Skip to main content
← All frameworks
SOC 1 (SSAE 18) ITGC Evidence

SOC 1 ITGC evidence, collected while you sleep.

SOC 1 examinations stand or fall on IT general controls: access, change management, and operations. CISGuard turns continuous CIS benchmark scans into the configuration evidence your service auditor requests.

GlobalService Organizations, Financial Services, Payroll, SaaS
Quick Facts

SOC 1 at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Attestation standard
SSAE No. 18 (AICPA AT-C Section 320)
Focus
Controls relevant to user entities' ICFR
Report types
Type I (design, point in time); Type II (operating effectiveness over a period)
Typical Type II period
6-12 months of operating evidence
Report audience
User entities and their financial statement auditors (restricted use)
CISGuard role
ITGC configuration evidence; the report itself is issued by your service auditor
Overview

What is SOC 1?

SOC 1 is the AICPA attestation report for service organizations whose services are relevant to user entities' internal control over financial reporting (ICFR). Examinations are performed under SSAE No. 18 (AT-C Section 320), and reports are restricted-use documents consumed by user entities and their financial statement auditors. A Type I report evaluates the design of controls at a point in time; a Type II report also tests operating effectiveness over a period, typically 6 to 12 months. Unlike SOC 2, which evaluates the fixed Trust Services Criteria, SOC 1 control objectives are defined by the service organization, but nearly every SOC 1 leans on the same IT general controls (ITGCs): logical access, change management, and computer operations. Those ITGCs are configuration questions at heart, which is exactly what continuous CIS benchmark scanning evidences. SOC 1 and SOC 2 complement each other: many service organizations run both examinations off a shared technical-controls evidence base.

Control Mapping

IT general control areas CISGuard evidences.

Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.

  • Logical access ITGCs
    Controls
    Organization-defined control objectives for access provisioning, privilege, and authentication
    Mapped by
    CIS Account, Privilege, and Password Policy benchmarks
  • Change management ITGCs
    Controls
    Organization-defined control objectives for authorized, tracked configuration change
    Mapped by
    Drift detection + configuration baseline comparison between scans
  • Computer operations ITGCs
    Controls
    Organization-defined control objectives for logging, monitoring, and patching
    Mapped by
    CIS Audit Policy + Update benchmarks with continuous scanning
  • Data protection ITGCs
    Controls
    Organization-defined control objectives for encryption and secure transmission
    Mapped by
    CIS Cryptography + Network benchmarks
How It Works

How CISGuard automates SOC 1 evidence.

SOC 1 control objectives differ per service organization, but the service auditor's ITGC testing is remarkably consistent: show that access is restricted, changes are controlled, and operations are monitored, across the entire Type II period. CISGuard provides that evidence automatically. Continuous CIS benchmark scans document the configuration state of every in-scope system, drift detection captures every configuration change between scans (the raw material of change-management testing), and historical posture trends demonstrate that controls operated throughout the period rather than only on the day of fieldwork. Because CISGuard runs on-premises or fully air-gapped, financial services providers and payroll processors can generate this evidence without scan data leaving their environment. CISGuard does not issue SOC 1 reports and is not a service auditor; it supplies the technical configuration evidence your CPA firm tests against your control objectives, replacing the screenshot-and-spreadsheet collection cycle that dominates SOC 1 preparation.

Auditor Evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.

  • Per-system CIS benchmark configuration reports covering in-scope ITGC systems
  • Drift detection log documenting every configuration change across the Type II period
  • Historical posture trends (7/30/90/180/365 days) demonstrating period-long operation
  • Per-control pass/fail results with timestamps for logical access and hardening checks
  • Exception register with approval workflow for documented deviations
  • Framework Coverage Report cross-referencing CIS controls to your defined control objectives
Frequently Asked

SOC 1 questions, answered directly.

What is the difference between SOC 1 Type I and Type II?

A Type I report evaluates whether controls are suitably designed at a single point in time. A Type II report additionally tests whether those controls operated effectively over a period, typically 6 to 12 months. Most user entities and their auditors request Type II, because ICFR reliance requires evidence of sustained operation. CISGuard's continuous scanning and historical trends supply exactly that period evidence for the technical controls.

Does CISGuard make my organization SOC 1 compliant?

No tool can. A SOC 1 report is an attestation issued by an independent CPA firm after examining your controls under SSAE 18. CISGuard produces the technical configuration evidence, continuous CIS benchmark results, drift history, and access-control state, that your service auditor tests. It replaces manual evidence collection; the opinion itself always comes from the auditor.

How is SOC 1 different from SOC 2?

SOC 1 addresses controls relevant to user entities' internal control over financial reporting, with control objectives defined by the service organization. SOC 2 evaluates the AICPA's fixed Trust Services Criteria for security, availability, and related categories. Many service organizations need both. Because both lean on the same IT general controls, CISGuard's continuous CIS benchmark evidence base serves both examinations at once.

Which IT general controls does CISGuard evidence for SOC 1?

The three ITGC pillars service auditors test: logical access (account, privilege, and password configuration), change management (drift detection between configuration baselines), and computer operations (audit logging, monitoring, and patch state). CISGuard evaluates these through its 22 CIS Benchmarks and 3,928 controls, then reports per-system pass/fail status with timestamps your auditor can sample directly.

Can CISGuard cover the full SOC 1 Type II audit period?

Yes. CISGuard retains historical posture data across the full period, with 7/30/90/180/365-day trend views. Every scheduled scan adds a timestamped evidence point, so a 6 or 12 month Type II window is documented continuously rather than reconstructed at fieldwork time. Drift events between scans give auditors a complete change record for the period.

Ready for SOC 1 readiness?

Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.