Section 3: 15–25%I11
Types of SOC Engagements (SOC 1, 2, and 3)
Exam insight
Service organizations (payroll processors, SaaS providers, data centers) handle data and processes that affect their customers, and ISC leans hard on which SOC report fits which need. Knowing the purpose, subject matter, and intended users of each SOC report underpins nearly every other ISC topic.
What AICPA wants you to know
- 1Distinguish SOC 1, SOC 2, and SOC 3 engagements by subject matter and intended users.
- 2Explain the difference between a Type 1 report (design only) and a Type 2 report (design and operating effectiveness).
- 3Define service organization, user entity, subservice organization, and complementary user entity controls.
- 4Compare the carve-out method and the inclusive method for handling subservice organizations.
- 5Identify SOC for Cybersecurity and SOC for Supply Chain and how they differ from the core SOC reports.
- 6Match a real-world scenario to the appropriate SOC report and report type.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
The SOC SelectorMatch scenario to report: SOC 1 for financial reporting, SOC 2 restricted, SOC 3 public, then pick the Type and trust services category.The SOC MechanicsKnow the roles and ownership: the service organization writes the description and assertion, the auditor opines, and CUECs sit with the user.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.