SOC 1 vs SOC 2 vs SOC 3: which SOC report do you need?
SOC 1, SOC 2 and SOC 3 are three different AICPA reports for three different audiences: financial-reporting controls, security and trust controls, and a public-facing summary.

The naming makes it sound like SOC 1, SOC 2 and SOC 3 are three tiers of the same audit, where bigger is better. They aren't. They're three different reports for three different audiences, all issued under the AICPA's System and Organization Controls (SOC) framework. Picking the wrong one wastes months, so it's worth getting the distinction straight before you engage an auditor.
SOC 1: controls that affect your customers' financial reporting
A SOC 1 report is about internal control over financial reporting (ICFR), but not yours, your customers'. If the service you provide feeds into your customers' financial statements, their auditors need assurance about the controls around it. That's what a SOC 1 gives them.
Classic examples are payroll processors, payment processors, and financial or billing platforms whose accuracy directly affects a client's books. The audience is your customers' financial auditors, and the report is built on the auditing standards for these engagements (SSAE 18 in the US; ISAE 3402 is the international equivalent). If your service doesn't touch anyone's financial reporting, you almost certainly don't need a SOC 1.
SOC 2: controls for security and trust
A SOC 2 report is about the Trust Services Criteria, security, availability, processing integrity, confidentiality and privacy. The audience is your customers' security and procurement teams, and the question it answers is whether you can be trusted with their data and their operations. This is the report almost every B2B software company is actually being asked for. We cover it in depth in what is SOC 2, and the Type I versus Type II choice within it.
Like SOC 1, a SOC 2 is a restricted-use document, shared under NDA, and comes in a Type I (point-in-time design) or Type II (effectiveness over a period) flavour.
SOC 3: the public version of a SOC 2
A SOC 3 report covers the same Trust Services Criteria as a SOC 2, but it's built for general use. It includes the auditor's opinion, management's assertion and a short system description, but it leaves out the detailed control descriptions, test procedures and results.
Because it doesn't expose sensitive detail, a SOC 3 can be published openly, on your website, in a sales deck, wherever you want a visible trust signal. It doesn't replace a SOC 2; you produce it from a SOC 2 Type II as the public-facing companion. If prospects keep asking for evidence you can't post publicly, a SOC 3 is the answer.
Choosing, in one pass
- Does your service affect your customers' financial statements? You may need a SOC 1.
- Do customers need assurance about how you protect their data and systems? You need a SOC 2, almost always a Type II.
- Do you want a public trust document to show anyone? Add a SOC 3, generated from your SOC 2.
Most software and services companies land on SOC 2, sometimes adding a SOC 3 for marketing, and only reach for SOC 1 if their product genuinely sits in a financial-reporting path. And because SOC 2 leans on the same control set as ISO 27001, organisations selling on both sides of the Atlantic frequently run the two together rather than building each from scratch.
Whichever report your buyers ask for, the constant is running the controls well enough to stand behind them. ResiliencePilot manages your controls and evidence in one place and maps them across SOC 2, ISO 27001 and the rest. See the SOC 2 solution, the SOC 2 hub, or book a demo.