Which best describes the difference between a type 1 and a type 2 SOC report?
A.
A type 2 SOC report validates the operating effectiveness of controls whereas a type 1 SOC report validates the suitability of the design of the controls.
B.
A type 2 SOC report validates the suitability of the design of the controls whereas a type 1 SOC report validates the operating effectiveness of controls.
C.
A type 1 SOC report provides an attestation whereas a type 2 SOC report offers a certification.
D.
There is no difference between a type 2 and type 1 SOC report.
CCAK Pg: 167
Type 1: report on management¡¦s description of the service organization system and the suitability of the
design of the controls to achieve the related control objectives included in the description as of a specified date.
Type 2: report on management¡¦s description of the service organization system and the suitability of the
design and operating effectiveness of the controls to achieve the related control objectives included in the
description throughout a specified period.
CCAK P# 167 There are two types of SOC 1 reports:
• Type 1—A report on management’s description of the service organization system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date.
• Type 2—A report on management’s description of the service organization system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
KarthikeyanTK
Highly Voted 1Â year, 9Â months ago4f2a581
Most Recent 3Â months, 3Â weeks agosai_murthy
9Â months, 1Â week agofoley23
1Â year, 10Â months ago