United States (AICPA attestation standards; every CPA attestation engagement, including SOC 1, SOC 2 and SOC 3)

SSAE 18

308 controls. 184 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

308 controls 184 frameworks share controls with it United States (AICPA attestation standards; every CPA attestation engagement, including SOC 1, SOC 2 and SOC 3) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

SSAE 18 SOC Reporting Evidence & Implementation Kit

308 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SSAE-01Common Attestation Concepts (AT-C 105)0
SSAE-02Examination Engagements (AT-C 205)0
SSAE-03Review Engagements (AT-C 210)0
SSAE-04Agreed-Upon Procedures (AT-C 215)0
SSAE-05SOC 1 Engagements (AT-C 320)0
SSAE-06SOC 2 Engagements (AT-C 205 with TSC)0
SSAE-07SOC 3 General Use Reports0
SSAE-08Preconditions for Attestation Engagement0
SSAE-09Independence and Ethics1
SSAE-10Engagement Risk Assessment0
SSAE-11Materiality in Attestation0
SSAE-12Written Representations0
SSAE-13Other Information in Reports0
SSAE-14Reporting on Pro Forma Financial Information (AT-C 310)0
SSAE-15Reporting on Compliance (AT-C 315)0
SSAE-16Examinations of Prospective Financial Information (AT-C 305)0
SSAE-17Engagement Documentation0
SSAE-18Quality Management at Firm and Engagement Level0
SSAE-19Modifications to the Standard Report0
SSAE-20Use by Specified Parties and Restricted Distribution0
SSAE18-A1.1A1.1 - Availability Commitments and Requirements30
SSAE18-A1.2A1.2 - Environmental Protections and Recovery36
SSAE18-A1.3A1.3 - Recovery Plan Testing36
SSAE18-C1.1C1.1 - Confidential Information Identification0
SSAE18-C1.2C1.2 - Confidential Information Disposal0
SSAE18-CC1.1CC1.1 - COSO Principle 1: Integrity and Ethical Values0
SSAE18-CC1.2CC1.2 - COSO Principle 2: Board Independence and Oversight0
SSAE18-CC1.3CC1.3 - COSO Principle 3: Management Structure and Authority0
SSAE18-CC1.4CC1.4 - COSO Principle 4: Commitment to Competence0
SSAE18-CC1.5CC1.5 - COSO Principle 5: Accountability0
SSAE18-CC2.1CC2.1 - COSO Principle 13: Quality Information0
SSAE18-CC2.2CC2.2 - COSO Principle 14: Internal Communication0
SSAE18-CC2.3CC2.3 - COSO Principle 15: External Communication0
SSAE18-CC3.1CC3.1 - COSO Principle 6: Risk Identification69
SSAE18-CC3.2CC3.2 - COSO Principle 7: Risk Analysis69
SSAE18-CC3.3CC3.3 - COSO Principle 8: Fraud Risk Assessment0
SSAE18-CC3.4CC3.4 - COSO Principle 9: Change Management25
SSAE18-CC5.1CC5.1 - COSO Principle 10: Control Activity Selection0
SSAE18-CC5.2CC5.2 - COSO Principle 11: Technology General Controls0
SSAE18-CC5.3CC5.3 - COSO Principle 12: Control Activity Policies0
SSAE18-CC6.1CC6.1 - Logical Access Security Software0
SSAE18-CC6.2CC6.2 - New User Registration and Authorization50
SSAE18-CC6.3CC6.3 - Access Removal0
SSAE18-CC6.4CC6.4 - Physical Access Restrictions16
SSAE18-CC6.5CC6.5 - Logical Access to Protected Assets0
SSAE18-CC6.6CC6.6 - External Threats and Security Measures0
SSAE18-CC6.7CC6.7 - Data Transmission Restrictions0
SSAE18-CC6.8CC6.8 - Unauthorized Software Prevention0
SSAE18-CC7.1CC7.1 - Infrastructure and Software Monitoring0
SSAE18-CC7.2CC7.2 - Anomaly Monitoring in Operations0
SSAE18-CC7.3CC7.3 - Security Event Evaluation0
SSAE18-CC7.4CC7.4 - Incident Response132
SSAE18-CC7.5CC7.5 - Incident Recovery71
SSAE18-CC8.1CC8.1 - Infrastructure and Software Change Management25
SSAE18-CC9.1CC9.1 - Risk Mitigation Activities0
SSAE18-CC9.2CC9.2 - Vendor and Business Partner Risk Management50
SSAE18-P1.1P1.1 - Privacy Notice48
SSAE18-P1.2P1.2 - Choice and Consent48
SSAE18-PI1.1PI1.1 - Processing Integrity Definition97
SSAE18-PI1.2PI1.2 - System Processing Completeness and Accuracy0
SSAE18-PI1.3PI1.3 - Processing Error Handling0
SSAE18-SOC1-01Control Environment0
SSAE18-SOC1-02Risk Assessment72
SSAE18-SOC1-03Information and Communication0
SSAE18-SOC1-04Monitoring Activities1
