3.1 AICPA Attestation Framework: SSAE No. 18/21 & SOC 1 vs. SOC 2 vs. SOC 3
Analyze the professional attestation standards governing service organization examinations (SSAE No. 18 / SSAE No. 21, codified in AT-C Sections 105, 205, and 320), comparing the specific subject matters and distribution restrictions of SOC 1, SOC 2, and SOC 3 reports.
🎯 Essential Technical Takeaways
- SSAE No. 18 (as amended by SSAE 21) governs examination engagements for service organizations under AICPA AT-C codification.
- SOC 1 reports (AT-C 320) evaluate controls relevant to user entities' Internal Control Over Financial Reporting (ICFR).
- SOC 2 reports evaluate controls relevant to Security, Availability, Processing Integrity, Confidentiality, and Privacy (non-financial systems).
- SOC 1 and SOC 2 reports are Restricted-Use (confidential); SOC 3 reports are General-Use for unrestricted public marketing.
When organizations outsource core business functions to third-party service providers (such as cloud hosting, payroll processors, or SaaS platforms), user entity management and their independent auditors require formal assurance regarding the service provider's internal controls. The American Institute of Certified Public Accountants (AICPA) establishes the professional standards governing these examinations under Statements on Standards for Attestation Engagements (SSAE) No. 18, as amended by SSAE No. 21, codified in AT-C Sections 105, 205, and 320.
The AICPA SOC suite provides three distinct reporting frameworks: (1) SOC 1 (SSAE 18 / AT-C 320): specifically evaluates controls at a service organization that are relevant to user entities' Internal Control Over Financial Reporting (ICFR). It is designed for financial statement auditors evaluating outsourced transactions that flow into general ledgers (e.g., payroll, trust administration, loan servicing); (2) SOC 2: evaluates technology and cloud systems relevant to one or more Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) where data does not directly impact user financial statements; and (3) SOC 3: covers the same Trust Services Criteria as SOC 2, but is sanitized into a general-use summary report intended for unrestricted public distribution and marketing.
SOC 1 and SOC 2 reports are legally classified as 'Restricted-Use' attestation documents. They disclose proprietary network diagrams, security control definitions, and detailed auditor test procedures and results. Sharing a SOC 1 or SOC 2 report requires an executed Non-Disclosure Agreement (NDA) to protect against exposing internal system architecture to adversaries.
⚠️ CPA Evolution Exam Traps & Control Pitfalls
- Selecting a SOC 1 report for a cloud SaaS application that does not impact financial statement balances.
- Distributing a restricted-use SOC 2 report publicly without an executed Non-Disclosure Agreement (NDA).
- Citing SAS 70 or SSAE 16 on modern examinations (both are obsolete, superseded standards).
Interactive Knowledge Checkpoint
A CPA firm performs attestation examinations for service organizations. Under the AICPA Statements on Standards for Attestation Engagements (SSAEs), which codified standard currently governs examination engagements for System and Organization Controls (SOC 1 and SOC 2)?