SSAE 18: US Attestation Standard for Service Organizations
Statement on Standards for Attestation Engagements No. 18 (SSAE 18) is the AICPA professional standard that governs how CPAs perform attestation engagements in the United States, including SOC 1 (service organization controls relevant to financial reporting) and SOC 2 (service organization controls for security, availability, processing integrity, confidentiality, and privacy) reports. Understanding SSAE 18 helps organizations navigate the SOC reporting process more effectively.
What SSAE 18 Is and Who Issues It
SSAE 18 was issued by the AICPA's Auditing Standards Board (ASB) and became effective for reports issued on or after May 1, 2017. It superseded and replaced SSAE 16, which itself replaced the older SAS 70 standard in 2011. Each successive iteration has strengthened requirements for auditor independence, evidence standards, and reporting transparency — reflecting lessons learned from audit failures and evolving assurance needs.
The AICPA is the national professional organization for CPAs in the United States. Its standards are mandatory for AICPA members performing attestation engagements and are widely recognized as authoritative by regulators, investors, and clients. SSAE 18 is specifically a US standard — its international counterpart is ISAE 3402, issued by the IAASB. The two standards are closely aligned (90% overlap) but not identical; US CPA firms issue reports under SSAE 18 while non-US firms use ISAE 3402.
The significance of SSAE 18 extends beyond the text of the standard itself. It is the authoritative basis for the AICPA's entire SOC reporting suite — SOC 1, SOC 2, and SOC 3 reports all derive from SSAE 18 attestation requirements, with the AICPA's Trust Services Criteria, SOC for Cybersecurity, and SOC for Supply Chain guides layering on additional subject-matter-specific guidance.
Who Needs to Understand SSAE 18
Several groups have a direct stake in understanding SSAE 18 requirements:
Service organizations undergoing SOC 1 or SOC 2 examinations are the primary subjects. Understanding what the standard requires helps management prepare effective system descriptions, maintain consistent controls throughout the observation period, and produce the evidence the auditor will need. Under-preparation is the leading cause of audit delays and exceptions.
CPA firms performing attestation engagements must comply with SSAE 18 as a professional standard. Failure to follow SSAE 18 requirements when issuing SOC reports creates professional liability and exposes the firm to peer review findings.
User entities receiving SOC reports should understand SSAE 18 well enough to evaluate the report they receive: is the observation period current? Are the control objectives meaningful? Do reported exceptions affect controls relevant to their use of the service? What complementary user entity controls (CUECs) must they maintain?
Compliance professionals and internal auditors managing SOC programmes benefit from SSAE 18 literacy to assess vendor SOC reports, identify gaps, and explain the reports to business stakeholders.
Procurement and vendor risk teams use SOC reports as primary evidence in vendor risk assessments. Understanding the difference between Type 1 and Type 2, the significance of exceptions, and how to read the description of tests performed makes these teams far more effective.
The Standard's Structure: AT-C Sections in Depth
SSAE 18 is codified in the AT-C (Attestation — Clarified) section of the AICPA Professional Standards. The key sections are:
AT-C Section 105 — Concepts Common to All Attestation Engagements
This section establishes the foundational concepts: the meaning of attestation, the distinction between the attest function and consulting or advisory work, professional skepticism requirements, and the general requirements for independence, due care, competence, and reporting. It defines the levels of attestation — examination (highest), review (moderate), and agreed-upon procedures (reporting only, no opinion) — that govern the depth of work performed and the strength of the opinion issued.
AT-C Section 205 — Examination Engagements
SOC 2 reports are examination engagements under AT-C 205. This section governs the planning, evidence gathering, evaluation, and reporting requirements when the practitioner issues a positive-form opinion — stating affirmatively that the subject matter is fairly presented in all material respects. AT-C 205 requires the practitioner to assess engagement risk, design procedures responsive to that risk, obtain sufficient appropriate evidence, and evaluate evidence findings.
