Live Founding Cohort open, limited seats remaining Back to main site →

SOC 1 vs SOC 2 vs SOC 3 vs ISO 27001 vs FedRAMP

Five different reports. Each answers a different question for a different reader. This lesson decodes which one your enterprise customer actually wants, and why founders lose weeks going down the wrong path.

Free preview 10 min read Verified
Legal basis
SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only). Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.

Your enterprise buyer asks for "your SOC report" and you spend the next two weeks trying to figure out which one they mean. This lesson prevents that.

Five reports. Each answers a different question for a different reader.

The comparison table

ReportStandards bodyWhat it coversWho reads itWhen your customer asks for it
SOC 1AICPA (AT-C 320)Controls at a service organization relevant to user entities financial reportingYour customer's external financial auditorIf you process transactions that materially affect their financial statements. Payroll processing, payments, revenue recognition.
SOC 2AICPA (AT-C 205 + TSC)Information security controls, at minimum Security TSC; optionally Availability, Processing Integrity, Confidentiality, PrivacyYour customer's vendor risk management, security, procurement, legal teamsAny SaaS that touches customer data. The default demand for enterprise SaaS.
SOC 3AICPAShort-form version of SOC 2 for public distribution (no NDA)Anyone (your marketing team publishes on the website)Rarely asked for directly. Used as a public trust signal, not as VRM evidence.
ISO 27001ISO / IEC (Geneva)Information Security Management System (ISMS) meeting the ISO/IEC 27001:2022 standardYour customer's security team, especially in Europe, UK, APAC, Middle EastAlternative to SOC 2. Some customers demand one, some the other, some both.
FedRAMPUS Federal government (GSA)Cloud service authorisation to serve US federal agenciesUS federal agency contracting officersOnly if you sell to US federal government or federal-adjacent primes.

SOC 1 versus SOC 2, the confusion

Founders confuse SOC 1 and SOC 2 more often than any other pair. Both are AICPA. Both are examination engagements under SSAE 18. Different reporting section, different criteria, different reader.

SOC 1 lives under AT-C 320 [L2-C1]. It covers controls at a service organisation that could affect a user entity's Internal Control Over Financial Reporting (ICFR). Example: you run payroll processing for a US Fortune 500. If your controls fail, their financial statements could be materially misstated. Their external auditors need to know your controls work. That is SOC 1.

SOC 2 lives under AT-C 205 read with the Trust Services Criteria [L2-C2]. It covers information security controls. Example: you run a CRM SaaS that stores customer contact data. If your controls fail, customer data leaks. Their security and VRM teams need to know your controls work. That is SOC 2.

If you are an Indian SaaS selling any typical B2B product (CRM, marketing automation, HR, IT, help desk, analytics, database, developer tools, security), your customer wants SOC 2, not SOC 1. If you are a payments or payroll processor, they may want both.

SOC 2 versus ISO 27001, the choice

SOC 2 is AICPA-based and reads more naturally to US enterprise buyers. ISO 27001 is ISO/IEC-based and reads more naturally to European, UK, APAC and Middle East enterprise buyers. Some large customers demand both.

The pragmatic Indian SaaS approach: start with SOC 2 Type II if your dominant revenue is US enterprise, or ISO 27001 if it is European enterprise. Add the other one 12 months later. Vanta, Drata, Sprinto and Secureframe all offer combined SOC 2 + ISO 27001 programmes that share most of the control set. The marginal cost of adding the second framework is typically 40 to 60 percent of the first, not double.

Zoho publishes both a SOC 2 Type II and ISO 27001 certification on its security page. Freshworks does the same. That is the current bar for a mature Indian SaaS: both frameworks, both current.

SOC 3, the misunderstood report

SOC 3 is a short-form public-distribution version of SOC 2. Same underlying examination, but the report is stripped down to a summary that can be posted publicly without an NDA. Very few Indian SaaS pursue SOC 3 as a separate engagement because it typically adds 15 to 25 percent to the audit fee for a report that most customers do not specifically ask for. Freshworks, Zoho and most Indian unicorns skip SOC 3 and publish a "SOC 2 Type II report available under NDA" statement on their Trust Portal instead.

FedRAMP, the special case

FedRAMP applies only if you sell to the US federal government or to federal-adjacent primes. Very few Indian SaaS pursue it in the first two years post SOC 2. Cost of a FedRAMP Moderate authorisation runs 500,000 to 2,000,000 US dollars and takes 12 to 24 months. If you have US federal ambition, add FedRAMP after SOC 2 and ISO 27001 are stable. If you do not, FedRAMP is not on your roadmap.

