SOC 1 audit services

If your service touches your customers' financial reporting, their auditors will ask for a SOC 1 report. We perform Type 1 and Type 2 examinations through our CPA attest arm under SSAE 18, from scoping through the signed opinion.
Talk to an auditor
Definition

What is a SOC 1 audit?

A SOC 1 audit is an independent examination of the controls at a service organization that are relevant to its customers' internal control over financial reporting. It is performed under the AICPA attestation standards (SSAE 18, AT-C section 320). The deliverable is a restricted-use report for your customers and their auditors: the auditor's opinion, management's assertion, the system description, and the control objectives with tests and results. BD Emerson performs SOC 1 Type 1 and Type 2 examinations directly through its CPA attest arm, from scoping and control objective definition through fieldwork and the signed opinion.

Services

What does a SOC 1 examination cover?

SOC 1 vs SOC 2
Business process controls
IT general controls
Type 1 and Type 2 reports
What the report contains
CUECs and subservice organizations

SOC 1 vs SOC 2

A SOC 1 tests control objectives you define around customers' financial reporting, while SOC 2 audits test against the Trust Services Criteria. User auditors read a SOC 1; security teams and procurement read a SOC 2. Many service organizations need both.

Business process controls

Control objectives span the transaction flow your service runs for customers: initiation, processing, recording, and reporting. We test that each objective is achieved from input through the entries that reach your customers' ledgers.

IT general controls

Business process controls depend on the systems beneath them, so the examination also covers IT general controls: access, change management, and computer operations for the applications and infrastructure in scope.

Type 1 and Type 2 reports

A Type 1 reports on control design at a point in time. A Type 2 covers design and operating effectiveness over a review period, normally six to twelve months, set so it covers most of your customers' fiscal year.

What the report contains

The report carries the auditor's opinion, management's assertion, the system description in Section 3, and each control objective with tests and results in Section 4, plus the complementary user entity controls your customers operate. Use is restricted to user entities and their auditors.

CUECs and subservice organizations

We define complementary user entity controls your customers can actually operate, and we present subservice organizations under the carve-out or inclusive method. Carve-out is the common choice, and the boundary is stated plainly either way.

Our approach

How we run the examination

01

Scope before fieldwork

We start with the services that affect customers' ledgers and define control objectives around them. A tight scope keeps testing pointed at what user auditors will rely on.

02

Pick Type 1 or Type 2 deliberately

A first-year Type 1 followed by a Type 2 is the common path. When customers already demand operating effectiveness, we go straight to Type 2 and align the period to their auditors' fiscal-year coverage.

03

Exceptions reported in full

When a control fails testing, the result is reported in Section 4 as it occurred. We evaluate whether the objective is still achieved and explain how the exception will read to user auditors.

04

Pricing tied to named drivers

A Type 1 typically runs $20,000 to $40,000 and a Type 2 $30,000 to $60,000 for a single-service scope. Control objective count, transaction volume, locations, and ITGC centralization move the number.

contact us

Schedule a SOC 1 examination

Talk to an auditor about the services in scope, the control objectives they imply, and the review period your customers' auditors expect.

Our Advantage

Why BD Emerson for SOC 1

Performed by our CPA attest arm

BD Emerson performs SOC 1 examinations directly under the AICPA attestation standards. The partner who signs the opinion scopes the engagement, and fieldwork stays in house.

Independence, stated plainly

Our audit practice is independent of our consulting and technology practices. If BD Emerson consultants built your control environment, AICPA independence rules send the examination to another firm, and we say so.

Reports user auditors can use

Control objectives, tests, and results are written so your customers' auditors can rely on them without follow-up, and the CUECs we define are ones your customers can run.

How We Work

How the SOC 1 examination runs

The examination runs in ten steps from scoping to the signed report. Each step is examination work performed by our CPA attest arm, and your team remediates anything the testing surfaces.
Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What is a SOC 1 audit?

Do my customers want a SOC 1 or a SOC 2?

Who needs a SOC 1 report?

Should we start with a Type 1 or go straight to a Type 2?

What does a SOC 1 audit cost, and how long does it take?

What happens if a control fails testing?

Can the firm that built our controls audit them?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners