
At some point, you’ll receive an email from an enterprise client saying: “Please send us your SOC report.” And then the guesswork begins. SOC 1, SOC 2 or SOC 3? Type 1 or Type 2? Anyone dealing with this for the first time is faced with a jumble of letters that can quickly become costly if you commission the wrong audit. Yet the whole thing follows a simple logic: it’s always just a question of who wants to know what about your controls.
Not all SOCs are the same
First, a terminology trap that constantly causes confusion in practice. The abbreviation stands for two completely different things.
Security Operations Center
A unit comprising people, processes and technology that monitors your IT. It operates at levels L1 to L4 and uses operating models such as in-house, managed or hybrid.
System and Organisation Controls
An audit report from an independent auditor on your controls. These include SOC 1, SOC 2 and SOC 3, as well as Type 1 and Type 2. That is what this article is about.
When a customer asks for ‘your SOC report’, they almost always mean the second definition. A Security Operations Center does not produce a SOC report, but it can serve as very convincing evidence within one.
Are you looking for the other SOC? We’ve explained the structure, operating models and Levels L1 to L4 here: What is a SOC? And what variants are there?
What a SOC report is
A SOC report is not a certificate, but an audit report by an independent auditor on a service provider’s internal controls. It answers the question of whether a company has actually implemented the controls it claims to have in place, and whether they are working.
The report is not intended for a regulatory body, but for your clients and their auditors. They remain responsible for their data and financial statements, even if they have outsourced processes to you. The report serves as evidence to them that this outsourcing was carried out properly. This is precisely why there are three variants, which differ in terms of audience and level of detail.
SOC 1: when it comes to figures
SOC 1 focuses exclusively on the controls that affect your client’s financial reporting. The classic scenario: you handle payment or billing processes. If your systems calculate incorrectly, incorrect figures end up in the client’s balance sheet, and their auditor will want to know whether they can trust your processes.
A payment service provider that handles invoices for a hospital operator typically needs SOC 1. A time-tracking provider whose data feeds into payroll accounting does too. Anyone operating a pure collaboration tool has nothing to do with their clients’ balance sheets and does not need SOC 1.
Common mistake: SOC 1 is commissioned simply because it’s ‘the 1’ and is therefore supposedly the entry-level standard. However, the numbers do not represent levels but different topics. If you don’t handle any financial data, SOC 1 is just a waste of budget.
SOC 2: the report almost everyone is referring to
SOC 2 is the report that enterprise customers ask for in the vast majority of cases. It assesses your controls against the Trust Services Criteria (TSC). There are five of these, but only ‘Security’ is mandatory.
Security (mandatory)
Protection of the system against unauthorised access. The only mandatory criterion, often referred to as Common Criteria.
Availability
Availability in accordance with agreed service levels. Relevant where strict SLAs are stipulated in the contract.
Confidentiality
Protection of confidential information, such as trade secrets or your customers’ contractual data.
Processing Integrity
Completeness, accuracy and timeliness of processing. Relevant wherever data is transformed or calculated.
Privacy
Handling of personal data. Privacy in the TSC sense is not synonymous with the GDPR and does not replace it.
You select the four optional criteria as required, and this is precisely where the real decision lies. Each additional criterion increases the effort, costs and duration of the audit. A scope that unnecessarily encompasses all five TSC criteria is not a mark of quality, but is usually a sign of a lack of preparation.
Recommendation: Start with Security and add only those criteria that your clients actually ask for in contracts or security questionnaires. The scope can be expanded in subsequent audits.
SOC 3: the version for the public
SOC 3 is based on the same audit as SOC 2, but provides significantly fewer details. The difference lies in the audience. A SOC 2 report contains specific descriptions of controls and audit findings and is only provided to clients under an NDA. SOC 3 is the abridged, freely distributable version for the website.
Major cloud providers operate exactly in this way: the SOC 3 seal is publicly displayed on the trust page, whilst enterprise customers receive the full SOC 2 report on request. SOC 3 is therefore less of an audit tool and more of an outward signal of trust.
In a nutshell: SOC 1 is for your customers’ auditors. SOC 2 is for their security teams and procurement departments. SOC 3 is for everyone else who simply wants to see that you have been audited.
Type 1 or Type 2
Regardless of whether it’s SOC 1 or SOC 2, each report is available in two versions. This distinction is often overlooked, but it determines the report’s significance.
Type 1: Snapshot
On a specific cut-off date, the auditor checks whether the controls are designed and implemented as claimed. It is the design that is confirmed, not the actual practice.
Type 2: Performance Test
The auditor checks, over a period typically ranging from three to twelve months, whether the controls have been effective throughout. Both the design and operational effectiveness are confirmed.
Serious clients want to see a Type 2 report. A Type 1 report merely states that your systems were in order on a single day. It is nevertheless useful as a starting point, as it is quicker to obtain and bridges the gap until your Type 2 observation period has elapsed.
This brings us full circle to the other SOC: a Type 2 report requires complete evidence spanning several months. Anyone who operates a Security Operations Center or purchases one as a managed service already has this monitoring and incident evidence anyway and can submit it directly as proof.
Which combination is right for you?
The decision can be broken down into three questions:
Do your services impact your customers’ financial reporting? If so, there’s hardly any way round SOC 1.
Do enterprise customers ask for security evidence during the procurement process? Then SOC 2 Type 2 is the goal, with a deliberately narrow TSC scope.
Do you want to demonstrate trust to the outside world? Then add SOC 3, but only once SOC 2 is in place.
A common misconception that can prove costly: SOC 2 replaces neither ISO 27001 nor the GDPR. It is a US-based audit framework that is increasingly appearing in European tenders, but does not cover European requirements. Anyone who needs both should plan the controls together from the outset, rather than running two separate projects.
How Mint Secure supports you in this
SOC audits themselves are carried out by auditors; that is not our business. What we do is establish the controls that such a report ultimately assesses in a robust manner and provide technical evidence for them.
Establishing controls
Whether it’s ISMS, BSI Basic Protection or CISO as a Service: we bring your security organisation up to a standard that can withstand any audit, regardless of the audit format.
Demonstrating effectiveness
Penetration tests, vulnerability management and attack surface analyses provide exactly the technical evidence required during an audit.
Not sure what you really need? In a free initial consultation, we’ll clarify what evidence your clients actually require and what you’re currently missing. Get in touch now.
Conclusion
SOC 1, SOC 2 and SOC 3 are not successive stages, but three answers to three different questions. SOC 1 addresses financial reporting, SOC 2 addresses security controls for business clients, and SOC 3 addresses public perception.
The second key distinction is between Type 1 and Type 2. Only Type 2 demonstrates that your controls remain effective over time. Type 1 is an intermediate step, not an end goal.
The report itself is produced by the auditor. You must provide the substance behind it, and that is precisely where we can support you. Please get in touch.

