’s financial statements.
There are two types of reports for these engagements:
Type 1
– report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date.
Type 2
– report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period.
Use of these reports is restricted to, your company, your customers, and your auditors. If you’d like a report you can share publicly, you may want a SOC 3.
View Drata Glossary
Learn more about other compliance and cybersecurity concepts in our glossary.