The "sufficient appropriate evidence" standard is particularly important. The auditor must design tests that are broad enough to provide confidence about the entire observation period, not just the moments they directly observe. For controls that operate frequently (daily backups, automated monitoring), a representative sample may suffice. For controls that operate rarely (annual access reviews, quarterly risk assessments), every instance may be in scope.
AT-C Section 210 — Review Engagements
Review engagements provide limited assurance — the practitioner states negatively that nothing came to their attention suggesting the subject matter is not fairly presented. Reviews are less common for SOC reports but are used in certain contexts where the cost of an examination is not warranted by the risk level.
AT-C Section 215 — Agreed-Upon Procedures
AUP engagements are not opinions — the practitioner reports findings from specified procedures agreed upon by the engaging parties. AUP engagements under AT-C 215 are sometimes used for targeted compliance validation, vendor due diligence, or regulatory submissions where the requesting party specifies exactly which procedures should be performed.
AT-C Section 320 — Reporting on an Examination of Controls at a Service Organization
This is the section specifically governing SOC 1 reports. It defines the requirements for the service organization's system description, management's assertion, the service auditor's report, and (for Type 2) the description of tests and results. AT-C 320 requires the service auditor to evaluate whether the description fairly presents the service organization's system, whether controls are suitably designed, and (for Type 2) whether they operated effectively throughout the period.
A significant SSAE 18 innovation over its predecessor (SSAE 16) is the explicit requirement for the service organization to monitor the controls of subservice organizations it uses. If your payroll processing service uses a cloud provider to host its systems, SSAE 18 requires you to address that subservice organization through either the inclusive or carve-out method. Auditors must specifically evaluate the service organization's subservice organization monitoring process.
Type 1 vs Type 2: Impact on Reliance
SOC 1 Type 1 reports address control design at a point in time. They are useful for establishing a baseline, satisfying initial client requests, and preparing for a Type 2 observation period. User entity auditors generally cannot place substantive reliance on a Type 1 report.
SOC 1 Type 2 reports cover operating effectiveness over the observation period (minimum six months for SOC 1; the AICPA Trust Services Criteria require at least six months for SOC 2 as well). User entity auditors can rely on a clean Type 2 report to reduce their own substantive testing of the service organization's controls. This reliance reduces the cost and complexity of user entity financial statement audits — a major commercial benefit for service organizations that can point to a clean SOC 1 Type 2 report.
For SOC 2, the commercial dynamic is similar but the audience shifts. Enterprise buyers use SOC 2 Type 2 reports to assess vendor security rather than for financial audit reliance. A clean SOC 2 Type 2 report under SSAE 18 / Trust Services Criteria is the gold standard for technology vendor security assurance. See the full SOC 2 guide for detailed coverage.
The Engagement Process Under SSAE 18
Acceptance and planning: The service auditor assesses independence, evaluates the engagement's appropriateness, and plans risk-responsive procedures. The service organization and auditor agree on the description boundary, control objectives (SOC 1) or trust service criteria (SOC 2), and the observation period.
Readiness preparation: Before the observation period begins, the service organization should conduct a readiness assessment to identify control design gaps and remediate them. Starting an SSAE 18 observation period before controls are consistently designed and documented is a common and costly mistake.
Observation period operation: Controls must operate as described throughout the period. Evidence is collected systematically — logs, tickets, approvals, policy attestations, access reviews, and other artifacts documenting that controls ran as designed.
Fieldwork: The service auditor obtains and tests evidence, assesses the fairness of the description, and evaluates findings. For Type 2, the auditor assesses the nature, timing, and extent of testing needed to conclude on operating effectiveness.
Reporting: The service auditor issues a report with an opinion. For Type 2, the description of tests and results is included. The service organization and client must agree on the report's distribution — SOC 1 and SOC 2 reports are restricted-use documents shared only with clients and their auditors (SOC 3 is the public-facing summary version).
