SSAE 18 SOC 1 Attestation — DC, Maryland & Virginia

    SOC 1 Audit (SSAE 18) for Service Organizations — DC, Maryland & Virginia

    AICPA-standard AT-C 320 reports for payroll processors, benefit administrators, loan servicers, and service organizations. When your clients' auditors ask for your controls report, we make sure you're ready.

    Schedule a Call

    What is a SOC 1 audit and when is it required?

    A SOC 1 audit (SSAE 18 AT-C 320, formerly SAS 70) examines a service organization's internal controls over financial reporting (ICFR). It is required when a service organization processes transactions that affect their clients' financial statements — common for payroll processors, benefit administrators, loan servicers, transfer agents, and data centers. User entity auditors request SOC 1 reports when auditing clients that rely on these service organizations.

    Why Service Organizations Need a SOC 1 Report

    Your client's auditor is requesting your SOC 1 report and you don't have one — threatening the client relationship

    You're a payroll processor or benefits administrator and prospects are asking for your controls report

    Your SOC 1 report expired and you need to renew before your clients' year-ends

    You had a SAS 70 report years ago and need to convert to modern SSAE 18 SOC 1 format

    Key Terms

    SSAE 18
    Statement on Standards for Attestation Engagements No. 18 — the AICPA standard governing SOC 1 (AT-C 320) and SOC 2 (AT-C 205) reports. Replaced SSAE 16 and SAS 70 in 2017.
    User Entity
    The client organization that uses the service organization's services. User entity auditors request SOC 1 reports to understand controls at the service organization that may affect the user entity's financial statements.

    SOC 1 Attestation Services

    Complete SSAE 18 SOC 1 engagements from readiness through annual re-audit.

    SOC 1 Readiness Assessment

    Gap analysis of your current controls against the control objectives you'll include in the report. Identifies documentation gaps and control weaknesses before fieldwork begins.

    Type I Report (SSAE 18 AT-C 320)

    Point-in-time CPA opinion on whether your controls are suitably designed to achieve control objectives. Faster than Type II — no observation period required.

    Type II Report (SSAE 18 AT-C 320)

    6-12 month operating effectiveness testing. The standard required by most user entity auditors. Includes testing procedures, results, and the CPA's opinion on effectiveness.

    Control Remediation

    Guidance on fixing control gaps identified during readiness assessment or fieldwork. We help you implement controls before they appear as exceptions in the final report.

    Annual Re-audit

    Ongoing SOC 1 Type II audits to maintain currency. SOC 1 reports cover a specific period — most user entities require a current report that covers your most recent fiscal year.

    SOC 1 Type I vs Type II — Key Differences

    FeatureSOC 1 Type ISOC 1 Type II
    What it coversControls designed appropriately at a point in timeControls operated effectively over 6-12 months
    Opinion standardSuitability of designOperating effectiveness
    Typical useFirst-year report; new service organizationsOngoing annual requirement; most user entities require Type II
    Timeline2-4 months9-15 months (including observation)
    User entity acceptanceLimited — some accept for first year onlyBroadly accepted; required by most auditors

    SOC 1 Engagement Process — 4 Steps

    1

    Scoping

    Identify which financial reporting controls are in scope based on services provided to user entities. Define the control objectives that will be included in the report.

    2

    Readiness Assessment

    Gap analysis against control objectives. Identify what's documented vs. missing. Provide a remediation roadmap before the observation period or Type I testing begins.

    3

    Type I or Observation Period

    Either point-in-time testing (Type I) for immediate documentation, or 6-12 month effectiveness testing (Type II) for the comprehensive report most auditors require.

    4

    Report Issuance

    CPA issues the SSAE 18 AT-C 320 report. You distribute to user entities and their auditors as needed — and to prospects during the sales process.

    SOC 1 Audit FAQs

    Common questions from service organizations and their finance teams about SSAE 18 SOC 1 reports.

    Client Auditor Requesting Your SOC 1? We Can Help.

    Whether you need a Type I report quickly or a comprehensive Type II engagement, we scope a fixed-fee SOC 1 that meets your users' auditors' requirements.

    Schedule a Call

    Serving payroll processors, benefit administrators, loan servicers, and service organizations in DC, Maryland, Virginia, and nationwide.