SSAE18-SOC1-05Control Activities for Financial Processing4
SSAE18-SOC1-06Transaction Processing Controls33
105-H01AT-C 105 Conduct of an Attestation Engagement in Accordance With the Attestation Standards (.14 to .24)0
105-H02AT-C 105 Acceptance and Continuance (.25 to .27)0
105-H03AT-C 105 Preconditions for an Attestation Engagement (.28 to .32)0
105-H04AT-C 105 Acceptance of a Change in the Terms of the Engagement (.33 to .34)0
105-H05AT-C 105 Using the Work of Participating Practitioners and Referred-to Practitioners (.35 to .36)0
105-H06AT-C 105 Quality Management: Engagement Resources (.37 to .39)0
105-H07AT-C 105 Quality Management: Leadership Responsibilities for Managing and Achieving Quality (.40 to .48)0
105-H08AT-C 105 Quality Management: Compliance With Relevant Ethical Requirements (.49 to .54)0
105-H09AT-C 105 Quality Management: Monitoring and Remediation, and Overall Responsibility (.55 to .56)0
105-H10AT-C 105 Engagement Documentation (.57 to .64)0
105-H11AT-C 105 Engagement Quality Review (.65)0
105-H12AT-C 105 Professional Skepticism and Professional Judgment (.66 to .68)0
105.14AT-C 105.14 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.15AT-C 105.15 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.16AT-C 105.16 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.17AT-C 105.17 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.18AT-C 105.18 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.19AT-C 105.19 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.20AT-C 105.20 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.21AT-C 105.21 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.22AT-C 105.22 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.23AT-C 105.23 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.24AT-C 105.24 Conduct of an Attestation Engagement in Accordance With the Attestation Standards0
105.25AT-C 105.25 Acceptance and Continuance0
105.26AT-C 105.26 Acceptance and Continuance0
105.27AT-C 105.27 Acceptance and Continuance0
105.28AT-C 105.28 Preconditions for an Attestation Engagement0
105.29AT-C 105.29 Preconditions for an Attestation Engagement0
105.30AT-C 105.30 Preconditions for an Attestation Engagement0
105.31AT-C 105.31 Preconditions for an Attestation Engagement0
105.32AT-C 105.32 Preconditions for an Attestation Engagement0
105.33AT-C 105.33 Acceptance of a Change in the Terms of the Engagement0
105.34AT-C 105.34 Acceptance of a Change in the Terms of the Engagement0
105.35AT-C 105.35 Using the Work of Participating Practitioners and Referred-to Practitioners0
105.36AT-C 105.36 Using the Work of Participating Practitioners and Referred-to Practitioners0
105.37AT-C 105.37 Quality Management: Engagement Resources0
105.38AT-C 105.38 Quality Management: Engagement Resources0
105.39AT-C 105.39 Quality Management: Engagement Resources0
105.40AT-C 105.40 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.41AT-C 105.41 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.42AT-C 105.42 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.43AT-C 105.43 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.44AT-C 105.44 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.45AT-C 105.45 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.46AT-C 105.46 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.47AT-C 105.47 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.48AT-C 105.48 Quality Management: Leadership Responsibilities for Managing and Achieving Quality0
105.49AT-C 105.49 Quality Management: Compliance With Relevant Ethical Requirements0
105.50AT-C 105.50 Quality Management: Compliance With Relevant Ethical Requirements0
105.51AT-C 105.51 Quality Management: Compliance With Relevant Ethical Requirements0
105.52AT-C 105.52 Quality Management: Compliance With Relevant Ethical Requirements0
