Skip to main content
Category: SOC Reporting

SSAE 18

Also known as: SSAE 18, Statement on Standards for Attestation Engagements No. 18, SSAE No. 18
Simply put

SSAE 18 is an attestation standard published by the American Institute of Certified Public Accountants (AICPA) that guides how CPA auditors evaluate and report on a service organization's controls. It is the standard under which SOC examinations are performed, producing an auditor's report rather than a certificate. It recodified and superseded a series of earlier attestation standards to improve the usefulness and quality of these reports.

Formal definition

SSAE No. 18, Statement on Standards for Attestation Engagements No. 18, is issued by the AICPA and serves as the professional standard governing attestation engagements, including SOC examinations performed by licensed CPA firms. It recodified and superseded SSAE Nos. 10-17 (subject to certain exceptions noted in the AICPA source) and consolidated prior guidance, including the standard formerly known as SSAE 16, into a unified framework. SSAE 18 provides practitioners with guidance on evaluating and reporting on a service organization's controls; the resulting deliverable is an attestation report, and its conclusions are bounded by the controls and period covered by the engagement. It does not constitute a certification and is distinct from certification-based frameworks such as ISO/IEC 27001.

Why it matters

SSAE 18 is the professional standard that gives SOC examinations their authority and consistency. Because a SOC 2 or SOC 1 engagement is an attestation performed by a licensed CPA firm rather than a certification, the credibility of the resulting report depends on the practitioner following a recognized standard. SSAE 18 provides that standard, defining how auditors evaluate and report on a service organization's controls. Understanding this connection helps compliance professionals frame what a SOC report actually represents: an independent CPA's opinion, bounded by the controls and the period covered, not a guarantee against breaches or a certificate of security.

SSAE 18 also matters because it consolidated and clarified prior guidance. It recodified and superseded a series of earlier attestation standards (SSAE Nos. 10-17, subject to certain exceptions noted in the AICPA source) and absorbed the standard formerly known as SSAE 16 into a unified framework. This recodification was aimed at increasing the usefulness and quality of these reports, giving readers greater confidence in the consistency of the underlying methodology across engagements and firms.

For teams that request or rely on SOC reports, knowing that the work sits under SSAE 18 clarifies both its value and its limits. The standard governs how the examination is conducted, but the conclusions remain scoped to the specific controls and time period the engagement covered. It is distinct from certification-based frameworks such as ISO/IEC 27001, so an SSAE 18 attestation report should not be treated as interchangeable with an ISO certificate, and satisfying one does not automatically satisfy the other.

Who it's relevant to

Compliance and GRC managers
Professionals overseeing a SOC program need to understand that their examination is performed under SSAE 18 and produces an attestation report scoped to specific controls and a defined period. This helps them accurately describe deliverables to stakeholders and avoid mischaracterizing a SOC report as a certification.
CPA auditors and attestation practitioners
Licensed CPA firms conducting SOC examinations apply SSAE 18 as the governing professional standard for evaluating and reporting on a service organization's controls. It provides the methodology and reporting guidance that give their opinions consistency and authority.
Vendor risk and procurement teams
Teams that request SOC reports from service providers benefit from recognizing that SSAE 18 underpins the report's credibility while also bounding its conclusions to the covered controls and period. This informs how much assurance a report provides and where additional diligence may be warranted.
Security and engineering leaders at service organizations
Leaders preparing their organization for a SOC examination should understand that SSAE 18 governs how auditors will assess their controls. Because scope decisions shape which criteria and time period are evaluated, this context helps them plan control implementation and evidence collection appropriately.

Inside SSAE 18

AICPA Attestation Standard
SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the AICPA standard under which a SOC 2 examination is performed by a licensed CPA firm, resulting in an attestation report rather than a certification.
Attestation Engagement Framework
It establishes the requirements a practitioner follows when reporting on subject matter or an assertion of another party, including the CPA firm's responsibilities for planning, evidence gathering, and forming an opinion.
Type I and Type II Basis
SSAE 18 supports both a Type I examination (suitability of design of controls at a point in time) and a Type II examination (design and operating effectiveness over a defined review period whose length is set by scoping decisions).
Subservice Organization Considerations
The standard addresses how services performed by subservice organizations are handled, typically through the carve-out or inclusive methods, depending on the scope of the engagement.
Management Assertion Requirement
SSAE 18 engagements generally rely on a written assertion from the responsible party regarding the subject matter being examined, which the practitioner evaluates as part of forming the report opinion.

Common questions

Answers to the questions practitioners most commonly ask about SSAE 18.

Does SSAE 18 produce a certification for my organization?
No. SSAE 18 is an attestation standard, not a certification scheme. An engagement performed under SSAE 18 results in a report issued by a licensed CPA firm expressing the practitioner's opinion. It does not produce a certificate, and describing a SOC 2 outcome as a certification is inaccurate. Certification against a management system, such as ISO/IEC 27001, is a separate concept issued by an accredited certification body.
Is SSAE 18 the same thing as SOC 2?
Not exactly. SSAE 18 is the AICPA attestation standard that governs how the examination is conducted, while SOC 2 refers to the specific type of report produced under that standard using the Trust Services Criteria. SSAE 18 also underpins other engagements, such as SOC 1. In short, SSAE 18 is the professional framework, and SOC 2 is one application of it.
Who is permitted to perform an engagement under SSAE 18?
Engagements under SSAE 18 are performed by a licensed CPA firm. The practitioner examines the service organization's controls and, at the conclusion of the engagement, issues a report containing an opinion. The involvement of a CPA firm is a defining characteristic that distinguishes this attestation model from a certification issued by a certification body.
How does SSAE 18 relate to the difference between a Type I and Type II report?
SSAE 18 provides the standard under which both report types are performed. A Type I report assesses the suitability of the design of controls at a point in time, while a Type II report assesses both the design and operating effectiveness of controls over a defined review period. The length of that period is determined by scoping decisions rather than fixed by the standard.
What does a report issued under SSAE 18 actually cover?
The report attests only to the controls and, for a Type II, the review period that were within scope. It reflects the practitioner's opinion on those controls as described. It does not guarantee freedom from breaches, nor does it extend to controls, systems, or time periods outside the defined scope of the engagement.
Does an SSAE 18 engagement satisfy ISO/IEC 27001 requirements?
Not automatically. SSAE 18 governs an attestation examination, whereas ISO/IEC 27001 involves certification of an information security management system against a management system standard. Mapping between the two is possible but partial, and satisfying one does not by itself satisfy the other. Organizations pursuing both typically plan for the distinct requirements of each.

Common misconceptions

SSAE 18 produces a certification that a company is 'SOC 2 certified.'
SSAE 18 governs an attestation examination performed by a licensed CPA firm that results in a report, not a certificate. There is no SOC 2 certification; referring to a 'certified' outcome is inaccurate. Certification is associated with standards such as ISO/IEC 27001, which is issued by an accredited certification body.
An SSAE 18 report guarantees the organization has not been and will not be breached.
A report attests only to the controls and, for Type II, the period covered by the examination. It does not guarantee freedom from security incidents or breaches, and it says nothing about periods or controls outside the defined scope.
SSAE 18 applies only to SOC 2 examinations.
SSAE 18 is the broader attestation standard that also underpins other examinations such as SOC 1 and SOC 3. SOC 2 is one type of engagement performed under it, distinguished by its use of the Trust Services Criteria.

Best practices

Confirm the engagement is performed by a licensed CPA firm and clarify with the practitioner whether you are pursuing a Type I or Type II report, since each addresses different subject matter.
Define the review period explicitly during scoping for a Type II examination, recognizing that the period length varies and is set by scoping decisions rather than a fixed duration.
Determine early whether subservice organizations will be handled through the carve-out or inclusive method, and document that decision with your CPA firm.
Prepare a clear written management assertion aligned to the subject matter being examined, as the engagement relies on it.
Communicate to stakeholders that the resulting report attests only to the controls and period covered and does not guarantee freedom from breaches or cover areas outside the defined scope.
Avoid describing the outcome as a certification in marketing or vendor documentation; use accurate language such as 'SOC 2 report' to prevent misrepresentation.