Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SSAE 18 — SSAE 18 Explained: The Essential 2026 Guide for Service Organizations

SSAE 18 Explained: The Essential 2026 Guide for Service Organizations

SSAE 18 is the AICPA statement that recodified the US attestation standards in 2016 and, within them, issued AT-C section 320 — the standard a SOC 1 examination is performed under. When a customer asks for “your SSAE 18 report”, they mean a SOC 1 report. This guide explains what the statement is, where it came from, what has been amended since, why nobody is “certified” under it, and what the standard actually requires of a service organisation.

What this guide covers

SSAE 18 explained
SSAE 18 issued AT-C section 320, the standard every SOC 1 examination is performed under.

What SSAE 18 is

Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, was issued by the AICPA’s Auditing Standards Board in April 2016. It rewrote the whole body of attestation standards into clarified form and gave them a new numbering: the AT-C sections. The section that matters to service organisations is AT-C 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting, effective for service auditors’ reports dated on or after 1 May 2017.

Two other AT-C sections apply to every SOC 1 engagement alongside 320: section 105, the concepts common to all attestation engagements, and section 205, assertion-based examination engagements. AT-C 320 repeats some of their requirements in the SOC 1 context and relies on the rest. That structure is why the codified text of AT-C 320 still reads “Source: SSAE No. 18” even after the later amendments described below.

From SAS 70 to SSAE 16 to SSAE 18

The lineage is worth knowing because customers still use the old names.

Standard Status What it did
SAS 70 (1992) Superseded An auditing standard, not an attestation standard, under which service auditors issued “SAS 70 reports”. It had no management assertion.
SSAE 16 (2010) Superseded Moved service organisation reporting into the attestation standards as AT section 801, added the written management assertion, and aligned with ISAE 3402. The AICPA introduced the SOC 1 name at the same time.
SSAE 18 (2016) Current, as amended Recodified everything; AT 801 became AT-C 320. Required the service auditor to obtain management’s acknowledgements before accepting, sharpened the rules on subservice organisations and on information produced by the service organisation.

A vendor that still says “SAS 70” has not updated its language in over a decade; the report it holds, if it holds one, is a SOC 1 report under AT-C 320. Our SOC 1 report guide explains what that document contains.

SSAE 18 has been amended, and is still current

A recurring confusion is whether the statement has been replaced. It has not. Later statements amended the attestation standards, and the AICPA’s codification incorporates them, but AT-C 320 remains the SOC 1 standard and its source line remains SSAE No. 18.

  • SSAE 19 rewrote the agreed-upon procedures standard (AT-C 215), effective for reports dated on or after 15 July 2021. It does not touch SOC 1.
  • SSAE 20 amended the description of the concept of materiality across the attestation standards.
  • SSAE 21, Direct Examination Engagements, issued in September 2020 and effective for reports dated on or after 15 June 2022, added AT-C 206 and made conforming changes to the other sections — which is why the codified AT-C 320 carries “revised June 2022” footnotes.
  • SSAE 22, Review Engagements, issued in December 2020, replaced the review standard (AT-C 210).
  • SSAE 23 aligned the attestation standards with the AICPA’s quality management standards and is effective for engagements beginning on or after 15 December 2025; it changes practitioner terminology and quality responsibilities, not what management of a service organisation must do.

The practical reading: a report issued in 2026 is performed under AT-C 320 as it stands in the current codification, and “SSAE 21” is not a newer version of the SOC 1 standard, whatever a vendor’s marketing says.

Nobody is SSAE 18 certified

It is a standard for the auditor, not a standard the service organisation is measured against. There is no certificate, no registrar and no pass mark. What exists is a service auditor’s opinion on management’s description of its system and on the design and operating effectiveness of the controls in it, for a stated period, against control objectives management itself specified. A supplier that calls itself “SSAE 18 certified” or “compliant” is describing the existence of a report, and the report should be read rather than the claim. Our SOC 1 vs SOC 2 guide makes the same point for the security report.