105.53AT-C 105.53 Quality Management: Compliance With Relevant Ethical Requirements0
105.54AT-C 105.54 Quality Management: Compliance With Relevant Ethical Requirements0
105.55AT-C 105.55 Quality Management: Monitoring and Remediation, and Overall Responsibility0
105.56AT-C 105.56 Quality Management: Monitoring and Remediation, and Overall Responsibility0
105.57AT-C 105.57 Engagement Documentation0
105.58AT-C 105.58 Engagement Documentation0
105.59AT-C 105.59 Engagement Documentation0
105.60AT-C 105.60 Engagement Documentation0
105.61AT-C 105.61 Engagement Documentation0
105.62AT-C 105.62 Engagement Documentation0
105.63AT-C 105.63 Engagement Documentation0
105.64AT-C 105.64 Engagement Documentation0
105.65AT-C 105.65 Engagement Quality Review0
105.66AT-C 105.66 Professional Skepticism and Professional Judgment0
105.67AT-C 105.67 Professional Skepticism and Professional Judgment0
105.68AT-C 105.68 Professional Skepticism and Professional Judgment0
205-H01AT-C 205 Conduct of an Examination Engagement (.05)0
205-H02AT-C 205 Preconditions for an Examination Engagement (.06)0
205-H03AT-C 205 Agreeing on the Terms of the Engagement (.07 to .09)0
205-H04AT-C 205 Requesting a Written Assertion (.10)0
205-H05AT-C 205 Planning and Performing the Engagement (.11 to .13)0
205-H06AT-C 205 Risk Assessment Procedures (.14 to .16)0
205-H07AT-C 205 Materiality in Planning and Performing the Engagement (.17 to .18)0
205-H08AT-C 205 Identifying Risks of Material Misstatement (.19)0
205-H09AT-C 205 Responding to Assessed Risks and Obtaining Evidence (.20 to .21)0
205-H10AT-C 205 Further Procedures (.22 to .32)0
205-H11AT-C 205 Fraud, Laws, and Regulations (.33 to .34)0
205-H12AT-C 205 Revision of Risk Assessment (.35)0
205-H13AT-C 205 Evaluating the Reliability of Information Produced by the Entity (.36)0
205-H14AT-C 205 Using the Work of a Practitioner's Specialist (.37 to .39)0
205-H15AT-C 205 Using the Work of Internal Auditors (.40 to .45)0
205-H16AT-C 205 Evaluating the Results of Procedures (.46 to .48)0
205-H17AT-C 205 Considering Subsequent Events and Subsequently Discovered Facts (.49 to .50)0
205-H18AT-C 205 Written Representations (.51 to .55)0
205-H19AT-C 205 Requested Written Representations Not Provided or Not Reliable (.56 to .57)0
205-H20AT-C 205 Other Information (.58)0
205-H21AT-C 205 Description of Criteria (.59)0
205-H22AT-C 205 Forming the Opinion (.60 to .61)0
205-H23AT-C 205 Preparing the Practitioner's Report (.62 to .68)0
205-H24AT-C 205 Reference to the Practitioner's Specialist (.69)0
205-H25AT-C 205 Modified Opinions (.70 to .83)0
205-H26AT-C 205 Responsible Party Refuses to Provide a Written Assertion (.84 to .86)0
205-H27AT-C 205 Communication Responsibilities (.87 to .88)0
205-H28AT-C 205 Documentation (.89 to .90)0
205.05AT-C 205.05 Conduct of an Examination Engagement0
205.06AT-C 205.06 Preconditions for an Examination Engagement0
205.07AT-C 205.07 Agreeing on the Terms of the Engagement0
205.08AT-C 205.08 Agreeing on the Terms of the Engagement0
205.09AT-C 205.09 Agreeing on the Terms of the Engagement0
205.10AT-C 205.10 Requesting a Written Assertion0
205.11AT-C 205.11 Planning and Performing the Engagement0
205.12AT-C 205.12 Planning and Performing the Engagement0
205.13AT-C 205.13 Planning and Performing the Engagement0
205.14AT-C 205.14 Risk Assessment Procedures0
205.15AT-C 205.15 Risk Assessment Procedures0
205.16AT-C 205.16 Risk Assessment Procedures0
205.17AT-C 205.17 Materiality in Planning and Performing the Engagement0
205.18AT-C 205.18 Materiality in Planning and Performing the Engagement0
205.19AT-C 205.19 Identifying Risks of Material Misstatement0
205.20AT-C 205.20 Responding to Assessed Risks and Obtaining Evidence0
205.21AT-C 205.21 Responding to Assessed Risks and Obtaining Evidence0
205.22AT-C 205.22 Further Procedures0
205.23AT-C 205.23 Further Procedures0
