Skip to main content
Category: SOC Reporting

Attestation Standards

Also known as: SSAE, Statements on Standards for Attestation Engagements, SSAEs, Attestation Engagement Standards
Simply put

Attestation standards are the professional rules that a licensed CPA firm follows when it examines and issues a formal opinion on management's claims about its controls. In the SOC 2 context, these standards are why a SOC 2 engagement produces an attestation report rather than a certification. The report reflects the CPA's opinion on the controls and period covered, not a guarantee that no security issues exist.

Formal definition

Attestation standards, issued by the AICPA as the Statements on Standards for Attestation Engagements (SSAEs), govern the conduct of attest engagements performed by CPA firms for nonissuers and provide the professional framework under which reports such as SOC 2 are prepared and issued. These standards relate to the conduct of individual attest engagements, distinct from quality control standards that govern a firm's overall attest practice, and they establish the requirements a practitioner follows in examining and reporting on management's assertions about its controls. A SOC 2 engagement performed under these standards results in an attestation report expressing the CPA's opinion, covering only the controls in scope and the specified period; it is not a certification and does not attest to matters outside the defined scope. In practice, the applicable standard and its requirements depend on the type of engagement, the assertions being examined, and scoping decisions made for that engagement.

Why it matters

Attestation standards are the reason a SOC 2 engagement produces an attestation report rather than a certification. When a licensed CPA firm examines management's claims about its controls, it does so under the AICPA's Statements on Standards for Attestation Engagements (SSAEs), which establish the professional requirements the practitioner must follow in examining and reporting on those assertions. Understanding this distinction matters because it defines what a SOC 2 report actually represents: the CPA's opinion on the controls in scope over the specified period, not a guarantee that no security issues exist or will occur.

For compliance managers and the organizations relying on their reports, this framing has practical consequences. Because the SSAEs govern how the opinion is formed and reported, a SOC 2 report carries meaning only within its defined scope and review period. It does not attest to matters outside that scope, and it should not be read as a broad assurance of security. This is a common point of confusion when a customer or vendor treats a SOC 2 report as equivalent to a certification such as ISO 27001, which is issued by an accredited certification body under a different model entirely.

The standards also clarify who is qualified to perform the work. Because SSAEs apply to attest engagements performed by CPA firms, a SOC 2 report reflects an opinion issued by a licensed practitioner following an established professional framework. This is part of why the resulting report is treated as a credible, third-party attestation rather than a self-declaration, while still being bounded by the engagement's scoping decisions.

Who it's relevant to

Compliance and GRC Managers
These professionals need to understand that a SOC 2 report is an attestation issued under the SSAEs, meaning it reflects a CPA's opinion bounded by scope and period. This helps them set accurate expectations internally and with customers, and avoid conflating a SOC 2 report with a certification such as ISO 27001, which follows a different model.
Auditors and CPA Practitioners
Practitioners performing SOC 2 engagements work directly under the SSAEs, which establish the requirements for examining and reporting on management's assertions. They must also distinguish these engagement-level standards from the quality control standards that govern their firm's overall attest practice, and apply the requirements appropriate to the engagement type and assertions in scope.
Vendor Risk and Procurement Teams
Teams evaluating a supplier's SOC 2 report benefit from knowing it is an attestation covering only the controls and period in scope, not a guarantee that no security issues exist. This informs how much assurance to draw from the report and where additional due diligence may be warranted.
Security Engineers and Control Owners
Those responsible for the controls being examined benefit from understanding that the CPA's opinion is formed under an established professional framework and is limited to the assertions and scope defined for the engagement. This clarifies what evidence supports the attestation and where the boundaries of the report lie.

Inside SSAE

SSAE 18
The Statements on Standards for Attestation Engagements No. 18, issued by the AICPA, under which SOC 2 examinations are performed. It establishes the requirements a licensed CPA firm follows when conducting an attestation engagement and reporting on a service organization's controls.
Attestation Engagement
An engagement in which a practitioner issues a report on subject matter, or an assertion about subject matter, that is the responsibility of another party (the service organization). A SOC 2 examination is an attestation engagement resulting in a report rather than a certification.
Management Assertion
The written statement prepared by the service organization's management describing its system and asserting that controls are suitably designed (and, for Type II, operating effectively) against the applicable Trust Services Criteria. The practitioner attests to this assertion.
Type I vs. Type II Scope
Under the attestation standards, a Type I report addresses the suitability of design of controls at a point in time, while a Type II report addresses both design and operating effectiveness over a defined review period whose length is set by scoping decisions.
Trust Services Criteria
The criteria against which controls are evaluated in a SOC 2 attestation. Security (the Common Criteria) is the only required category; Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. These are distinct from ISO 27001 Annex A controls.
Practitioner's Report and Opinion
The output of the attestation, in which the licensed CPA firm expresses an opinion on the subject matter or management's assertion. The report attests only to the controls and period covered.

