Two reports, two questions. A SOC 1 asks whether the controls at your organisation are sound enough for your client’s auditor to rely on while auditing their books. A SOC 2 asks whether the data your customers hand you is properly looked after. They are not two tiers of a single thing.
SOC 1 or SOC 2? Your buyer already knows.
One report answers to your client's auditor. The other answers to your client.
Our promise
“Buy the wrong report and you pay twice.”
This is the SOC 2 readiness fee. SOC 1 is quoted after a scoping call, and either opinion is a licensed CPA firm’s, never ours. The fee is fixed at $12,500, and nothing is charged until you approve it.
Request this readiness scanTwo reports, in three chapters
A customer writes “send us your SOC report” and nobody asks which one. A quarter later the window has closed on the wrong one, and it cannot be exchanged. A SOC 2 will not satisfy an auditor who asked for a SOC 1, however thorough that report is, and the money has been spent either way.
Our job is the read before the audit. We start from the request in the words it arrived in, settle which of the two answers it, draw the boundary, and cost what is missing. A licensed CPA firm signs either opinion, and we issue neither report and sell no software, so nothing steers the answer.
Two reports. Two different readers.
A SOC 1 is read by your client’s financial auditor. A SOC 2 is read by your client.
- Issued under - SSAE No. 18, AT-C section 320
- Tested against - control objectives you state yourself
- Read by - user entities and their auditors, restricted
- Asked for by - clients carrying SOX obligations
- Issued under - SSAE No. 18, AT-C section 205
- Tested against - the AICPA Trust Services Criteria
- Read by - customers, prospects and partners, on NDA
- Asked for by - procurement and security reviewers
One is about money. One is about data.
When you touch a client's books
A SOC 1 covers the controls you run that reach your client's financial statements. Payroll, payments, loan servicing, insurance claims. Their auditor reads it while auditing them, which is why distribution is restricted and why the request nearly always arrives from an accountant rather than a buyer.
When your client's data sits with you
A SOC 2 covers security first, and then whichever of availability, processing integrity, confidentiality and privacy you elect. It is read by your customers and your prospects rather than by anybody's auditors, and it is the report that arrives attached to an enterprise security questionnaire mid-deal.
Sometimes the answer is both
A payroll company that also sells an HR platform can need a SOC 1 for the payroll processing and a SOC 2 for the platform. That is two engagements with two system descriptions, not one report carrying two badges - and the reason to settle it early is that each one draws its own boundary.
“A SOC report is a SOC report, surely.”
Neither stands in for the other. Ask which.
It is the most common finding we write up.
- Who it is for
- SaaS & platform vendors
- Payroll & payments firms
- Security & GRC leads
- Finance & procurement
- Founders answering an RFP
A SOC 2 cannot stand in for a SOC 1. If your client’s auditor asked for one, the other will not satisfy the request.
Both reports come as Type I or Type II. Most enterprise contracts mean Type II, which covers a period rather than a day.
A payroll firm that also sells HR software can need both — one per service line, each with a boundary of its own.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your scope check
Four moments, and the first one decides.
Whichever report you end up holding was chosen at week zero, by whoever sent the request - everything after that is downstream of one reading.
-
Asked
Week zeroThe request arrives, from a client's auditor or from a buyer's security review. Which one settles the rest.
-
Scoped
Weeks 1-4Which report, which services sit inside the boundary, and which criteria you elect beyond Security.
-
Observed
3 to 12 monthsA Type II watches controls operate across a window you choose. Either report can be issued that way.
-
Renewed
Every 12 monthsBoth reports cover a period and then stop. Budget either one as a subscription rather than a project.
Teams read “we need a SOC report” and start the cheapest engagement that matches the phrase. The choice was never theirs to make — it was made by whoever sent the request, and it cannot be corrected once the window has run.
What separates them, and what we do about it
12 lines on which the two reports differ, and the artefact that answers each one. Paired, so every claim on this page can be checked against the line beside it.
- What it is about SOC 1 financial reporting. SOC 2 security and data
- Which question your report has to answer, settled from the request itself rather than from whichever report is easier to get.
- Who reads it SOC 1 their auditor. SOC 2 your customer
- Named before scoping, because a restricted-distribution report you cannot hand to a prospect is a cost with no sales use.
- The standard it is issued under AT-C 320 for SOC 1. AT-C 205 plus the criteria for SOC 2
- Confirmed in writing with the CPA firm, so the engagement letter names the section the requester actually asked about.
- Whether one can stand in It cannot - a SOC 2 does not satisfy a SOC 1 request
- Checked against the wording of the request before anything is commissioned, which is the cheapest hour on this page.
- Type I or Type II Both reports come either way, and it moves everything
- Which one your requester actually asked for, in writing, before you pay for the more expensive answer to the wrong question.
- The observation window Commonly three to twelve months, and you choose it
- What a shorter window costs you in credibility and a longer one costs you in time, set against who is asking for the report.
- Which criteria are elected SOC 2 only - Security always, the other four by choice
- Which of the four a buyer has actually named, so you are not tested against criteria nobody asked you to carry.
- The system boundary Drawn per service, and the two reports rarely share one
- What sits inside each report, and whether one engagement can honestly cover a processing service and a software product.
- Whether controls produce evidence The same question for either report, every time
- Which controls throw off their own evidence and which need a human with a screenshot tool every quarter, named one by one.
