Dual Reporting

One Audit, Two Reports: SOC 1 for US Buyers, ISAE 3402 for European Buyers

A SOC 1 Type I or Type II report under SSAE 18 from our licensed US CPA firm, with ISAE 3402 dual reporting for your European and international customers, from a single engagement.

Two Sets of Auditors, Two Report Formats

You process payroll, payments, billing, claims or other transactions that end up in your customers' financial statements, so their auditors need independent assurance over your controls. Your US customers and their auditors ask for a SOC 1 report under SSAE 18; your European customers and their auditors ask for ISAE 3402.

US-based auditors typically require a SOC 1, issued under AICPA standards. European and international auditors, who work under International Standards on Auditing (ISAs), prefer ISAE 3402, the IAASB standard for controls at a service organization and the international equivalent of SSAE 18. If you serve both groups, obtaining both reports is often advisable. Dual reporting gets you there with a single engagement that produces both reports at the same time, reducing cost and effort, instead of two audits over the same controls.

What You Receive

As our SOC 1 and ISAE 3402 pages state: a Type I or Type II report issued under SSAE 18 standards by our licensed US CPA firm, with ISAE 3402 dual reporting. The engagement delivers:

  • A SOC 1 report (Type I or Type II) under SSAE 18 from Auditsuisse Assurance NA PC, a licensed US CPA firm enrolled in the AICPA Peer Review program, with our CPA firm's opinion, management letter and recommendations.
  • An ISAE 3402 report (Type I or Type II) from the same engagement, under the IAASB standard, with our practitioner's opinion, management letter and recommendations.
  • Guidance on the management assertion, management statement and system description, so they meet AICPA and ISAE 3402 requirements respectively.
  • Complementary user entity controls (CUECs) documented for your customers' auditors, and subservice organization guidance on the inclusive versus carve-out method.

Auditsuisse is a US CPA firm enrolled in AICPA peer review with Swiss operations (Auditsuisse Assurance AG is a Swiss-registered Expert Auditor headquartered in Zurich), which gives the reports credibility with both US and international stakeholders, whether your customers are in Zurich, London or New York. Book a 30-minute scoping call to confirm which reports your customers' auditors need.

Where SOC 2 Fits

Not every buyer wants a SOC 1. SOC 1 and ISAE 3402 cover controls relevant to your customers' financial reporting. SOC 2 covers security, availability, processing integrity, confidentiality and privacy against the AICPA Trust Services Criteria, and it is what enterprise security and procurement teams ask for. The default rule for B2B SaaS: you need SOC 2 unless your software touches your customers' books, in which case you need SOC 1 as well.

If your US buyers ask for SOC 2, that is a separate report from the same firm: SOC 2 Type I and Type II reports under AICPA attestation standards, accepted by enterprise customers globally, with standard fixed fees on our SOC 2 pricing page. ISAE 3402 is the international equivalent of SOC 1, so dual reporting applies to the SOC 1 engagement. Payroll, payments, billing and fintech platforms often need SOC 1 and SOC 2 together; we scope both in one pass and issue two separate opinions (see when you need SOC 1 and SOC 2 together).

One Engagement

One Fieldwork, Two Reports: What Stays the Same and What Differs

Scoping and Fieldwork

Same for both. One scoping of control objectives, in-scope systems, examination period and report type; one preparation phase; one examination of controls through inquiry, observation, inspection and re-performance.

The Standard

SOC 1: SSAE 18, the AICPA attestation standard, primarily used in the United States.
ISAE 3402: the IAASB standard for controls at a service organization, recognized across Europe, Asia-Pacific and other markets.

Who Reads It

SOC 1: your US customers and their auditors, who typically require it.
ISAE 3402: your European and international customers and their auditors, who work under ISAs and prefer it.

Report Type

Same for both. A Type I reports on the design of controls at a point in time; a Type II on design and operating effectiveness over a period. The choice is made at scoping.

Management's Statement

SOC 1: a management assertion and system description that meet AICPA requirements.
ISAE 3402: a management statement and system description that meet ISAE 3402 requirements.

The Opinion

SOC 1: our CPA firm's opinion under SSAE 18.
ISAE 3402: our practitioner's opinion under ISAE 3402. Two reports, each with a management letter and recommendations, from one engagement.

Price and Timeline

We publish standard fixed fees for SOC 2 but not for SOC 1 or ISAE 3402: those fees depend on the number and complexity of your control objectives, so we quote them after a scoping call. You receive a single fixed fee, confirmed in your engagement letter, so there are no mid-engagement surprises.

On timing, the report type matters more than the standard. A Type I is issued as of a point in time; a Type II covers a period during which your controls must operate, so it always takes longer. SOC 1 timelines are comparable to SOC 2 at equivalent scope: a SOC 2 Type I takes about 4 to 8 weeks of fieldwork and reporting (roughly 3 to 6 months in total including readiness), and a SOC 2 Type II roughly 6 to 15 months in total, including an observation period of 3 to 12 months. See our SOC 2 audit timeline; your dual-reporting timeline is confirmed at scoping.

If you also need SOC 2, our standard fixed fees (Security Trust Services Category) run from $3,000 to $10,000 for a Type I, $5,000 to $15,000 for a Type II and $7,000 to $20,000 for a combined Type I + Type II engagement, by headcount up to 999 employees. These are base prices for standard engagements, confirmed at scoping and in the engagement letter; the full schedule is on the SOC 2 pricing page.

How to Start

Book a 30-minute scoping call. We confirm which of your customers' auditors need SOC 1 and which need ISAE 3402, whether your US buyers also need SOC 2, Type I or Type II and the examination period, the systems and control objectives in scope, and the fee. Every engagement requires individual approval and confirmation of auditor independence before an engagement letter is issued.

The engagement then runs through scoping, preparation, examination and reporting. Fieldwork is on-site or remote, a senior auditor is assigned from day one, and our team works in English, German, French and Italian.

Common Questions

Dual Reporting FAQ

Can one audit produce both a SOC 1 and an ISAE 3402 report?

Yes. Auditsuisse conducts a single audit engagement that produces both reports simultaneously: a SOC 1 Type I or Type II report issued under SSAE 18 by our licensed US CPA firm, and an ISAE 3402 report issued on the same engagement under the IAASB standard. Your controls are examined once and reported in the format each auditor expects.

Which report do US customers need, and which do European customers need?

US-based auditors typically require a SOC 1 report, issued under the AICPA's SSAE 18 attestation standard. European and international auditors, who work under International Standards on Auditing, prefer an ISAE 3402 report. If you serve both groups, dual reporting delivers both without running two audits.

What is the difference between SOC 1 and ISAE 3402?

Both address controls at a service organization that are relevant to its customers' financial reporting, and both come as a Type I or a Type II. The difference is the standard-setter: SOC 1 follows AICPA standards (SSAE 18) and is primarily used in the United States; ISAE 3402, its international equivalent, follows IAASB standards and is recognized across Europe, Asia-Pacific and other markets.

Do we need SOC 2 as well?

Only if your customers' security or procurement teams ask for it. SOC 1 and ISAE 3402 cover controls relevant to financial reporting; SOC 2 covers security, availability, processing integrity, confidentiality and privacy. Most B2B SaaS vendors need SOC 2. It is a separate report from the same firm, with standard fixed fees from $3,000 for a Type I and $5,000 for a Type II.

Who can issue these reports?

Only a licensed CPA firm can issue a SOC 1 report. Auditsuisse Assurance NA PC is a licensed US CPA firm enrolled in the AICPA Peer Review program; Auditsuisse Assurance AG is a Swiss-registered Expert Auditor headquartered in Zurich; the ISAE 3402 report comes from the same firm. Our Director of Audits, Sébastien Ruosch, holds both a Swiss and a US CPA license. Both are attestation reports containing the auditor's opinion, not certificates.

How do we start?

Book a 30-minute scoping call. We confirm which auditors need which report, Type I or Type II and the examination period, the systems and control objectives in scope, and your fixed fee. Every engagement requires individual approval and confirmation of auditor independence before an engagement letter is issued.

Get Started

Confirm Your Dual-Reporting Scope and Fee

A 30-minute scoping call confirms which reports your customers' auditors need, the report type and examination period, and your fixed fee.