What to tell your customer when they ask

Ask a clarifying question. "When you asked for our SOC report, do you mean SOC 1 (financial controls) or SOC 2 (information security controls)? Most SaaS customers want SOC 2 Type II." Nine out of ten will say SOC 2 Type II. The tenth wanted SOC 1 and you have just saved yourself weeks of confusion.

Next lesson: Type I versus Type II. Design at a point in time versus operating effectiveness over a period. Which to start with, when to move, why the choice matters for the sales cycle.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
AICPA AT-C Section, AT-C 320 SOC 1 Reporting on Service Org Controls (SOC 1 reporting section (contrast for SOC 2)) L2-C1
AT-C 320 governs SOC 1 reporting (controls at a service organization relevant to user entities internal control over financial reporting). Referenced in the SOC 2 course for contrast: SOC 1 sits under AT-C 320 and covers financial-reporting controls; SOC 2 sits under AT-C 205 read with the Trust Services Criteria and covers information security controls. Founders sometimes conflate the two report types.
AICPA AT-C Section, AT-C 205 Examination Engagements (Examination engagement standard (SOC 2)) L2-C2
AT-C 205 governs Examination Engagements. This is the standard SOC 2 examinations are performed under. The practitioner obtains sufficient appropriate evidence to conclude on management assertion that (a) description of the service organization system is accurate (both Type I and Type II) and (b) controls are suitably designed (Type I) and operating effectively (Type II) throughout the specified period.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The story of SOC 2
Module 2: Common Criteria Part 1: CC1 to CC5, governance and risk
  • CC1 Control Environment: tone at the top, board oversight, org structure
  • CC2 Communication and Information: internal comms, external commitments, the Trust Portal
  • CC3 Risk Assessment: asset inventory, threat identification, likelihood, impact, residual risk
  • CC4 Monitoring Activities: continuous monitoring, deficiency reporting, remediation tracking
  • CC5 Control Activities: selection, technology-general controls, segregation of duties
Module 3: Common Criteria Part 2: CC6 to CC9, operations
  • CC6 Logical and Physical Access Controls: IAM, MFA, provisioning, remote access, keys
  • CC7 System Operations: detection tooling, incident response, backup and recovery
  • CC8 Change Management: dev lifecycle, code review, testing, approval, deployment, rollback
  • CC9 Risk Mitigation: vendor risk, third-party risk, business continuity, insurance
  • The 2022 Revised Points of Focus: what auditors now specifically look for
Module 4: The optional four Trust Services Criteria
  • Availability TSC — the uptime criterion
  • Processing Integrity TSC — the transaction criterion
  • Confidentiality TSC — the trade-secret criterion
  • Privacy TSC — and the GDPR / DPDP Act 2023 / CCPA overlap
  • TSC decision matrix — which to add and when, by industry
Module 5: The Control Framework and Policy Pack
  • The Control Matrix — mapping TSC clauses to controls, owners and evidence
  • The 10-Policy Pack — draft skeletons your auditor will ask to see
  • Risk Assessment Framework — asset, threat, likelihood, impact, residual risk
  • Vendor Risk Register — the working register your auditor tests against CC9.2
  • Incident Response Plan and Tabletop Runbook
Module 6: Evidence Collection Operating Model
  • Continuous vs point-in-time evidence, and how the auditor samples
  • Buy vs Build: Vanta, Drata, Sprinto, Secureframe, Comply.ai, or in-house
  • Evidence types: what makes evidence auditor-quality vs unusable
  • The Evidence Collection Calendar, a twelve-month template
  • Audit trail hygiene: organising the evidence pack for the first 48 hours of fieldwork
Module 7: Selecting the Auditor and the Audit Cycle
  • What makes a SOC 2 auditor: licensing, independence, sector experience
  • The Auditor RFP and Selection Matrix: running Big 4 against mid-tier against boutique
  • The SOC 2 Engagement Letter, full SSAE 18 template
  • The audit cycle week by week, kickoff to report issuance
  • Auditor opinion types: unqualified, qualified, adverse, disclaimer
Module 8: Post-Audit and Continuous Compliance
  • Publishing the SOC 2 report on your customer trust portal
  • Answering vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report
  • The annual re-audit cycle and the bridge letter
  • Adding TSCs beyond Security: Availability, then Confidentiality, then Privacy
  • SOC 2 to ISO 27001 upgrade path and emerging AI controls