205.24AT-C 205.24 Further Procedures0
205.25AT-C 205.25 Further Procedures0
205.26AT-C 205.26 Further Procedures0
205.27AT-C 205.27 Further Procedures0
205.28AT-C 205.28 Further Procedures0
205.29AT-C 205.29 Further Procedures0
205.30AT-C 205.30 Further Procedures0
205.31AT-C 205.31 Further Procedures0
205.32AT-C 205.32 Further Procedures0
205.33AT-C 205.33 Fraud, Laws, and Regulations0
205.34AT-C 205.34 Fraud, Laws, and Regulations0
205.35AT-C 205.35 Revision of Risk Assessment0
205.36AT-C 205.36 Evaluating the Reliability of Information Produced by the Entity0
205.37AT-C 205.37 Using the Work of a Practitioner's Specialist0
205.38AT-C 205.38 Using the Work of a Practitioner's Specialist0
205.39AT-C 205.39 Using the Work of a Practitioner's Specialist0
205.40AT-C 205.40 Using the Work of Internal Auditors0
205.41AT-C 205.41 Using the Work of Internal Auditors0
205.42AT-C 205.42 Using the Work of Internal Auditors0
205.43AT-C 205.43 Using the Work of Internal Auditors0
205.44AT-C 205.44 Using the Work of Internal Auditors0
205.45AT-C 205.45 Using the Work of Internal Auditors0
205.46AT-C 205.46 Evaluating the Results of Procedures0
205.47AT-C 205.47 Evaluating the Results of Procedures0
205.48AT-C 205.48 Evaluating the Results of Procedures0
205.49AT-C 205.49 Considering Subsequent Events and Subsequently Discovered Facts0
205.50AT-C 205.50 Considering Subsequent Events and Subsequently Discovered Facts0
205.51AT-C 205.51 Written Representations0
205.52AT-C 205.52 Written Representations0
205.53AT-C 205.53 Written Representations0
205.54AT-C 205.54 Written Representations0
205.55AT-C 205.55 Written Representations0
205.56AT-C 205.56 Requested Written Representations Not Provided or Not Reliable0
205.57AT-C 205.57 Requested Written Representations Not Provided or Not Reliable0
205.58AT-C 205.58 Other Information0
205.59AT-C 205.59 Description of Criteria0
205.60AT-C 205.60 Forming the Opinion0
205.61AT-C 205.61 Forming the Opinion0
205.62AT-C 205.62 Preparing the Practitioner's Report0
205.63AT-C 205.63 Preparing the Practitioner's Report0
205.64AT-C 205.64 Preparing the Practitioner's Report0
205.65AT-C 205.65 Preparing the Practitioner's Report0
205.66AT-C 205.66 Preparing the Practitioner's Report0
205.67AT-C 205.67 Preparing the Practitioner's Report0
205.68AT-C 205.68 Preparing the Practitioner's Report0
205.69AT-C 205.69 Reference to the Practitioner's Specialist0
205.70AT-C 205.70 Modified Opinions0
205.71AT-C 205.71 Modified Opinions0
205.72AT-C 205.72 Modified Opinions0
205.73AT-C 205.73 Modified Opinions0
205.74AT-C 205.74 Modified Opinions0
205.75AT-C 205.75 Modified Opinions0
205.76AT-C 205.76 Modified Opinions0
205.77AT-C 205.77 Modified Opinions0
205.78AT-C 205.78 Modified Opinions0
205.79AT-C 205.79 Modified Opinions0
205.80AT-C 205.80 Modified Opinions0
205.81AT-C 205.81 Modified Opinions0
205.82AT-C 205.82 Modified Opinions0
205.83AT-C 205.83 Modified Opinions0
205.84AT-C 205.84 Responsible Party Refuses to Provide a Written Assertion0
205.85AT-C 205.85 Responsible Party Refuses to Provide a Written Assertion0
205.86AT-C 205.86 Responsible Party Refuses to Provide a Written Assertion0
205.87AT-C 205.87 Communication Responsibilities0
205.88AT-C 205.88 Communication Responsibilities0
205.89AT-C 205.89 Documentation0
205.90AT-C 205.90 Documentation0
320-H01AT-C 320 Management and Those Charged With Governance (.09)0
320-H02AT-C 320 Preconditions (.10 to .12)0
320-H03AT-C 320 Requesting a Written Assertion (.13)0
320-H04AT-C 320 Assessing the Suitability of the Criteria (.14 to .18)0
320-H05AT-C 320 Materiality (.19)0
320-H06AT-C 320 Obtaining an Understanding of the Service Organization's System and Assessing the Risk of Material Misstatement (.20 to .23)0
320-H07AT-C 320 Responding to Assessed Risks and Further Procedures (.24)0