What SSAE 18 requires of the service organisation

Most of AT-C 320 is written to the service auditor, but a great deal of it lands on management, because the auditor cannot accept the engagement unless management accepts a set of responsibilities and cannot issue the report unless management delivers on them.

  • Six acknowledgements before acceptance: that management is responsible for the description and the assertion, has a reasonable basis for the assertion, selects the criteria and states them, specifies the control objectives and names any outside party that specified them, identifies the risks and designs and documents the controls, and provides the written assertion with the description.
  • A description that meets the criteria: eight required elements, from the services and classes of transactions through to the other components of internal control, plus the changes during the period for a Type 2 report, and no omission or distortion.
  • Control objectives that are reasonable, and controls that would achieve them if operating effectively — the design criterion — and that were consistently applied by competent, authorised people throughout the period — the operating-effectiveness criterion.
  • Written representations at the end, including that management has disclosed any non-compliance or uncorrected misstatements affecting user entities, and any actual, suspected or alleged fraud.
  • Complementary controls and subservice organisations adequately described, with the carve-out or inclusive method stated.

Refusal to provide the written assertion ends the engagement; refusal to sign the representation letter is a scope limitation that precludes an unmodified opinion. Neither is something a report can carry as a footnote.

The statement and ISAE 3402

ISAE 3402 is the IAASB’s international standard for the same engagement, issued in December 2009 and never revised. The two standards are close enough that one examination can be reported under both, and different enough that a description written for one needs care under the other: ISAE 3402 has no term for complementary subservice organisation controls, its list of written representations is longer, and it requires observation and inspection to confirm the system is implemented. The comparison is in our ISAE 3402 guide. Australia’s ASAE 3402 keeps the ISAE paragraph numbering; Canada’s CSAE 3416 is built on CSAE 3000 and is a separate text.

Type 1, Type 2 and the period under AT-C 320

AT-C 320 defines a Type 1 report as speaking to a date and a Type 2 report as speaking to a period, with the auditor’s tests and results included in the Type 2. It does not fix the length of the period; the AICPA’s management guidance suggests a substantial portion of user entities’ financial years. The choice between them, and the first-year constraints that push many organisations to a Type 1 first, are in our SOC 1 Type 2 vs Type 1 guide.

Preparing for an SSAE 18 examination

The work is management’s, and it divides into planning, evaluation and reporting. Decide the scope, type and period; identify subservice organisations and choose a method for each; specify the objectives and test them for reasonableness; write the description to the eight elements; map risks to objectives and controls to risks; keep evidence from the first day of the period and test the controls yourself; capture changes as they happen; then finalise the assertion, review the draft opinion and sign the representations.

The SOC 1 Toolkit is built on that sequence: 87 templates, a description template for every required element, a library of 19 control objectives with their risks and controls, the CUEC and subservice registers, both assertions, the representation-letter checklist and the bridge letter, with every document citing the AT-C 320 and ISAE 3402 paragraphs it answers. For a first engagement, the SOC 1 Toolkit is where the description starts.

Further reading in this series: SOC 1 control objectives, the SOC 1 audit checklist built on the AT-C 320 obligations above, and SOC 1 audit cost.

Frequently asked questions

Is SSAE 18 the same as SOC 1?

It is the statement that issued the standard (AT-C 320); SOC 1 is the AICPA’s name for the report produced under it. In practice the terms are interchangeable, and the reports are the same document.

Has SSAE 18 been replaced by SSAE 21?

No. SSAE 21 added a direct examination standard and made conforming changes to the other sections. AT-C 320, the SOC 1 standard, still cites SSAE No. 18 as its source in the current codification. The AICPA’s list of SSAEs currently effective shows the codified position.

Does SSAE 18 apply outside the United States?

It is a US standard, but service organisations anywhere obtain the report when their customers are US-audited, and many obtain a dual report under both it and ISAE 3402 from one examination.

What is an SSAE 18 Type 2 report?

A SOC 1 Type 2 report: management’s description, management’s assertion and the auditor’s opinion on the description, the design of the controls and their operating effectiveness throughout a stated period, with the tests and results included.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.