SOC 1 VS SOC 2 · READINESS FROM $9,000

SOC 1 or SOC 2? Your buyer already knows.

One report answers to your client's auditor. The other answers to your client.


A reviewer with hair tied back, in a charcoal blazer over a white shirt, seated at a dark stone desk by a window in a warm, low-lit office, writing on a loose printed page with a stoneware cup beside them.
Independent means no stake in the answer
Financial reporting Customer data AT-C 320 AT-C 205 Type I or II

Our promise

“Buy the wrong report and you pay twice.”

This is the SOC 2 readiness fee. SOC 1 is quoted after a scoping call, and either opinion is a licensed CPA firm’s, never ours. The fee is fixed at $12,500, and nothing is charged until you approve it.

Request this readiness scan
The case file

Two reports, in three chapters

The Pair

Two reports, two questions. A SOC 1 asks whether the controls at your organisation are sound enough for your client’s auditor to rely on while auditing their books. A SOC 2 asks whether the data your customers hand you is properly looked after. They are not two tiers of a single thing.

The Mistake

A customer writes “send us your SOC report” and nobody asks which one. A quarter later the window has closed on the wrong one, and it cannot be exchanged. A SOC 2 will not satisfy an auditor who asked for a SOC 1, however thorough that report is, and the money has been spent either way.

The Office

Our job is the read before the audit. We start from the request in the words it arrived in, settle which of the two answers it, draw the boundary, and cost what is missing. A licensed CPA firm signs either opinion, and we issue neither report and sell no software, so nothing steers the answer.

The two reports

Two reports. Two different readers.

A SOC 1 is read by your client’s financial auditor. A SOC 2 is read by your client.

SOC 1 — controls over financial reporting № 01
  • Issued under - SSAE No. 18, AT-C section 320
  • Tested against - control objectives you state yourself
  • Read by - user entities and their auditors, restricted
  • Asked for by - clients carrying SOX obligations
SOC 1 · iDharma · Presented for assay
SOC 2 — security, and what you elect № 02
  • Issued under - SSAE No. 18, AT-C section 205
  • Tested against - the AICPA Trust Services Criteria
  • Read by - customers, prospects and partners, on NDA
  • Asked for by - procurement and security reviewers
SOC 2 · iDharma · Presented for assay
Know which is yours

One is about money. One is about data.

SOC 1

When you touch a client's books

A SOC 1 covers the controls you run that reach your client's financial statements. Payroll, payments, loan servicing, insurance claims. Their auditor reads it while auditing them, which is why distribution is restricted and why the request nearly always arrives from an accountant rather than a buyer.

SOC 2

When your client's data sits with you

A SOC 2 covers security first, and then whichever of availability, processing integrity, confidentiality and privacy you elect. It is read by your customers and your prospects rather than by anybody's auditors, and it is the report that arrives attached to an enterprise security questionnaire mid-deal.

The catch

Sometimes the answer is both

A payroll company that also sells an HR platform can need a SOC 1 for the payroll processing and a SOC 2 for the platform. That is two engagements with two system descriptions, not one report carrying two badges - and the reason to settle it early is that each one draws its own boundary.

What most teams assume

“A SOC report is a SOC report, surely.”

What the request says

Neither stands in for the other. Ask which.

It is the most common finding we write up.

  • Who it is for
  • SaaS & platform vendors
  • Payroll & payments firms
  • Security & GRC leads
  • Finance & procurement
  • Founders answering an RFP
Why the choice matters
A row of dark leather-bound volumes on a shelf under a low warm light, one drawn forward and standing slightly open with pale paper tabs marking pages inside it and a ribbon hanging from the fore-edge.
01 SOC 2 is the report technology buyers ask for. SOC 1 exists for a narrower reason: your service changes a number that lands in your client’s financial statements.
02

A SOC 2 cannot stand in for a SOC 1. If your client’s auditor asked for one, the other will not satisfy the request.

03

Both reports come as Type I or Type II. Most enterprise contracts mean Type II, which covers a period rather than a day.

04

A payroll firm that also sells HR software can need both — one per service line, each with a boundary of its own.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

Reach -

This is the SOC 1 test, in plain words. Payroll runs, payments moved, loans serviced, claims settled - amounts your client books because you calculated or moved them. Holding their data is not the same thing.

