Which SOC Report Do You Need? Take the SOC Reporting Needs Assessment
Customers, prospects, and partners increasingly want independent proof that your controls work. Choosing among System and Organization Controls (SOC) reports comes down to three things: whether your services touch your customers’ financial statements, what kind of data you protect on their behalf, and whether the report will stay private or be shared publicly.
The Short Answer
If your customers rely on your services and reports from your system to book journal entries to their financial statements, you likely need a SOC 1® report. If your customers want independent evidence that you protect their systems and data, measured against the AICPA’s Trust Services Criteria for security, availability, processing integrity, confidentiality, and/or privacy, you likely need a SOC 2® report. Plenty of service organizations fall into both groups, needing SOC 1 and SOC 2 reports. A SOC 3® report is the shareable, general use version of a SOC 2 and is issued together with the SOC 2 report, not on its own.
If this will be your first SOC report, a readiness assessment is usually the best place to start.
Use the questions below to sort out which applies to you.
How to Use This Assessment
- Read through the 15 questions below and note your answers. Bring in your IT, security, or compliance lead for the questions in Sections 4 and 7, if you are unsure.
- Compare your answers to the guide in What Your Answers Point To.
- Send us a note through the Contact Us form on this page. Mention the SOC Reporting Needs Assessment and share a few of your answers, and a RubinBrown SOC specialist will follow up to talk through your recommendation.
Section 1: About Your Organization
1. Which best describes your organization?
- Software as a Service (SaaS) provider
- Managed services provider
- Cloud hosting or data center provider
- Data processing organization • Financial services provider
- Healthcare services provider
- Professional services firm
- Other
2. What types of information do you handle for customers? Select all that apply.
- Personally identifiable information (PII)
- Financial information
- Protected health information (PHI)
- Payment card information
- Confidential business information
- Intellectual property
- We don’t handle sensitive customer data
- Not sure
Section 2: Who’s Asking and Why
3. Has anyone asked you for independent assurance over your controls? If so, who? Select all that apply.
- Existing customers
- Prospective customers, during sales calls
- Customer procurement or vendor risk teams, through security questionnaires
- Regulators
- Investors or board members
- Business partners or vendors in your supply chain
- No one has asked, but we expect it soon
- No one has asked
- Not sure
4. How would you describe the security questionnaires your team receives from customers and prospects?
Security questionnaires are the detailed checklists that customer procurement and vendor risk teams send before signing or renewing a contract.
- We rarely receive them
- We receive a few each year and handle them without much trouble
- Volume is growing, and they take significant time away from our security or IT team
- They are slowing down sales cycles or contract renewals
- Not sure
5. If a specific report type was requested, which one(s)?
- SOC 1
- SOC 2
- SOC 3
- SSAE 16, SSAE 18, or another SSAE report
- Someone asked for “a SOC report” but didn’t specify
- Not applicable, no specific request yet
6. Have you lost or delayed a sales opportunity because of a compliance or assurance requirement?
Section 3: Financial Reporting Impact
7. Do your services directly affect your customers’ internal controls over financial reporting?
Examples include payroll processing, transaction processing, claims administration, revenue processing, financial recordkeeping, fund administration and data centers hosting critical client (accounting) systems.
- Yes, this is central to what we do
- Possibly, but we’re not sure how our services map to our customers’ financial reporting
- No, our services don’t touch financial reporting
- Not sure Section
4: Security and Trust Services Scope
8. Setting financial reporting aside, how important is it to show customers that your security and other controls are designed and working effectively?
- Critical, it’s a requirement to win or keep business
- Important, it comes up often
- Somewhat important, there’s occasional interest
- Not important right now
9. Which Trust Services Criteria are your customers most interested in? Select all that apply. These five categories, defined by the AICPA, are the building blocks of SOC 2 and SOC 3 reports.
- Security: protection against unauthorized access
- Availability: systems are up and usable as committed
- Processing integrity: processing is complete, accurate, and timely
- Confidentiality: confidential information is protected
- Privacy: personal information is collected, used, and disposed of properly
- Not sure
10. What do customers ask about most? Select all that apply.
- Cybersecurity controls
- Security monitoring and logging
- Incident response
- Vulnerability and patch management
- Access controls
- Change management
- Secure software development (SDLC)
- Vendor and third-party risk management
- Business continuity and disaster recovery
- System availability
- Data protection and encryption
- Data retention and disposal
- Data privacy
- None of the above
Section 5: Report Distribution
11. If you pursue a SOC report, who needs to see it?
- Only specific customers, prospects, or partners, under a nondisclosure agreement
- Anyone, including prospects, your website visitors, and the general public
- Both: some customers need the detailed report, and others just need public assurance
- Not sure
Section 6: Compliance Landscape
12. Is your organization subject to any of the following? Select all that apply.
- HIPAA
- GDPR
- PCI DSS
- SOX
- NIST frameworks
- ISO 27001
- State privacy regulations
- Specific customer contract requirements
- None
- Other
Section 7: Current Readiness
13. Do you currently maintain documented, enforced policies and procedures?
- Yes, comprehensive and current
- Partially, some policies exist but we have gaps
- No, not yet formalized
14. Which of the following are in place at your organization today? For each area, note whether it is in place, partially in place, or not yet in place.
