Scrutineer · By framework
SOC 1 compliance software for SSAE 18 reports and Type 2 audits
A SOC 1 has no standard criteria. Your management writes the control objectives and a CPA firm tests what you wrote, which is why a downloaded checklist never quite fits.
Scrutineer holds the objectives, the controls sitting under them and the evidence for every month of the period, so the description of the system matches what actually ran.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with SOC 1 compliance software
The trigger is your customer financial audit, not your security program
A SOC 1 exists for one reason: your service touches something that ends up in your customers financial statements. Payroll, claims processing, billing and receivables, loan servicing, fund administration, custody and transfer agency work all qualify. Under AU-C 402 a user auditor has to understand controls at any service organization relevant to internal control over financial reporting, and a SOC 1 is how they get that understanding without auditing you themselves. If nobody is relying on you for a number in a financial statement, you probably need a SOC 2 instead. Scrutineer pins that question first, because building the wrong report is a full year lost.
Nobody hands you the control objectives, and that is the hard part
SOC 2 gives you the Trust Services Criteria and you map to them. SOC 1 gives you nothing. Management writes the control objectives, tied to the risks your processing creates for the user entities, and the service auditor tests what you wrote. Write them too narrowly and you get a clean opinion that your customers auditors still cannot rely on, which is the worst possible outcome because it costs the full fee and buys nothing. Scrutineer keeps each objective next to the controls that support it and the evidence that proves the control ran, so a gap in coverage is visible before fieldwork, not after.
A Type 2 covers a period, so the evidence has to exist for the whole period
A Type 1 describes design at a point in time. A Type 2 tests operating effectiveness across a stated period, commonly six to twelve months, and that changes what evidence means. A screenshot taken the week before fieldwork does not show that quarterly access reviews happened in month two. Scrutineer pulls proof from your identity, ticketing and cloud systems on a schedule and timestamps it, so a sample drawn from any month in the window has something behind it. It also tracks the gap between your period end and each customer fiscal year end, which is what a bridge letter is meant to cover.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Settles whether your service is actually ICFR relevant, so you scope a SOC 1 rather than defaulting to a SOC 2 your customers did not ask for
- Holds management written control objectives with the controls and evidence mapped under each one, instead of in a spreadsheet nobody updates
- Timestamps evidence across the full Type 2 period, so a sample from month two has proof behind it rather than a screenshot from last week
- Tracks complementary user entity controls so the CUEC list in your description reflects what you genuinely depend on customers to do
- Records subservice organizations and whether each is carved out or included, and flags when a carved out provider SOC report has lapsed
- Reuses the same evidence base for SOC 2, ISO 27001 and SOX Section 404, because the IT general controls underneath them overlap heavily
- Keeps the description of the system aligned with what changed during the period, which is where most exceptions actually originate
- Flags the window between your report period end and each customer year end, so bridge letters go out before the request arrives
- Answers the control questionnaires and CUEC confirmations that user auditors send during their own busy season
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Report reference
What your customer actually asked for, who writes the criteria, and who is allowed to read it
Most comparisons of SOC reports line up SOC 1, SOC 2 and SOC 3 as though they were three tiers of the same thing. They are not. The distinction that decides your project is who writes the criteria: for SOC 2 the AICPA does, and you map to a fixed list. For SOC 1 your own management does, and a clean opinion on badly written objectives is worth nothing to the auditor who asked. Find the row that matches the request you received, then read the last column, because that is where the money is lost.
| What you were asked for | Who writes the criteria | What it actually covers | Who may read it | Where it goes wrong |
|---|---|---|---|---|
| A SOC 1 Type 2 report | Your management writes the control objectives. The AICPA publishes no criteria list for SOC 1. | Design and operating effectiveness of controls relevant to customers financial reporting, tested across a stated period of commonly six to twelve months | Restricted use: your management, your user entities, and their financial statement auditors | Objectives written too narrowly. You get a clean opinion, pay the full fee, and the user auditor still cannot place reliance on it under AU-C 402. |
| A SOC 1 Type 1 report | Your management, same as a Type 2 | Suitability of design and implementation at a single point in time. No testing of whether controls actually operated. | Restricted use, same audience | Treated as a cheaper substitute. It is a reasonable first year step, but a user auditor relying on your controls generally cannot use a Type 1, and no bridge letter is available for one. |
| A SOC 2 report | The AICPA, through the Trust Services Criteria: security, plus any of availability, processing integrity, confidentiality and privacy | Security and operational commitments. Not financial reporting. | Restricted use, though widely shared under NDA with prospects and vendor risk teams | Sent to a customer external auditor who asked for financial reporting assurance. A SOC 2 does not answer AU-C 402 no matter how thorough it is. |
| A SOC 3 report | The AICPA Trust Services Criteria, same as SOC 2 | A short general use summary of a SOC 2 Type 2 examination, without the detailed tests and results | General use. You may publish it on your website. | Asking for a public SOC 1. There is no SOC 3 equivalent for SOC 1, so a publishable financial controls report simply does not exist. |
| SSAE 18 certification, or SSAE 16 certification | Nobody. The request is malformed and the honest reply is a correction. | SSAE 18 is the standard that created AT-C 320, the section a SOC 1 is performed under. SSAE 16 was its predecessor and was superseded in 2017. | Not applicable | Answering yes. There is no SOC 1 certificate and nobody is SSAE certified. Claiming otherwise in a security questionnaire is a misstatement a diligent buyer will catch. |
| An ISAE 3402 report | Your management writes the objectives, exactly as in SOC 1 | The international equivalent of SOC 1, issued under IAASB standards, commonly requested by European and Asian auditors | Restricted use, scoped by the reporting framework | Commissioning a second, separate examination. A CPA firm can usually issue a combined SOC 1 and ISAE 3402 report from one set of fieldwork, so paying twice is avoidable. |
| A bridge letter, or gap letter | Your management writes and signs it. The service auditor does not. | An assertion that nothing material changed between your report period end and the customer year end, typically covering no more than three months | The same audience as the report it bridges | Assuming it carries audit weight. It is unaudited management representation, only available for a Type 2, and some user auditors decline it entirely or refuse long gaps. |
| Assurance over a subservice organization you carved out | Your management identifies the complementary subservice organization controls it expects | The description names the subservice organization and the controls expected of it. Those controls are named, not tested. | The same audience as your report | Reading CSOCs as tested coverage. They are a disclosure, not an assertion, and your customer still has to obtain the subservice organization own SOC report to close the chain. |
Reflects the standards in force as at August 2026. A SOC 1 is performed under AT-C section 320, created by SSAE 18, layered on AT-C 105 and AT-C 205 as revised by SSAE 21, with the SSAE 23 quality management amendments applying to engagements beginning on or after December 15, 2025. SSAE 21 did not replace SSAE 18 for SOC 1, contrary to a good deal of published guidance. Scrutineer prepares and maintains control evidence. It does not perform examinations, and no software vendor can issue a SOC 1 opinion.
Good questions
Questions about SOC 1 compliance software
Keep reading
Guides that go deeper on service organization reporting
SOC 1 compliance checklist: what auditors test
There is no standard checklist, because your management writes the objectives. Here is what actually generalizes, and what fieldwork looks like.
Read the guideIT general controls explained
Access, change management and operations: the layer underneath every SOC 1, SOC 2 and SOX program, and where exceptions usually originate.
Read the guideSOC 2 Type 1 vs Type 2
The same point-in-time versus period distinction, on the security side, and how to sequence the two without paying twice.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification