SSAE 18
SSAE 18 is an attestation standard published by the American Institute of Certified Public Accountants (AICPA) that guides how CPA auditors evaluate and report on a service organization's controls. It is the standard under which SOC examinations are performed, producing an auditor's report rather than a certificate. It recodified and superseded a series of earlier attestation standards to improve the usefulness and quality of these reports.
SSAE No. 18, Statement on Standards for Attestation Engagements No. 18, is issued by the AICPA and serves as the professional standard governing attestation engagements, including SOC examinations performed by licensed CPA firms. It recodified and superseded SSAE Nos. 10-17 (subject to certain exceptions noted in the AICPA source) and consolidated prior guidance, including the standard formerly known as SSAE 16, into a unified framework. SSAE 18 provides practitioners with guidance on evaluating and reporting on a service organization's controls; the resulting deliverable is an attestation report, and its conclusions are bounded by the controls and period covered by the engagement. It does not constitute a certification and is distinct from certification-based frameworks such as ISO/IEC 27001.
Why it matters
SSAE 18 is the professional standard that gives SOC examinations their authority and consistency. Because a SOC 2 or SOC 1 engagement is an attestation performed by a licensed CPA firm rather than a certification, the credibility of the resulting report depends on the practitioner following a recognized standard. SSAE 18 provides that standard, defining how auditors evaluate and report on a service organization's controls. Understanding this connection helps compliance professionals frame what a SOC report actually represents: an independent CPA's opinion, bounded by the controls and the period covered, not a guarantee against breaches or a certificate of security.
SSAE 18 also matters because it consolidated and clarified prior guidance. It recodified and superseded a series of earlier attestation standards (SSAE Nos. 10-17, subject to certain exceptions noted in the AICPA source) and absorbed the standard formerly known as SSAE 16 into a unified framework. This recodification was aimed at increasing the usefulness and quality of these reports, giving readers greater confidence in the consistency of the underlying methodology across engagements and firms.
For teams that request or rely on SOC reports, knowing that the work sits under SSAE 18 clarifies both its value and its limits. The standard governs how the examination is conducted, but the conclusions remain scoped to the specific controls and time period the engagement covered. It is distinct from certification-based frameworks such as ISO/IEC 27001, so an SSAE 18 attestation report should not be treated as interchangeable with an ISO certificate, and satisfying one does not automatically satisfy the other.
Who it's relevant to
Inside SSAE 18
Common questions
Answers to the questions practitioners most commonly ask about SSAE 18.