SOC report content and structure

Area 3: SOC Engagements (15-25%)

Your Progress

0 of 59 questions attempted

Topics

  • Management description and assertions
  • Complementary user/subservice controls

Lessons

Study Frameworks

SOC Report Comparison

FeatureSOC 1SOC 2SOC 3
FocusControls over financial reporting (ICFR)Trust Services Criteria (SAPCP)Trust Services Criteria (summary)
StandardSSAE 18 / AT-C 320AT-C 205AT-C 205
AudienceUser entities and their auditorsManagement, regulators, specified partiesGeneral public
DistributionRestrictedRestrictedGeneral use
Type IDesign at a point in timeDesign at a point in timeN/A (Type II only)
Type IIDesign + effectiveness over a periodDesign + effectiveness over a periodShort-form report based on SOC 2 Type II
Typical period6-12 months6-12 monthsSame period as companion SOC 2 Type II
Practice These Topics(59 questions)