SOC 1
Compliance

Readiness and control support for SOC 1 — the report covering your controls relevant to your customers’ internal control over financial reporting (ICFR) — for both Type I and Type II.

Overview

Assurance for financial reporting.

If your service affects your customers’ financial reporting — payroll, payments, billing, or financial platforms — their auditors will ask for a SOC 1 report. It attests to the controls at your organisation that are relevant to their internal control over financial reporting.

We run the readiness assessment, define control objectives and activities, set up evidence collection, and coordinate with your CPA through Type I and Type II. Where you also need security assurance, we align SOC 1 with SOC 2 and ISO 27001 to avoid duplication.


Scope

What we deliver.

Control objectives and evidence for financial-reporting assurance.

Framework: AICPA SSAE 18 ISAE 3402 Type I & Type II ICFR controls

FAQ

SOC 1 FAQ

The questions we're asked most about scope, cost, and timing.

How much does SOC 1 cost?
SOC 1 readiness support is typically €2,500–4,000 per month over 3–6 months, separate from the auditor’s fees. Use our estimator for a tailored figure.
What is the difference between SOC 1 and SOC 2?
SOC 1 covers controls relevant to your customers’ financial reporting (ICFR). SOC 2 covers security and the other Trust Service Criteria. Many service providers need both, and they can be delivered together.
Who needs a SOC 1 report?
Service organisations whose services affect customers’ financial statements — payroll, payments, billing, loan servicing, and similar — where customers’ auditors require assurance.
What is the difference between Type I and Type II?
Type I assesses control design at a point in time; Type II assesses operating effectiveness over a period (usually 3–12 months).
Do you perform the SOC 1 audit?
No — a licensed CPA firm performs the examination. We prepare you and coordinate with the auditor throughout.
How do we know if we need SOC 1 or SOC 2?
SOC 1 is for when your service affects customers’ financial reporting; SOC 2 is for security and related criteria. We help you confirm which (or both) you need.
What standard is SOC 1 performed under?
SSAE 18 (US) and/or ISAE 3402 (international); we prepare you for the relevant one for your customers.
Who defines the control objectives?
You do, with our help — they reflect the services you provide that are relevant to your customers’ financial reporting.
How long does SOC 1 take?
Readiness typically takes 3–6 months, with a Type II observation window afterwards.
Can SOC 1 and SOC 2 be done together?
Yes — where you need both, we align the work and evidence to reduce duplication.

Related services

Explore more.

Ready to start SOC 1?

A 30-minute scoping call costs nothing. A blocked customer audit costs considerably more.

Book a meeting Send an email