SOC 1 ITGC evidence, collected while you sleep.
SOC 1 examinations stand or fall on IT general controls: access, change management, and operations. CISGuard turns continuous CIS benchmark scans into the configuration evidence your service auditor requests.
SOC 1 at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- Attestation standard
- SSAE No. 18 (AICPA AT-C Section 320)
- Focus
- Controls relevant to user entities' ICFR
- Report types
- Type I (design, point in time); Type II (operating effectiveness over a period)
- Typical Type II period
- 6-12 months of operating evidence
- Report audience
- User entities and their financial statement auditors (restricted use)
- CISGuard role
- ITGC configuration evidence; the report itself is issued by your service auditor
What is SOC 1?
SOC 1 is the AICPA attestation report for service organizations whose services are relevant to user entities' internal control over financial reporting (ICFR). Examinations are performed under SSAE No. 18 (AT-C Section 320), and reports are restricted-use documents consumed by user entities and their financial statement auditors. A Type I report evaluates the design of controls at a point in time; a Type II report also tests operating effectiveness over a period, typically 6 to 12 months. Unlike SOC 2, which evaluates the fixed Trust Services Criteria, SOC 1 control objectives are defined by the service organization, but nearly every SOC 1 leans on the same IT general controls (ITGCs): logical access, change management, and computer operations. Those ITGCs are configuration questions at heart, which is exactly what continuous CIS benchmark scanning evidences. SOC 1 and SOC 2 complement each other: many service organizations run both examinations off a shared technical-controls evidence base.
IT general control areas CISGuard evidences.
Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.
- Logical access ITGCs
- Controls
- Organization-defined control objectives for access provisioning, privilege, and authentication
- Mapped by
- CIS Account, Privilege, and Password Policy benchmarks
- Change management ITGCs
- Controls
- Organization-defined control objectives for authorized, tracked configuration change
- Mapped by
- Drift detection + configuration baseline comparison between scans
- Computer operations ITGCs
- Controls
- Organization-defined control objectives for logging, monitoring, and patching
- Mapped by
- CIS Audit Policy + Update benchmarks with continuous scanning
- Data protection ITGCs
- Controls
- Organization-defined control objectives for encryption and secure transmission
- Mapped by
- CIS Cryptography + Network benchmarks
How CISGuard automates SOC 1 evidence.
SOC 1 control objectives differ per service organization, but the service auditor's ITGC testing is remarkably consistent: show that access is restricted, changes are controlled, and operations are monitored, across the entire Type II period. CISGuard provides that evidence automatically. Continuous CIS benchmark scans document the configuration state of every in-scope system, drift detection captures every configuration change between scans (the raw material of change-management testing), and historical posture trends demonstrate that controls operated throughout the period rather than only on the day of fieldwork. Because CISGuard runs on-premises or fully air-gapped, financial services providers and payroll processors can generate this evidence without scan data leaving their environment. CISGuard does not issue SOC 1 reports and is not a service auditor; it supplies the technical configuration evidence your CPA firm tests against your control objectives, replacing the screenshot-and-spreadsheet collection cycle that dominates SOC 1 preparation.
Evidence artifacts CISGuard generates.
Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.
- Per-system CIS benchmark configuration reports covering in-scope ITGC systems
- Drift detection log documenting every configuration change across the Type II period
- Historical posture trends (7/30/90/180/365 days) demonstrating period-long operation
- Per-control pass/fail results with timestamps for logical access and hardening checks
- Exception register with approval workflow for documented deviations
- Framework Coverage Report cross-referencing CIS controls to your defined control objectives
SOC 1 questions, answered directly.
What is the difference between SOC 1 Type I and Type II?
A Type I report evaluates whether controls are suitably designed at a single point in time. A Type II report additionally tests whether those controls operated effectively over a period, typically 6 to 12 months. Most user entities and their auditors request Type II, because ICFR reliance requires evidence of sustained operation. CISGuard's continuous scanning and historical trends supply exactly that period evidence for the technical controls.
Does CISGuard make my organization SOC 1 compliant?
No tool can. A SOC 1 report is an attestation issued by an independent CPA firm after examining your controls under SSAE 18. CISGuard produces the technical configuration evidence, continuous CIS benchmark results, drift history, and access-control state, that your service auditor tests. It replaces manual evidence collection; the opinion itself always comes from the auditor.
How is SOC 1 different from SOC 2?
SOC 1 addresses controls relevant to user entities' internal control over financial reporting, with control objectives defined by the service organization. SOC 2 evaluates the AICPA's fixed Trust Services Criteria for security, availability, and related categories. Many service organizations need both. Because both lean on the same IT general controls, CISGuard's continuous CIS benchmark evidence base serves both examinations at once.
Which IT general controls does CISGuard evidence for SOC 1?
The three ITGC pillars service auditors test: logical access (account, privilege, and password configuration), change management (drift detection between configuration baselines), and computer operations (audit logging, monitoring, and patch state). CISGuard evaluates these through its 22 CIS Benchmarks and 3,928 controls, then reports per-system pass/fail status with timestamps your auditor can sample directly.
Can CISGuard cover the full SOC 1 Type II audit period?
Yes. CISGuard retains historical posture data across the full period, with 7/30/90/180/365-day trend views. Every scheduled scan adds a timestamped evidence point, so a 6 or 12 month Type II window is documented continuously rather than reconstructed at fieldwork time. Drift events between scans give auditors a complete change record for the period.
Continue exploring CISGuard coverage.
SOC 2
SOC 2 Type II requires evidence of controls operating effectively over a period. CISGuard provides that period evidence automatically: 26 Trust Services Criteria mapped, continuous monitoring satisfying the "over time" requirement.
Read more →SOX
CISGuard automates the IT General Controls underlying Sarbanes-Oxley Section 404 ICFR evidence, with continuous configuration, access, and change-management evidence the external auditor walks through.
Read more →GLBA Safeguards Rule
CISGuard automates the technical safeguards required by the Gramm-Leach-Bliley Act Safeguards Rule, with continuous evidence aligned to the December 2021 amendments and the broader FFIEC Cybersecurity Assessment Tool.
Read more →ISO 27001
CISGuard maps 36 ISO/IEC 27001:2022 Annex A controls to CIS benchmark scans, automating the technical evidence that certification audits demand and continuous-monitoring requirements imply.
Read more →Ready for SOC 1 readiness?
Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.