Common questions

Answers to the questions practitioners most commonly ask about SSAE.

Is a SOC 2 report the same as a certification?
No. A SOC 2 report is the product of an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 attestation standards. It results in a report expressing the practitioner's opinion, not a certificate. Certification is a different model, used, for example, in ISO/IEC 27001, where an accredited certification body issues a certificate against a management system standard. Referring to a SOC 2 outcome as a 'certification' misstates both the standard applied and the nature of the deliverable.
Does an attestation report guarantee that an organization has not experienced or will not experience a breach?
No. An attestation report speaks only to the controls and the period covered by the engagement. A SOC 2 Type II report, for instance, addresses the design and operating effectiveness of the described controls over the defined review period; it does not assert that no security incident occurred or guarantee freedom from future breaches. The scope, the criteria selected, and the period examined all bound what the report can and cannot support.
Which attestation standard governs a SOC 2 examination?
SOC 2 examinations are conducted under the AICPA's SSAE 18 attestation standards, performed by a licensed CPA firm. The examination evaluates controls against the applicable Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. The specific criteria in scope should be confirmed with the practitioner during scoping.
How do I decide between a Type I and a Type II attestation?
The choice depends on what you need to demonstrate. A Type I addresses the suitability of the design of controls at a point in time, which can be appropriate when you need to show a control environment is in place. A Type II addresses both design and operating effectiveness over a defined review period, which typically provides stronger assurance to customers. The length of the review period is a scoping decision and varies by engagement, so discuss timing and objectives with your CPA firm.
Can a single attestation report satisfy both SOC 2 and ISO 27001 requirements?
Not automatically. SOC 2 is an attestation examination under SSAE 18, while ISO/IEC 27001 is a certification against a management system standard issued by an accredited certification body. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other. Organizations pursuing both typically coordinate evidence collection where controls overlap, but each outcome is produced under its own process and against its own criteria.
What should I confirm about scope before an attestation engagement begins?
Clarify which Trust Services Criteria categories are in scope, since Security is required while the other categories are optional and selected based on your reporting objectives. For a Type II, confirm the review period, as it is set by scoping decisions rather than fixed by the standard. Because an attestation report attests only to the controls and period covered, aligning scope with what your customers or stakeholders need is a practical step to take early with your CPA firm.

Common misconceptions

A SOC 2 attestation results in a certification that proves an organization is secure.
A SOC 2 examination is an attestation performed by a licensed CPA firm under SSAE 18 and results in a report, not a certification. The report attests only to the controls and period covered and does not guarantee freedom from breaches. ISO/IEC 27001, by contrast, is a certification issued by an accredited certification body.
The attestation standards mandate a fixed review period for a SOC 2 Type II engagement.
A Type II report addresses operating effectiveness over a defined review period, but the length of that period is set by scoping decisions rather than fixed by the standard. A Type I report, by contrast, addresses only design suitability at a point in time.
Passing a SOC 2 attestation automatically satisfies ISO 27001 requirements because both cover security.
The two frameworks are distinct, and mapping between them is possible but partial. Satisfying one does not automatically satisfy the other, and the Trust Services Criteria should not be conflated with ISO 27001's clause 4-10 requirements or Annex A controls.

Best practices

Confirm that the attestation is performed by a licensed CPA firm under SSAE 18 and refer to the outcome as a report, not a certification.
Clearly define the engagement type early, distinguishing a Type I (design suitability at a point in time) from a Type II (design and operating effectiveness over a defined period), and set the review period through deliberate scoping decisions.
Select the applicable Trust Services Criteria based on scope, treating Security (the Common Criteria) as required and Availability, Processing Integrity, Confidentiality, and Privacy as optional additions.
Prepare a clear management assertion describing the system and controls, since the practitioner attests to that assertion under the attestation standards.
Communicate the report's boundaries to stakeholders, noting that it attests only to the controls and period covered and does not guarantee freedom from breaches.
When comparing to ISO 27001 or other reports such as SOC 1 or SOC 3, treat any cross-framework mapping as partial and avoid asserting that one outcome satisfies another.