Requester -

The requester is the strongest signal there is. An accountant asking while auditing your client wants a SOC 1. A procurement or security team running a vendor review wants a SOC 2. They rarely want the other one.

Type -

Type II covers a period, Type I a single day. Both SOC 1 and SOC 2 come either way. Paying for a Type I when the contract named a Type II is the most avoidable spend on this page, and one email settles it.

The calendar

Four moments, and the first one decides.

Whichever report you end up holding was chosen at week zero, by whoever sent the request - everything after that is downstream of one reading.

  1. Asked

    Week zero

    The request arrives, from a client's auditor or from a buyer's security review. Which one settles the rest.

  2. Scoped

    Weeks 1-4

    Which report, which services sit inside the boundary, and which criteria you elect beyond Security.

  3. Observed

    3 to 12 months

    A Type II watches controls operate across a window you choose. Either report can be issued that way.

  4. Renewed

    Every 12 months

    Both reports cover a period and then stop. Budget either one as a subscription rather than a project.

The trap

Teams read “we need a SOC report” and start the cheapest engagement that matches the phrase. The choice was never theirs to make — it was made by whoever sent the request, and it cannot be corrected once the window has run.

Side by side

What separates them, and what we do about it

12 lines on which the two reports differ, and the artefact that answers each one. Paired, so every claim on this page can be checked against the line beside it.

What it is about SOC 1 financial reporting. SOC 2 security and data
Which question your report has to answer, settled from the request itself rather than from whichever report is easier to get.
Who reads it SOC 1 their auditor. SOC 2 your customer
Named before scoping, because a restricted-distribution report you cannot hand to a prospect is a cost with no sales use.
The standard it is issued under AT-C 320 for SOC 1. AT-C 205 plus the criteria for SOC 2
Confirmed in writing with the CPA firm, so the engagement letter names the section the requester actually asked about.
Whether one can stand in It cannot - a SOC 2 does not satisfy a SOC 1 request
Checked against the wording of the request before anything is commissioned, which is the cheapest hour on this page.
Type I or Type II Both reports come either way, and it moves everything
Which one your requester actually asked for, in writing, before you pay for the more expensive answer to the wrong question.
The observation window Commonly three to twelve months, and you choose it
What a shorter window costs you in credibility and a longer one costs you in time, set against who is asking for the report.
Which criteria are elected SOC 2 only - Security always, the other four by choice
Which of the four a buyer has actually named, so you are not tested against criteria nobody asked you to carry.
The system boundary Drawn per service, and the two reports rarely share one
What sits inside each report, and whether one engagement can honestly cover a processing service and a software product.
Whether controls produce evidence The same question for either report, every time
Which controls throw off their own evidence and which need a human with a screenshot tool every quarter, named one by one.
Needing both reports Real, and commoner than the comparison pages suggest
Whether your service lines genuinely split that way, so you commission two engagements deliberately rather than discovering it late.
What drives the request SOC 1 a client's SOX work. SOC 2 enterprise procurement
Traced back to the person who asked, because the driver tells you what they will accept and when they need it.
Renewal and the bridge Annual for both, plus a bridge letter between reports
What holding either report costs every year after the first, which is the line that decides whether starting was worth it.
The engagement

Your control set, independently read

For either report, and for the case where you need both.

  1. Read the request

    Who asked, what they named, and which of the two reports would actually satisfy them.

  2. Draw the boundary

    Which services sit inside, which criteria you elect, and whether one report covers them all.

  3. Price and sign off

    You see the draft first. Then the gap list, the shortlist and the costed plan - dated.

Request your readiness review
An auditor in a charcoal suit and open-collared white shirt, with dark curly hair, standing against a warm pale wall and pointing into the open space alongside.
The record is what you are buying.
Struck in your favour

Why teams ask iDharma which report they need

We sell no software

No platform to license, no seats to grow, and no reason to call your spreadsheet a gap.

We issue neither report

A licensed CPA firm signs both opinions. We read you before either one, and we say so on every page.

One fixed fee, published

The SOC 2 readiness price is published here and in the checkout, and no finding we make changes it.

We read the request first

The wrong report is the most expensive mistake here, and it is settled before a scope is drawn.

Four marks, struck on every readiness report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Report selection memo

The whole reading in one document: which report the request actually calls for, what would sit inside its boundary, whether your service lines split across two engagements, which criteria you would elect, which controls already produce their own evidence, and what each remaining gap takes to close.

