
SOC 1 vs SOC 2 vs SOC 3: Which One Do You Need?
A SOC 1 report covers controls that affect your customers’ financial reporting. A SOC 2 report covers security, availability, processing integrity, confidentiality and privacy. A SOC 3 report covers the same ground as SOC 2 but in a short summary you are allowed to publish. If you are an Australian software or service business and a customer has asked for a SOC report, they almost always mean SOC 2. If they process your output into their financial statements, they mean SOC 1.
The part that catches Australian companies out is that all three are American reports, issued under American standards by American licensed accountants. Australia has its own close counterparts, and knowing which one your customer will accept can save you an expensive detour. This article covers both sides.

What is the difference between SOC 1 and SOC 2?
SOC 1 and SOC 2 differ in subject matter. A SOC 1 report is an examination of controls at a service organisation that are likely to be relevant to its customers’ internal control over financial reporting. It exists so that your customer’s financial auditor can rely on what happens inside your systems. Payroll bureaux, billing platforms, funds administrators and claims processors are the classic candidates.
A SOC 2 report is an examination against the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security is always included and the other four are optional, chosen to match what you promise customers. SOC 2 exists so that a customer’s procurement, security or risk team can satisfy themselves that you look after their data. If you sell software or a hosted service, this is the report being asked for. Our guide to which Trust Services Criteria apply covers how to choose.
Neither report is better than the other. They answer different questions, and a small number of businesses genuinely need both, usually financial technology companies whose platform both holds customer data and feeds customer ledgers.
What is a SOC 3 report and why can you publish it?
A SOC 3 report examines the same Trust Services Criteria as SOC 2, but it omits the detailed description of your systems and the auditor’s tests and results. That omission is the entire point. The AICPA describes SOC 3 reports as general use reports that can be freely distributed, whereas SOC 1 and SOC 2 are restricted use reports.
In practice a SOC 3 is a trust badge for your website and your sales deck. It tells a prospect that an independent examination happened and what the opinion was. It will not satisfy a serious due diligence review, because there is nothing in it for a reviewer to assess. Treat a SOC 3 as marketing evidence produced alongside a SOC 2, never as a replacement for one.
What is the difference between a Type 1 and a Type 2 report?
Type 1 and Type 2 describe how much the auditor tested, and they apply to both SOC 1 and SOC 2. A Type 1 report gives an opinion on whether controls were suitably designed as at a single specified date. A Type 2 report goes further and gives an opinion on whether those controls operated effectively across a period of time.
The observation period for a Type 2 report is agreed with your auditor and commonly runs from three to twelve months. Most Australian buyers of a SOC 2 want a Type 2, because a Type 1 proves only that you had the right documents on one day. A Type 1 is still useful as a staging post: it gets a report into a customer’s hands while the clock runs on the Type 2 period. We cover the choice in detail in SOC 2 Type 1 vs Type 2.
Which SOC report will your customer actually accept?
Ask them, in writing, before you commission anything. The request that arrives in a procurement email is often a template phrase rather than a considered requirement, and the cost difference between the options is large enough to justify one clarifying question.
| What the customer is worried about | The report that answers it | Type they will usually want |
|---|---|---|
| Your systems affect our financial statements | SOC 1 | Type 2 |
| You hold our customer data | SOC 2 | Type 2 |
| We need something for our website or a tender | SOC 3 | Issued from a SOC 2 Type 2 |
| We want an internationally recognised certificate | ISO 27001 instead | Not applicable |
| We are an Australian super fund or investment manager | GS 007 or ASAE 3402 | Type 2 equivalent |
If the answer comes back as a recognised certificate rather than an audit report, ISO 27001 may be the cheaper and more portable option, and it is often the better fit for Australian and European buyers. Our side by side comparison of ISO 27001 and SOC 2 sets out the trade offs.
What are the Australian equivalents of a SOC report?
Australia has its own service organisation assurance standards, issued by the Auditing and Assurance Standards Board. They are the reason an Australian customer may not need you to chase an American report at all.

- ASAE 3402 covers assurance reports on controls at a service organisation that are relevant to user entities’ financial reporting. It is the direct counterpart to SOC 1, and the current version dates from December 2022.
- ASAE 3150 covers assurance engagements on controls that fall outside the scope of ASAE 3402. This is the space an Australian practitioner works in when producing a security focused controls report, sometimes applying the AICPA Trust Services Criteria as the subject matter.
