Atlas Systems Named a Representative Vendor in 2025 Gartner® Market Guide for TPRM Technology Solutions → Read More

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

SOC 1 / SOC 2 / SOC 3

Last updated: Nov 26, 2025

Glossary › SOC 1 / SOC 2 / SOC 3

What is SOC 1 / SOC 2 / SOC 3?

SOC reports, issued under the AICPA framework, assess vendor control environments. SOC 1 focuses on financial reporting controls, SOC 2 on security and privacy principles, and SOC 3 on general-use summaries. In TPRM, SOC reports are core evidence tools for validating vendor control maturity.

FAQs

Why request SOC reports?

They provide independent assurance of controls.

How often are reports issued?

Annually.

Do SOC reports replace assessments?

No, they supplement them.

robot-human

Reinventing TPRM with
ComplyScore®

Learn how leading risk teams reduce cyber risk and protect compliance faster.

Third-party delays hurt compliance. Automate onboarding and stay ahead with ComplyScore®.