There are two main types of SOC 1 audits – the Type I and Type II reports. Each report covers three important areas:
- Mangement’s Assertion
- Mangement’s Description of the System
- Design of the Controls and Test Results
However, there are some important differences between the two reports:
- The Type 1 Audit – A SOC 1SM Type 1 report is a point-in-time report that audits the controls on a specific date.
- The Type 2 Audit – A SOC 1SM Type 2 report audits the controls over a period of time, typically a full year. It also determines the effectiveness of the control activities from a financial auditing standpoint.
SOC 1 Type 2 audits are not to be confused with SOC 2 audits, which is a different type of SOC compliance report altogether. The AICPA also released a fourth type of audit, the SOC for Cybersecurity report, in May 2018. Unlike SOC 1 and SOC 2 reports, the SOC for Cybersecurity audit can be performed by any type of organizations, and it provides an in-depth evaluation of a company’s cybersecurity risk management program.