SSAE 18 Explained: The Standard Behind SOC 1
Every SOC 1 report is produced under an AICPA attestation standard called SSAE 18. You don’t need to read the standard -- but you should understand what it requires of your CPA firm and what the key terms in your report mean.
What SSAE 18 is
SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the AICPA’s rulebook for attestation examinations, including SOC 1. It defines how the CPA firm plans the examination, what evidence it must obtain, how it forms its opinion, and what the report must contain. When a firm says it performs SOC 1 ‘in accordance with SSAE 18,’ it means the examination followed these rules -- which is what makes the report reliable to your customers’ auditors.
Type 1 vs Type 2 under SSAE 18
SSAE 18 defines the two report types: a Type 1 covers the design of controls at a point in time, while a Type 2 covers design and operating effectiveness throughout a period (minimum 6 months, typically 12). Only a Type 2 lets your customers’ auditors rely on your controls having actually operated -- which is why most enterprise customers require one. Full Type 1 vs Type 2 comparison.
Key terms in your report
- System description: your written description of the services and controls -- the CPA firm opines on it, so it must be accurate.
- Control objectives: the outcomes your controls are designed to achieve (you define these; the firm tests against them).
- Complementary user entity controls (CUECs): controls your customers must have for your controls to work -- spelled out so their auditors know their side of the bargain.
- Subservice organizations: vendors you rely on (e.g., a data center). Carve-out excludes their controls from your report; inclusive includes them. The choice changes what your customers’ auditors can rely on.
- Exceptions / qualified opinion: control failures found during the period. A few exceptions are normal; a qualified opinion means the failures were material.
Why only a CPA firm can issue it
SSAE 18 is an AICPA standard, and only licensed CPA firms are authorized to perform examinations under it. A ‘SOC 1 report’ from anyone else isn’t a SOC 1 report. Confirm your firm’s CPA credentials before you sign -- browse verified SOC 1 CPA firms.
Questions
Is SSAE 18 the same as SOC 1?
SSAE 18 is the AICPA standard; SOC 1 is the report produced under it. People use the terms interchangeably, but precisely: your CPA firm performs the examination in accordance with SSAE 18 and issues a SOC 1 report.
Did SSAE 18 replace something?
Yes -- SSAE 18 replaced SSAE 16 in 2017. If a customer still asks for an ‘SSAE 16,’ they mean a current SOC 1 report.
Related reading
Get quotes from SOC 1 CPA firms
Tell us about your environment once -- matched CPA firms reply with scoped quotes. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.