- Needing both reports Real, and commoner than the comparison pages suggest
- Whether your service lines genuinely split that way, so you commission two engagements deliberately rather than discovering it late.
- What drives the request SOC 1 a client's SOX work. SOC 2 enterprise procurement
- Traced back to the person who asked, because the driver tells you what they will accept and when they need it.
- Renewal and the bridge Annual for both, plus a bridge letter between reports
- What holding either report costs every year after the first, which is the line that decides whether starting was worth it.
Your control set, independently read
For either report, and for the case where you need both.
-
Read the request
Who asked, what they named, and which of the two reports would actually satisfy them.
-
Draw the boundary
Which services sit inside, which criteria you elect, and whether one report covers them all.
-
Price and sign off
You see the draft first. Then the gap list, the shortlist and the costed plan - dated.
Why teams ask iDharma which report they need
We sell no software
No platform to license, no seats to grow, and no reason to call your spreadsheet a gap.
We issue neither report
A licensed CPA firm signs both opinions. We read you before either one, and we say so on every page.
One fixed fee, published
The SOC 2 readiness price is published here and in the checkout, and no finding we make changes it.
We read the request first
The wrong report is the most expensive mistake here, and it is settled before a scope is drawn.
Four marks, struck on every readiness report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Report selection memo
The whole reading in one document: which report the request actually calls for, what would sit inside its boundary, whether your service lines split across two engagements, which criteria you would elect, which controls already produce their own evidence, and what each remaining gap takes to close.
Side-by-side comparison
Every line this page compares, as a sheet you can edit - the standard, the readers, the drivers and the type, set against your own answers.
Criteria gap report
Each elected criterion, or each control objective in a SOC 1, set against the control you run, with the evidence it produces named.
Evidence index
Which controls throw off their own evidence, which need a person each quarter, and what that costs across a Type II window.
Boundary memo
What sits inside each report and what was deliberately left out, with the reason for every call written down rather than assumed.
Remediation shortlist
What to fix before fieldwork and what can wait, ranked by what the opinion is at risk on rather than by what is quickest.
Requester question sheet
What to ask the person who requested a report - which one, Type I or Type II, which criteria, by when, and what they will accept.
Real numbers, upfront.
- Scope
- Set by the request, not by us
- Input
- Your controls, policies, evidence
- Re-read
- Annually, or on a scope change - a new service line, a new criterion, a new requester.
The request fixes the scope, so the fee is flat - and nothing is charged until you approve it.
Request your scan- Which report the request calls for
- Criteria gap read, control by control
- Boundary memo for each service line
- A dated evidence trail you keep
Four things to settle before you commission
None of these is a judgement call once you have asked. Each is either written down somewhere, or it is not.
The request,
read
Who asked, in what words, and which report would satisfy them. An auditor asking under a client's SOX work and a buyer running a security review want different documents.
The boundary,
drawn
Which services sit inside the report and which are deliberately outside it. A processing service and a software product rarely belong inside one description, and that line is cheaper drawn once.
The type,
named
Type I opines on control design at a point in time; Type II tests operation across a period. Both reports come either way, most enterprise contracts mean the second, and the requester knows which.
The period,
dated
Every report covers a window and then expires. What it costs to hold in year two, and the bridge letter covering the gap between one report ending and the next landing, belong in the first plan.
Four questions, and one email answers all of them.
SOC 1 or SOC 2 - which one do we need?
SOC 1 if your service changes numbers that land in your client's financial statements. SOC 2 if you store, process or transmit their data. Most technology companies need SOC 2, and the fastest way to be sure is to ask whoever requested a report which one they named.
Is SOC 2 harder to get than SOC 1?
Not necessarily. The difficulty depends on the controls you already run. SOC 2 carries more security-focused criteria, SOC 1 concentrates on financial-reporting controls, and for most technology companies SOC 2 is closer to what they already do.
Can a SOC 2 report replace a SOC 1?
No. They serve different purposes and are issued under different sections of SSAE No. 18. If your client's auditor has asked for a SOC 1, a SOC 2 report will not satisfy that request, however thorough it is.
Which report is requested more often?
SOC 2, by a wide margin, among technology buyers - enterprise customers commonly require it during vendor security review. SOC 1 is requested mainly by clients carrying SOX obligations of their own.
Can a company genuinely need both?
Yes, and it is commoner than most comparison pages suggest. A payroll company that also sells HR software may need a SOC 1 for the processing and a SOC 2 for the platform - two engagements, each with its own boundary.
Request your readiness review
Send us the request in the words it arrived in, and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. The first item is an email you were sent, and the rest is a folder someone can assemble in an afternoon - we name each one first.
- The request, in the words it arrived in
- Which services you would put inside the boundary
- Who asked, and what they said they need it for
- Any documentation - policies, prior reports
- Where your evidence lives today, and who collects it
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- AICPA SSAE No. 18, AT-C section 320
- AICPA SSAE No. 18, AT-C section 205
- AICPA Trust Services Criteria (rev. 2022)
- SSAE 18 effective
- 1 May 2017
- Criteria revised
- 2022
What it means
- General information about how the two reports differ — not legal or accounting advice, and no professional relationship arises from reading it. It determines nothing about your own services.
- Where the choice between them is arguable, our reports say so rather than the convenient one.
Scope & limitation
- Only the $9,000 SOC 2 readiness fee is ours - both opinions are a CPA firm's.
- Whether a given auditor accepts a given report is their call, not this page's.
- Do not rest a binding decision on it; engage qualified counsel.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.