- GS 007 is guidance on the audit implications of using service organisations for investment management services, covering custody, asset management, property management, superannuation member administration, investment administration and registry. If your customers are Australian super funds or investment managers, this is the request you will get.
These are close counterparts rather than certified equivalents. There is no formal cross recognition scheme that says an ASAE 3402 report satisfies a contract asking for SOC 1. Whether it does is a commercial conversation with the customer, which is another reason to ask before you commission.
Can an Australian company get a SOC 2 report?
Yes, and Australian companies do it regularly, but the mechanics matter. A SOC engagement is performed under AICPA attestation standards by a licensed CPA firm, so an authentic SOC 2 report traces back to a United States CPA licence. In practice Australian companies either engage the Australian arm of a global firm that can issue through its US licensed network, or engage a US firm directly and work remotely.
The alternative is to have an Australian registered auditor issue an ASAE based controls report against the Trust Services Criteria. It looks similar and answers the same question, but it is not the same legal instrument, and a customer who wrote SOC 2 into a contract may not accept it. Confirm acceptance in writing before you spend the money.
One warning that comes from the American profession itself. The AICPA’s own journal has raised concerns about fast and cheap SOC engagements funnelled through vendor platforms producing thin, templated reports. If you are on the receiving end of one, read it properly. If you are commissioning one, choose the auditor on the quality of the examination, not the speed of the sales pitch.
How often do you need a new SOC report?
Annual refresh is the market norm rather than a rule written into the standards. A SOC 2 Type 2 report covers a defined period, and once that period ends the report starts ageing. Most customers expect a report whose period ended within the last twelve months, and enterprise procurement teams often say so explicitly.
Between reports, the gap is normally handled with a bridge letter, a short statement signed by your own management confirming that nothing material changed between the end of the report period and the customer’s own reporting date. Bridge letters are an industry practice, not an AICPA standard, and they are not a substitute for a report. See our guide to SOC 2 bridge letters for what a good one says.
Common questions
Which is better, SOC 1 or SOC 2?
Neither is better. They cover different subject matter. SOC 1 reports on controls that affect your customers’ financial reporting, so it is what a customer’s financial auditor asks for. SOC 2 reports on security, availability, processing integrity, confidentiality and privacy, so it is what a customer’s security and procurement teams ask for. If you sell software or hosting, SOC 2 is almost certainly the one being requested.
What is the difference between SOC 2 and SOC 3?
A SOC 2 and a SOC 3 examine the same Trust Services Criteria. The SOC 2 report includes a detailed system description plus the auditor’s tests and results, and is a restricted use report. The SOC 3 report omits all of that detail and is a general use report you may publish freely. A SOC 3 is produced from a SOC 2 Type 2 examination, so it is an addition, not an alternative.
Is ISAE 3402 the same as SOC 1?
ISAE 3402 is the international standard covering the same territory as SOC 1: assurance reports on controls at a service organisation relevant to user entities’ financial reporting. In Australia the corresponding standard issued by the Auditing and Assurance Standards Board is ASAE 3402. They address the same question under different standard setters, so many customers will accept any of them once you ask.
What is a GS 007 report in Australia?
GS 007 is Australian guidance for auditors of entities that outsource investment management services, and for the service auditors reporting on those providers. It covers custody, asset management, property management, superannuation member administration, investment administration and registry services. If your customers are superannuation funds or investment managers, expect this request rather than SOC 1.
How often are SOC reports required?
Once a year in practice. The standards do not mandate a cycle, but a SOC 2 Type 2 report covers a fixed period, and most customers want one whose period ended within the last twelve months. Plan on a repeating annual examination, with a bridge letter covering the months between your report period ending and your customer’s own year end.
Do we need SOC 2 if we already have ISO 27001?
Often not. ISO 27001 certification satisfies many Australian, European and Asian buyers, and it is a certificate rather than a report, which makes it easier to share. American enterprise buyers, and some Australian ones with American parents, ask specifically for SOC 2. The deciding factor is who your customers are, not which framework is stronger.
Where to go next
Before you commission any of these, get the request in writing, confirm which report and which type the customer will accept, and check whether an Australian ASAE report or ISO 27001 would close the deal for less. If it is SOC 2, a readiness assessment first will save you paying an auditor to discover gaps you could have found yourself. See our SOC 2 services or get in touch and we will help you work out which report you actually need.