320-H08AT-C 320 Obtaining Evidence Regarding Management's Description of the Service Organization's System (.25 to .26)0
320-H09AT-C 320 Obtaining Evidence Regarding the Design of Controls (.27)0
320-H10AT-C 320 Obtaining Evidence Regarding the Operating Effectiveness of Controls (.28 to .34)0
320-H11AT-C 320 Subsequent Events (.35)0
320-H12AT-C 320 Written Representations (.36 to .38)0
320-H13AT-C 320 Other Information (.39)0
320-H14AT-C 320 Content of the Service Auditor's Report (.40 to .41)0
320-H15AT-C 320 Modified Opinions (.42 to .44)0
320-H16AT-C 320 Other Communication Responsibilities (.45)0
320.09AT-C 320.09 Management and Those Charged With Governance0
320.10AT-C 320.10 Preconditions0
320.11AT-C 320.11 Preconditions0
320.12AT-C 320.12 Preconditions0
320.13AT-C 320.13 Requesting a Written Assertion0
320.14AT-C 320.14 Assessing the Suitability of the Criteria0
320.15AT-C 320.15 Assessing the Suitability of the Criteria0
320.16AT-C 320.16 Assessing the Suitability of the Criteria0
320.17AT-C 320.17 Assessing the Suitability of the Criteria0
320.18AT-C 320.18 Assessing the Suitability of the Criteria0
320.19AT-C 320.19 Materiality0
320.20AT-C 320.20 Obtaining an Understanding of the Service Organization's System and Assessing the Risk of Material Misstatement0
320.21AT-C 320.21 Obtaining an Understanding of the Service Organization's System and Assessing the Risk of Material Misstatement0
320.22AT-C 320.22 Obtaining an Understanding of the Service Organization's System and Assessing the Risk of Material Misstatement0
320.23AT-C 320.23 Obtaining an Understanding of the Service Organization's System and Assessing the Risk of Material Misstatement0
320.24AT-C 320.24 Responding to Assessed Risks and Further Procedures0
320.25AT-C 320.25 Obtaining Evidence Regarding Management's Description of the Service Organization's System0
320.26AT-C 320.26 Obtaining Evidence Regarding Management's Description of the Service Organization's System0
320.27AT-C 320.27 Obtaining Evidence Regarding the Design of Controls0
320.28AT-C 320.28 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.29AT-C 320.29 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.30AT-C 320.30 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.31AT-C 320.31 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.32AT-C 320.32 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.33AT-C 320.33 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.34AT-C 320.34 Obtaining Evidence Regarding the Operating Effectiveness of Controls0
320.35AT-C 320.35 Subsequent Events0
320.36AT-C 320.36 Written Representations0
320.37AT-C 320.37 Written Representations0
320.38AT-C 320.38 Written Representations0
320.39AT-C 320.39 Other Information0
320.40AT-C 320.40 Content of the Service Auditor's Report0
320.41AT-C 320.41 Content of the Service Auditor's Report0
320.42AT-C 320.42 Modified Opinions0
320.43AT-C 320.43 Modified Opinions0
320.44AT-C 320.44 Modified Opinions0
320.45AT-C 320.45 Other Communication Responsibilities0
AMENDMENTSThe amendments since 2016 and the current numbering of AT-C 105 and 2050
AT-C 105AT-C 105: Concepts Common to All Attestation Engagements0
AT-C 205AT-C 205: Assertion-Based Examination Engagements0
AT-C 320AT-C 320: Reporting on an Examination of Controls at a Service Organization0
OTHER-SECTIONSThe other AT-C sections: 206 direct examination, 210 review, 215 agreed-upon procedures, 305, 310 and 315, and AT section 7010
SOCHow SOC 1, SOC 2 and SOC 3 reports sit on these sections, and the 2026 exposure draft0
STANDARDSSAE No. 18: the clarified and recodified attestation standards, and what is held0

Tell me when SSAE 18 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
  • Confidential information inventory
  • Encryption configuration baselines
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for SSAE 18, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition