What SSAE 18 is and why buyers ask for it
SSAE 18 — the Statement on Standards for Attestation Engagements No. 18 — is the AICPA attestation standard under which SOC 1 (and SOC 2) examinations are performed. Issued by the American Institute of Certified Public Accountants (AICPA), it replaced the earlier SSAE 16 standard and governs how these examinations of a service organisation’s controls are conducted and reported in the United States.
In practice, when a customer asks a vendor for “an SSAE 18 report,” they are asking for assurance — usually a SOC 1 report — over the controls the vendor operates that touch the customer’s financial data or critical operations. Like the other service-organisation reports in the Cyber Security family, it lets you satisfy many customers and their auditors with one independent examination rather than a stream of individual audits.
What the assessment covers
An SSAE 18 engagement reports on the controls relevant to the service you provide, in two forms:
- Type I — an assessment of the design and implementation of controls at a specific point in time.
- Type II — design and operating effectiveness tested over a period, commonly 6–12 months.
A defining feature of SSAE 18 compared with its predecessor is the emphasis on how a service organisation monitors any sub-service organisations it relies on, and on the complementary controls customers are expected to have in place. The engagement is scoped to the control objectives that matter for your service, with readiness work to close gaps before the formal examination.
How ABS helps
ABS prepares you for the examination and supports you through it:
- Scoping — we help you define the service, the system and the control objectives the report will cover.
- Readiness assessment — we map your current controls against those objectives and identify the gaps, including how you monitor any sub-service organisations.
- Remediation — we help you design and implement the controls and evidence needed to close the gaps.
- Examination support — we support you through the examination, which is performed, and the report issued, by a licensed CPA firm.
Typical timeline
A Type I report is typically achievable in around 10–14 weeks depending on how mature your controls already are; a Type II report adds the observation period over which they are tested. As always, the engagement starts with a fixed-price scoping call and a proposal within 24 hours.
Common questions
What is the difference between SSAE 18 and SOC 1?
SSAE 18 is the standard; SOC 1 is a report produced under it. SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the AICPA attestation standard under which SOC 1 (and SOC 2) examinations are performed and reported in the United States. When someone asks for an ‘SSAE 18 report’, they usually mean a SOC 1 report.
What happened to SSAE 16?
SSAE 18 superseded SSAE 16 in 2017, consolidating and updating the AICPA’s attestation standards. Among other changes it strengthened requirements around the monitoring of sub-service organisations. Reports previously issued under SSAE 16 are now performed under SSAE 18.
What is the difference between a Type I and a Type II report?
A Type I report assesses the design and implementation of controls at a specific point in time. A Type II report assesses design and operating effectiveness over a period — commonly 6–12 months. Most clients expect a Type II report.
How does SSAE 18 relate to ISAE 3402?
SSAE 18 governs SOC 1 reports in the US, while ISAE 3402 is the international equivalent issued by the IAASB. Organisations reporting to overseas clients often choose ISAE 3402; those reporting primarily to US audiences use SOC 1 under SSAE 18.
Who performs an SSAE 18 examination?
A licensed CPA firm performs the examination and issues the report. ABS prepares you for it: scoping, a readiness assessment, including how you monitor any sub-service organisations, remediation, and support through the examination.
How long does an SSAE 18 report stay current?
The report has no formal expiry date, but it covers a specific date (Type I) or period (Type II), so most clients and their auditors expect a new report every 12 months. A bridge letter from management can cover the gap between the end of the reporting period and the next report.
Which criteria does an SSAE 18 examination use?
It depends on the report. A SOC 1 examination is built around control objectives relevant to your clients’ financial reporting, agreed for your specific service; a SOC 2 examination uses the AICPA Trust Services Criteria, in which Security is always required.