SOC 1
A SOC 1 report is an examination of controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting. Its readers are the customer's management and the customer's financial statement auditors. Payroll processors are typical issuers.
SOC 1 uses control objectives that the service organization defines, such as making sure payroll transactions are authorized and recorded accurately. It comes in Type 1 and Type 2 versions, like SOC 2.
Canadian banks, insurers, and public companies often ask outsourced providers for a SOC 1 or CSAE 3416 report near year end, so their own auditors can plan how much to rely on the provider's controls.
SOC 2
A SOC 2 report covers controls relevant to security, availability, processing integrity, confidentiality, or privacy, measured against the AICPA Trust Services Criteria rather than objectives the company writes itself. It's meant for customers, prospects, and their auditors who need to assess outsourcing risk. Its use is restricted. Because it contains detailed descriptions of systems and controls, it is normally shared only under a non-disclosure agreement.
SOC 3
A SOC 3 report covers the same 5 categories as SOC 2 but gives far less detail. It omits control lists and test results. It is a general use report that can be freely distributed, which is why companies often post it on their trust or security page.
A SOC 3 is usually issued alongside a SOC 2 Type 2 from the same examination. It works as a public signal, but most security reviewers will still ask for the full SOC 2.
Canadian equivalents
Canada has its own standard. CSAE 3416, Reporting on Controls at a Service Organization, addresses reasonable assurance engagements on controls relevant to customers' financial reporting, and is close to SOC 1. It supplements CSAE 3000 and comes in Type 1 and Type 2 forms. According to CPABC, only CPAs licensed in the audit category of public practice can issue CSAE 3416 reports.
Canadian standards don't include a specific equivalent of SOC 2 or SOC 3. An engagement under CSAE 3000, Attestation Engagements Other than Audits or Reviews of Historical Financial Information, using the Trust Services Criteria, can achieve the same purpose. Expectations vary. Some customers, especially in the United States, will specifically ask for an AICPA SOC 2, so confirm what they expect.
Other SOC reports
The AICPA also offers SOC for Cybersecurity, which reports on an entity's cybersecurity risk management program as a whole, and SOC for Supply Chain, which covers controls at an organization that produces, manufactures, or distributes products. Both are much less common than SOC 1 and SOC 2 in vendor reviews, and few Canadian procurement teams ask for them today.
Which one to ask for
Ask for SOC 1 when a vendor's service affects your financial statements and your external auditor needs to rely on its controls. Ask for SOC 2 when you need to understand how a vendor protects your data and keeps its service running. Treat SOC 3 as a screening document. Some vendors provide both a SOC 1 and a SOC 2, covering different audiences with different reports.
Resources
- 2017 Trust Services Criteria (With Revised Points of Focus - 2022), AICPA and CIMA
- SOC 2: SOC for Service Organizations: Trust Services Criteria, AICPA and CIMA
- SOC 3: Trust Services Criteria for General Use Report, AICPA and CIMA
- Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Security
- Reports on Controls at Service Organizations FAQs, Chartered Professional Accountants of British Columbia
References
- SOC 1: SOC for Service Organizations: ICFR, AICPA and CIMA
- SOC 3: SOC for Service Organizations: Trust Services Criteria for General Use Report, AICPA and CIMA
- Reports on Controls at Service Organizations FAQs, Chartered Professional Accountants of British Columbia
General information, reviewed 2026-10-11. Not legal advice.