- Information security policies
- Incident response plan
- Business continuity plan
- Disaster recovery plan
- Risk assessment process
- Vendor management program
- Security awareness training
- Access management procedures
15. Has your organization previously completed any of the following? Select all that apply.
- SOC 1 examination
- SOC 2 examination
- ISO 27001 certification
- PCI DSS assessment
- HITRUST certification
- None
What Your Answers Point To
Every organization is different, and a SOC specialist will confirm the right fit with you. These are the patterns we look for.

Start with readiness
(Questions 13 through 15)
If this will be your first SOC 1 or SOC 2 report, a readiness assessment is almost always the right first step. It identifies control gaps and gives you time to close them before an auditor begins testing, which reduces the risk of exceptions in your final report. This is especially true if your policies are only partially documented or several control areas in Question 14 are not yet in place.
If you have completed a SOC 1 or SOC 2 examination before, you may be ready to move straight to an examination, and readiness becomes a conversation about any new systems, services, or criteria you plan to add.
Signs you need a SOC 1 report
(Question 7)
If your services affect how your customers record, process, or report financial information, their auditors will likely need a SOC 1 report. A “Yes” on Question 7 is a strong signal. A “Possibly” is worth a conversation, because deciding whether a service is relevant to a customer’s financial reporting is a judgment call best made with a specialist.
Signs you need a SOC 2 report
(Questions 3 - 5, 8 - 10)
A SOC 2 report is likely the right fit if any of these apply:
- A customer, prospect, or procurement team has asked for SOC 2 by name (Questions 3 and 5)
- Your team is spending significant time on security questionnaires, or questionnaires are slowing down deals (Question 4)
- Security assurance is critical or important to winning and keeping customers (Question 8)
- Customers care about one or more of the Trust Services Criteria (Question 9) or ask about the topics in Question 10
A note on security questionnaires:
Many organizations pursue a SOC 2 report specifically to get relief from questionnaire fatigue. Instead of answering hundreds of individual questions for every customer, you can share one independent report that addresses many of the same topics. Customers often accept a SOC 2 report in place of their questionnaire, or ask only a short set of follow up questions alongside it.
Signs you need both SOC 1 and SOC 2
SOC 1 and SOC 2 answer different questions, so look at each one on its own. If your services affect customers’ financial reporting
and customers expect broader security assurance, you will likely need both. This is common for payment processors, payroll providers, and software platforms that handle financial transactions.
Signs you need a SOC 3
(Question 11)
A SOC 3 report covers the same Trust Services Criteria as a SOC 2 but is written for general use, so you can post it on your website or share it freely. It does not include the detailed description of controls and test results that a SOC 2 does. Because a quality SOC 3 requires all of the same procedures as a SOC 2, it is issued as a companion to a SOC 2 examination rather than as a replacement for one. If you answered “Anyone” or “Both” to Question 11, plan for a SOC 2 with a companion SOC 3.
If you have other compliance requirements
(Question 12)
If you are also subject to frameworks such as HIPAA, ISO 27001, or NIST, a
SOC 2+ report can map those additional requirements into a single SOC 2 examination, which can reduce duplicate audit work.
If you lost or delayed a deal
(Question 6)
A lost or delayed opportunity does not change which report you need, but it does make timing important. A first SOC report, from readiness through examination and reporting, typically takes 9 to 14 months. Starting the conversation early helps you plan a realistic timeline and set expectations with customers who are waiting.
If your answers are mixed or you’re still not sure
That’s common, and it is exactly what a short scoping conversation is for. Requests that come through a customer contract, an ambiguous “SOC report” request, or a mix of financial and security needs are best sorted out together.
SOC 1 vs. SOC 2 vs. SOC 3 at a Glance
| |
SOC 1 |
SOC 2 |
SOC 3 |
| What it covers |
Controls relevant to customers’ financial reporting |
Controls related to security, availability, processing integrity, confidentiality, and/or privacy |
Same criteria as SOC 2, in summary form |
| Who uses it |
Customers’ management and their financial statement auditors |
Customers, prospects, partners, and regulators who need detail |
Anyone, including prospects and the public |
| Distribution |
Restricted use |
Restricted use, often shared under NDA |
General use, can be posted publicly |
| Includes test results |
Yes (Type 2) |
Yes (Type 2) |
No |
| Common drivers |
Customer auditor requests, SOX compliance |
Security questionnaires, enterprise sales, vendor risk reviews |
Marketing and public trust, always alongside a SOC 2 |
Get Your Recommendation
Ready to talk through your answers? Complete the Contact Us form on this page and mention the SOC Reporting Needs Assessment in your message. It helps to include:
- Who is asking for it (Question 3)
- Which report, if any, was requested (Question 5)
- Whether this would be your first SOC report (Question 15)
- Any deadline you are working against
A RubinBrown SOC specialist will follow up to confirm the right report type, scope, and next step for your organization.
Learn more: System and Organization Control (SOC) Reports
SOC 1®, SOC 2®, and SOC 3® are registered trademarks of the American Institute of Certified Public Accountants.