SOC 1
The report a service organization gives its customers' financial auditors, covering controls relevant to those customers' financial reporting. SSAE No. 23 layers quality-management alignment on top of the same AT-C 320 attestation standard, for engagements beginning on or after 2025-12-15.
AT-C section 320, as amended by SSAE No. 23 (2025-12-15) · AICPA — SOC 1
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
SOC 1 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
AICPA attestation standards — obtain AT-C section 320 (as amended by SSAE No. 23) before verbatim ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Control objectives · Complementary user entity controls · Subservice organizations
- Applies to
- service organizations · payroll · financial services · SaaS · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
03Version ledger
| SSAE No. 18 (AT-C section 320) | Superseded | date not published |
| AT-C section 320, as amended by SSAE No. 23 (2025-12-15) | Current edition · supersedes SSAE No. 18 (AT-C section 320) | 2024-06-10 |
05Change history
06Related frameworks
- SOC 22017 TSC (revised points of focus, 2022)
Also applies to SaaS · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
- GLBA Safeguards Rule16 CFR Part 314 (amended 2023)
Also applies to financial services · The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.
- NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)
Also applies to financial services · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.