Cyber Security

SSAE 18 — Attestation Standard for Service Organisations

Readiness and support for SOC reports under SSAE 18 — the AICPA attestation standard governing service organisation control reports in the United States.

Book a consultation
SSAE 18 readiness for a service organisation
10-14 weeks Indicative timeline — varies with scope, size, sites and shifts
AICPA Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
SSAE 18AICPAAttestationService Organization

What SSAE 18 is and why buyers ask for it

SSAE 18 — the Statement on Standards for Attestation Engagements No. 18 — is the AICPA attestation standard under which SOC 1 (and SOC 2) examinations are performed. Issued by the American Institute of Certified Public Accountants (AICPA), it replaced the earlier SSAE 16 standard and governs how these examinations of a service organisation’s controls are conducted and reported in the United States.

In practice, when a customer asks a vendor for “an SSAE 18 report,” they are asking for assurance — usually a SOC 1 report — over the controls the vendor operates that touch the customer’s financial data or critical operations. Like the other service-organisation reports in the Cyber Security family, it lets you satisfy many customers and their auditors with one independent examination rather than a stream of individual audits.

What the assessment covers

An SSAE 18 engagement reports on the controls relevant to the service you provide, in two forms:

  • Type I — an assessment of the design and implementation of controls at a specific point in time.
  • Type II — design and operating effectiveness tested over a period, commonly 6–12 months.

A defining feature of SSAE 18 compared with its predecessor is the emphasis on how a service organisation monitors any sub-service organisations it relies on, and on the complementary controls customers are expected to have in place. The engagement is scoped to the control objectives that matter for your service, with readiness work to close gaps before the formal examination.

How ABS helps

ABS prepares you for the examination and supports you through it:

  • Scoping — we help you define the service, the system and the control objectives the report will cover.
  • Readiness assessment — we map your current controls against those objectives and identify the gaps, including how you monitor any sub-service organisations.
  • Remediation — we help you design and implement the controls and evidence needed to close the gaps.
  • Examination support — we support you through the examination, which is performed, and the report issued, by a licensed CPA firm.

Typical timeline

A Type I report is typically achievable in around 10–14 weeks depending on how mature your controls already are; a Type II report adds the observation period over which they are tested. As always, the engagement starts with a fixed-price scoping call and a proposal within 24 hours.

Common questions

What is the difference between SSAE 18 and SOC 1?

SSAE 18 is the standard; SOC 1 is a report produced under it. SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the AICPA attestation standard under which SOC 1 (and SOC 2) examinations are performed and reported in the United States. When someone asks for an ‘SSAE 18 report’, they usually mean a SOC 1 report.

What happened to SSAE 16?

SSAE 18 superseded SSAE 16 in 2017, consolidating and updating the AICPA’s attestation standards. Among other changes it strengthened requirements around the monitoring of sub-service organisations. Reports previously issued under SSAE 16 are now performed under SSAE 18.

What is the difference between a Type I and a Type II report?

A Type I report assesses the design and implementation of controls at a specific point in time. A Type II report assesses design and operating effectiveness over a period — commonly 6–12 months. Most clients expect a Type II report.

How does SSAE 18 relate to ISAE 3402?

SSAE 18 governs SOC 1 reports in the US, while ISAE 3402 is the international equivalent issued by the IAASB. Organisations reporting to overseas clients often choose ISAE 3402; those reporting primarily to US audiences use SOC 1 under SSAE 18.

Who performs an SSAE 18 examination?

A licensed CPA firm performs the examination and issues the report. ABS prepares you for it: scoping, a readiness assessment, including how you monitor any sub-service organisations, remediation, and support through the examination.

How long does an SSAE 18 report stay current?

The report has no formal expiry date, but it covers a specific date (Type I) or period (Type II), so most clients and their auditors expect a new report every 12 months. A bridge letter from management can cover the gap between the end of the reporting period and the next report.

Which criteria does an SSAE 18 examination use?

It depends on the report. A SOC 1 examination is built around control objectives relevant to your clients’ financial reporting, agreed for your specific service; a SOC 2 examination uses the AICPA Trust Services Criteria, in which Security is always required.

More services

Related services

Cyber Security / 01 SOC 2 controls readiness for a cloud service provider

SOC 2 — Type I & Type II Reports

Readiness and support for SOC 2 reports on security, availability and confidentiality controls, for SaaS and cloud providers.

SOC 2Type IType IITrust Services
Get a quote
Cyber Security / 02 Payment card data security assessment under PCI DSS

PCI DSS — Payment Card Security

Readiness, scoping and assessment support for the Payment Card Industry Data Security Standard — for any organisation that stores, processes or transmits cardholder data.

PCI DSSCardholder DataPayments SecurityCyber Security
Get a quote
Cyber Security / 03 SOC 1 readiness for financial reporting controls at a service organisation

SOC 1 — System & Organization Controls (Type I & Type II)

Readiness and support for SOC 1 Type I and Type II reports, for service organisations whose controls affect their clients' financial reporting.

SOC 1AICPAFinancial ControlsService Organization
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us