Costs and Timeline
| Activity | Typical Cost | Timeline |
|---|---|---|
| Readiness assessment | $10,000 – $25,000 | 3–6 weeks |
| SOC 1 Type 1 examination | $15,000 – $50,000 | 4–8 weeks |
| SOC 1 Type 2 examination | $25,000 – $100,000 | 6–9 months total |
| SOC 2 Type 1 examination | $20,000 – $60,000 | 4–8 weeks |
| SOC 2 Type 2 examination | $30,000 – $200,000 | 6–9 months total |
| Annual renewal (Type 2) | $25,000 – $150,000 | 3–6 months |
First-time engagements cost approximately 30–50% more than renewals due to higher auditor effort in initial system understanding and readiness work.
SSAE 18 vs ISAE 3402
The practical distinction is geographic. SSAE 18 governs US CPA firms operating under AICPA standards; ISAE 3402 governs international assurance practitioners. The underlying substantive requirements are nearly identical (90% overlap). For service organizations with global clients, it is common to issue a dual-standard report — under both SSAE 18 and ISAE 3402 — using the same underlying audit work. Discuss the dual-standard approach with your audit firm if your client base spans US and international financial auditors.
See also:
- ISAE 3402 guide for the international equivalent
- ISAE 3000 guide for the overarching assurance framework
- SOC 2 guide for the security and privacy-focused SOC report
How Automation Helps
Executing an SSAE 18 SOC engagement requires collecting and organizing substantial evidence across many systems over an extended observation period. The evidence management burden — pull approvals from ticketing systems, access logs from identity management tools, backup confirmation logs, security scan results — is where compliance programs spend most of their time.
LowerPlane integrates with common infrastructure tools to automate evidence collection for SOC 1 and SOC 2 engagements, reducing manual effort by a substantial margin. With 50+ framework support and a 9.4/10 satisfaction rating from AuditXYZ users, it is priced from $4,000 per year with a free tier available. See the best compliance automation platforms comparison for a side-by-side evaluation.
Frequently Asked Questions
What changed from SSAE 16 to SSAE 18? SSAE 18 introduced three significant changes over its predecessor. First, it explicitly requires service organizations to monitor controls at the subservice organizations they use and to disclose relevant subservice organizations in the system description. Second, it clarified the requirements for management's written assertion. Third, it consolidated and clarified the attestation standards into the new AT-C codification structure, replacing the previous SAS/SSAE hybrid framework. Substantively, SSAE 18 engagements look very similar to SSAE 16 engagements to most users.
Can a SOC 2 report serve both internal risk management and client assurance purposes? Yes. SOC 2 reports are commonly used for both: as an internal compliance milestone validating that controls are operating effectively, and as external assurance provided to enterprise clients and prospects during security reviews. The restricted-use nature of SOC 1 and SOC 2 reports means they are shared under NDA or through secure portals rather than publicly posted — SOC 3 serves the public disclosure function.
Does SSAE 18 require the auditor to assess cybersecurity risks? For SOC 2 engagements, the Trust Services Criteria — not SSAE 18 itself — define what the auditor evaluates. The Security criterion (CC6-CC9) addresses cybersecurity controls. The service auditor assesses whether controls are suitably designed and operating effectively against those criteria, which includes logical and physical access controls, system monitoring, change management, and risk mitigation. SSAE 18 governs how the auditor reaches and expresses conclusions, while the Trust Services Criteria define what the controls should achieve.
How long should organizations retain SOC reports? Current SOC 1 and SOC 2 reports are retained for ongoing client assurance. Prior reports are typically retained for 5–7 years to support regulatory inquiries, litigation discovery, or internal investigations. The practical guidance is to retain all reports indefinitely given the low storage cost and potential future evidentiary value.
What is a SOC 2+ report and how does it relate to SSAE 18? A SOC 2+ report adds evaluation against an additional framework — such as HITRUST, NIST CSF, or CSA CCM — alongside the Trust Services Criteria. The + framework's controls are mapped to the Trust Services Criteria or evaluated in a separate section. The SOC 2+ structure allows the AICPA's recognized reporting format to accommodate framework-specific requirements, but it is important to understand that the "+" criteria are evaluated within the SSAE 18 examination framework — the practitioner must be competent to assess the additional framework criteria.