Dimov Audit

SOC report examples and which one your customer needs

A customer has asked for your SOC report before it signs or renews. You need the report that request names, signed by an independent CPA firm.

What is a SOC report

A SOC report is a CPA firm's opinion on the controls a service company runs for its customers. SOC stands for System and Organization Controls, the AICPA's name for this family of examinations. You commission the SOC audit, and the people who rely on your service read the report.

SOC 1 vs SOC 2 vs SOC 3

The AICPA splits the reports by the controls a CPA examines and by who may read the result:

  • SOC 1

    • A CPA examines the controls you run that affect your customers' internal control over financial reporting, meaning the controls they rely on for accurate financial statements.
    • The CPA restricts the report to you, your customers and their auditors.

    Example: a loan servicer that posts borrower payments to its lenders' accounts.

  • SOC 2

    • A CPA examines your controls over security, availability, processing integrity, confidentiality or privacy.
    • The CPA restricts the report to parties who know your system, such as customers and business partners.

    Example: a software company that stores customer data in its platform.

  • SOC 3

    Example: a hosting company that posts its report on its website for prospects.

We issue SOC 1 reports.

A SOC report example, section by section

Take an illustrative SOC 1 report example for a payroll processor whose figures each customer posts to its own books. You read the auditor's opinion first, then management's assertion, then the description of the system and its controls.

In a Type 1 report, the CPA gives an opinion on the design of your controls as of one date. In a Type 2 report, the CPA also gives an opinion on how the controls operated through a period, and lists each test and its result.

Your customer's auditors read those results when they assess the effect of your controls on your customer's financial statements.

Inside a SOC reportIllustrative SOC 1 Type 2, payroll processorService auditor's opinionThe CPA's conclusion on your description and your controlsManagement's assertionYour written statement about the description and the controlsSystem descriptionYour services, control goals and the controls behind themTests and resultsTYPE 2 ONLYEach test the CPA ran, such as sampled pay-rate changes, and what the CPA foundIn a SOC 3, the CPA shortens the description and leaves out the tests.
A printed vendor questionnaire on a desk

How to tell which report your customer wants

Read the request for the words SOC 1, SOC 2 or SOC 3, and for the reason your customer gives. If its auditors rely on your processing when they audit its financial statements, you need a SOC 1. We read the request with you before we quote.

What to check before a firm signs your report

The CPA firm that signs your report must follow AICPA attestation standards. In February 2026, the AICPA's Journal of Accountancy reported that CPAs who do SOC work are worried about tool vendors that promise fast, cheap reports.

Before you hire a firm for a SOC audit, check:

  • Its peer review results, its size and capacity, and client references you can call.
  • The scope it proposes, how it will sample and how it stays independent.
  • Whether the firm can deliver on the timeline and price it quotes.

Vendors sell SOC compliance and SOC certification. The AICPA describes SOC 2 as an examination in which a CPA examines controls and issues a report.

Ask each firm on your shortlist for its latest peer review report.

What sets the cost of a SOC audit

We set your SOC audit cost from the scope you ask us to examine:

  1. Which report you need, and whether it is a Type 1 or a Type 2
  2. How many services and controls you want covered
  3. How much evidence you can provide for each control, and how organized it is

For a Type 2, tell us the period your customer expects the report to cover.

  • AICPA

    peer-reviewed firm

  • 500+

    audit and attestation engagements

  • 50

    states served

  • 16+

    years auditing experience

Firm figures, as of September 2026.

George Dimov on trust in financial work:

A big part of the reason that people use us is what somebody else has said... Anything having to do with financials is just difficult to trust.
George Dimov, CPA

What one client said about our audit work:

Excellent service. Audit report done on time.
Shadrak Shabbas, Google review

Audit and attestation services

Treat the information as general, and ask a CPA to read your customer's request before you commit to a report.

Ask about SOC audit services for your company

Send your customer's request and a short description of the service you provide. We will tell you which report your customer needs and scope the work.

Contact

Connect with Dimov Audit

Our dedicated team is ready to assist you on your path to financial success.

New York Office

24 Mercer St, 2nd Floor, Suite 214
New York, NY 10013
United States

Reviewed by George Dimov, CPA. Dimov Audit examines controls at service companies under AICPA attestation standards. George brings 20+ years of accounting and consulting experience. Profile