SSAE 18 · SOC Reporting · Evidence & Implementation Kit
Get your service organization SOC-ready under SSAE 18, without decoding the attestation standard yourself.
Every readiness step handed to you as an adopt-ready control, from scoping SOC 1 versus SOC 2 and Type 1 versus Type 2 through the system description, control objectives and subservice monitoring, with the evidence your auditor examines.
SOC-ready in a weekend, not a quarter.
Here is the honest situation. Customers now demand a SOC report before they trust you with their data or their financial processes, and SSAE 18 is the attestation standard behind SOC 1 and SOC 2. Getting ready means scoping the right report and type, writing the system description and the management assertion, defining control objectives or selecting the Trust Services Criteria, and, an SSAE 18 emphasis, monitoring your subservice organizations. Preparing all of that and the evidence, and passing the examination, is weeks of work, and a vague system description or unmonitored vendors is exactly where a SOC examination finds exceptions.
This Kit removes the guesswork. It is every SOC readiness step written as an adopt-ready control you personalize in a weekend, with the evidence your auditor examines.
What you get, the moment you buy
33
Readiness steps as adopt-ready controls. Every SOC readiness step, from scoping and the system description through control objectives, the Trust Services Criteria, subservice monitoring and complementary user controls, written so you personalize and apply it.
33
Evidence-they-examine checklists. For each control, exactly what an auditor examines, plus where SOC examinations find exceptions, so you close the gap before the examination.
1
SOC Readiness Control Matrix, pre-built. Every step in a working spreadsheet, ready to record status and evidence location across the service organization.
1
Gap & Readiness Assessment. Score each step and the workbook returns your SOC readiness as a single percentage, and exactly what to fix next.
Grounded in SSAE 18 and the SOC reporting framework, with SOC 1 versus SOC 2, Type 1 versus Type 2, the system description and management assertion, and subservice-organization monitoring called out. Editable Word and Excel files.
Subservice monitoring is what SSAE 18 added
SSAE 18's headline change was requiring service organizations to actively monitor their subservice organizations and vendors. This Kit builds that vendor and subservice monitoring, the carve-out and inclusive methods, and complementary subservice controls, so the requirement examiners now test is handled, not overlooked.
What one control looks like
This is selecting the report type, SOC 1 versus SOC 2 and Type 1 versus Type 2, where readiness begins. All 33 are built to this depth.
SOC-1 Select the report type aligned to user needs SCOPING
Put this in place
[Service Organization] shall formally determine and document whether user entities require a SOC 1 report addressing controls relevant to their internal control over financial reporting or a SOC 2 report addressing the applicable Trust Services Criteria, record the rationale, capture user and regulatory requirements, and obtain executive sign-off on the selected report type before scoping controls.
Practitioner note.
SOC 1 is governed by AT-C 320 and serves user auditors evaluating internal control over financial reporting; SOC 2 addresses security and the other Trust Services Criteria.
Evidence your auditor examines
- Signed report-type decision memo citing SOC 1 versus SOC 2 rationale
- Register of user entity and regulatory requirements driving the selection
- Executive approval record for the chosen examination type
- Meeting minutes documenting the scoping decision
Common finding they raise: Many organizations request a SOC 2 out of habit when user entities actually need SOC 1 assurance over financial reporting controls, or the reverse, causing rework.
Why this is not another template pack
- The evidence is the point. A control you cannot evidence becomes an exception. This tells you exactly what an auditor examines and where SOC examinations find exceptions, for every readiness step.
- The system description and assertion built in. The system description, the management assertion and the control objectives or Trust Services Criteria are written into the controls, the deliverables management owns.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. SOC 2 uses the Trust Services Criteria that align with ISO 27001 and COSO, so this work feeds your wider security and control program.
Who buys this
Service organizations pursuing a SOC 1 or SOC 2 report, the compliance and security leads who own readiness, and consultants preparing for a SOC examination. Whether it is a first report or an annual cycle, you save weeks and walk in with the description, controls and evidence ready.
By the end of the weekend you will have
✓ An adopt-ready control for all 33 steps
✓ A completed SOC readiness control matrix
✓ The evidence your auditor examines
✓ Your system description and assertion anchored
✓ A SOC-readiness percentage and a fix list
✓ The common examination exceptions closed
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
SOC 1 or SOC 2? Both. SOC 1 covers controls over financial reporting; SOC 2 covers the Trust Services Criteria. The Kit helps you scope and prepare for either.
Type 1 or Type 2? Both. Type 1 is design at a point in time; Type 2 adds operating effectiveness over a period. The Kit builds readiness for both.
Does it cover subservice organizations? Yes. Subservice and vendor monitoring, an SSAE 18 emphasis, is its own control group.
What if it is not for me? A 30-day money-back guarantee.
Do not walk into a SOC examination unprepared.
Every SOC readiness step is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be SOC-ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com