Skip to main content
—
Framework library
Framework module · soc-1-ssae-18

SOC 1

The report a service organization gives its customers' financial auditors, covering controls relevant to those customers' financial reporting. SSAE No. 23 layers quality-management alignment on top of the same AT-C 320 attestation standard, for engagements beginning on or after 2025-12-15.

AT-C section 320, as amended by SSAE No. 23 (2025-12-15) · AICPA — SOC 1

Standing today
Directory entry

00Answer

from the registry record
What is SOC 1?
The report a service organization gives its customers' financial auditors, covering controls relevant to those customers' financial reporting. SSAE No. 23 layers quality-management alignment on top of the same AT-C 320 attestation standard, for engagements beginning on or after 2025-12-15.
Who does SOC 1 apply to?
SOC 1 applies to service organizations, payroll, financial services, SaaS, US, global, per AICPA — SOC 1.
What is the current version of SOC 1?
The current edition is AT-C section 320, as amended by SSAE No. 23 (2025-12-15), issued by AICPA — SOC 1. Source: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1.
What does an assessment under SOC 1 require?
No control catalog has been ingested for SOC 1 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

SOC 1 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

AICPA attestation standards — obtain AT-C section 320 (as amended by SSAE No. 23) before verbatim ingestion.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Control objectives · Complementary user entity controls · Subservice organizations
Applies to
service organizations · payroll · financial services · SaaS · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06

03Version ledger

2 editions
SSAE No. 18 (AT-C section 320)Supersededdate not published
AT-C section 320, as amended by SSAE No. 23 (2025-12-15)Current edition · supersedes SSAE No. 18 (AT-C section 320)2024-06-10

05Change history

06Related frameworks

scored from registry facts
  1. SOC 22017 TSC (revised points of focus, 2022)

    Also applies to SaaS · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

  2. Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  3. GLBA Safeguards Rule16 CFR Part 314 (amended 2023)

    Also applies to financial services · The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.

  4. NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)

    Also applies to financial services · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.

SOC 1 | ControlFrame