Workbook

Side-by-side comparison

Every line this page compares, as a sheet you can edit - the standard, the readers, the drivers and the type, set against your own answers.

Report

Criteria gap report

Each elected criterion, or each control objective in a SOC 1, set against the control you run, with the evidence it produces named.

Index

Evidence index

Which controls throw off their own evidence, which need a person each quarter, and what that costs across a Type II window.

Memo

Boundary memo

What sits inside each report and what was deliberately left out, with the reason for every call written down rather than assumed.

Ranked

Remediation shortlist

What to fix before fieldwork and what can wait, ranked by what the opinion is at risk on rather than by what is quickest.

Templates

Requester question sheet

What to ask the person who requested a report - which one, Type I or Type II, which criteria, by when, and what they will accept.

Format & fee

Real numbers, upfront.

Scope
Set by the request, not by us
Input
Your controls, policies, evidence
Re-read
Annually, or on a scope change - a new service line, a new criterion, a new requester.

The request fixes the scope, so the fee is flat - and nothing is charged until you approve it.

Request your scan
SOC 2 · Readiness review $12,500 flat
  • Which report the request calls for
  • Criteria gap read, control by control
  • Boundary memo for each service line
  • A dated evidence trail you keep
Show your hand

Four things to settle before you commission

None of these is a judgement call once you have asked. Each is either written down somewhere, or it is not.

The request,
read

Who asked, in what words, and which report would satisfy them. An auditor asking under a client's SOX work and a buyer running a security review want different documents.

The boundary,
drawn

Which services sit inside the report and which are deliberately outside it. A processing service and a software product rarely belong inside one description, and that line is cheaper drawn once.

The type,
named

Type I opines on control design at a point in time; Type II tests operation across a period. Both reports come either way, most enterprise contracts mean the second, and the requester knows which.

The period,
dated

Every report covers a window and then expires. What it costs to hold in year two, and the bridge letter covering the gap between one report ending and the next landing, belong in the first plan.

Four questions, and one email answers all of them.

FAQ

Plain answers

Which report, which type, and what it costs to get it wrong.

Request your scan
SOC 1 or SOC 2 - which one do we need?

SOC 1 if your service changes numbers that land in your client's financial statements. SOC 2 if you store, process or transmit their data. Most technology companies need SOC 2, and the fastest way to be sure is to ask whoever requested a report which one they named.

Is SOC 2 harder to get than SOC 1?

Not necessarily. The difficulty depends on the controls you already run. SOC 2 carries more security-focused criteria, SOC 1 concentrates on financial-reporting controls, and for most technology companies SOC 2 is closer to what they already do.

Can a SOC 2 report replace a SOC 1?

No. They serve different purposes and are issued under different sections of SSAE No. 18. If your client's auditor has asked for a SOC 1, a SOC 2 report will not satisfy that request, however thorough it is.

Which report is requested more often?

SOC 2, by a wide margin, among technology buyers - enterprise customers commonly require it during vendor security review. SOC 1 is requested mainly by clients carrying SOX obligations of their own.

Can a company genuinely need both?

Yes, and it is commoner than most comparison pages suggest. A payroll company that also sells HR software may need a SOC 1 for the processing and a SOC 2 for the platform - two engagements, each with its own boundary.

Get started

Request your readiness review

Send us the request in the words it arrived in, and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. The first item is an email you were sent, and the rest is a folder someone can assemble in an afternoon - we name each one first.

  1. The request, in the words it arrived in
  2. Which services you would put inside the boundary
  3. Who asked, and what they said they need it for
  4. Any documentation - policies, prior reports
  5. Where your evidence lives today, and who collects it

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • AICPA SSAE No. 18, AT-C section 320
  • AICPA SSAE No. 18, AT-C section 205
  • AICPA Trust Services Criteria (rev. 2022)
SSAE 18 effective
1 May 2017
Criteria revised
2022

What it means

  • General information about how the two reports differ — not legal or accounting advice, and no professional relationship arises from reading it. It determines nothing about your own services.
  • Where the choice between them is arguable, our reports say so rather than the convenient one.

Scope & limitation

  • Only the $9,000 SOC 2 readiness fee is ours - both opinions are a CPA firm's.
  • Whether a given auditor accepts a given report is their call, not this page's.
  • Do not rest a binding decision on it; engage qualified counsel.

Something on this page out of date?

Tell us