Statement on Standards for Attestation Engagements 18
· About Statement on Standards for Attestation Engagements 18
Key Takeaways
- SSAE 18 is the AICPA attestation standard behind SOC 1 and SOC 2 reporting, and it remains the operative baseline in 2026 for service-organization control examinations conducted under AT-C section 320.[1][3]
- The standard applies to practitioners’ reports dated on or after 1 May 2017, when SSAE 18 became effective and replaced SSAE 16 for these engagements.[1][11]
- SSAE 18 requires service auditors to assess risk, subservice organizations, management’s assertion, and complementary user entity controls more rigorously than the prior framework.[1]
- There is no government-imposed civil fine schedule in the standard itself; the primary consequences are adverse SOC opinions, qualified reports, loss of customer trust, and contractual or market exclusion when controls cannot be attested to.[1][3]
- A 2025 quality-management amendment applies to engagements beginning on or after 15 December 2025, and proposed 2026 conforming amendments remain proposed rather than final as of August 2026.[3][12][7]
- SOC reports may still be prepared under SSAE 18, but practitioners should track current codified AT-C sections and any later AICPA amendments that affect the engagement model.[3][7]
What It Is
SSAE 18 stands for Statement on Standards for Attestation Engagements No. 18, the AICPA Auditing Standards Board’s clarified attestation framework that recodified U.S. attestation standards and governs service-organization control reports, especially SOC 1 and SOC 2 engagements.[1][3]
The standard is enforced through the AICPA attestation standards rather than by a public regulator with fines. Its practical force comes from CPA firms issuing SOC reports under the standard and from customers, auditors, and contracting parties relying on those reports in vendor assurance programs.[1][3]
The key dates are:
- April 2016: SSAE 18 was issued by the AICPA Auditing Standards Board.[11]
- 1 May 2017: SSAE 18 became effective for practitioners’ reports dated on or after this date.[1][11]
- 15 December 2025: amendments related to quality management became effective for engagements beginning on or after this date.[12]
- August 2026: the AICPA’s current codified listing still treats SSAE 18 and later amendments as the current attestation framework.[3]
Who Must Comply
SSAE 18 is relevant to CPA practitioners and audit firms that perform SOC examinations, and to service organizations whose internal controls are being reported on in a SOC 1 or SOC 2 engagement.[1][3]
It applies when an organization wants a report on controls at a service organization relevant to user entities’ internal control over financial reporting for SOC 1, or on controls relevant to the trust services criteria for SOC 2, including security, availability, processing integrity, confidentiality, and privacy.[1][3]
The standard has no numeric revenue, employee, or geographic threshold. Applicability is engagement-driven: if a CPA performs an attestation engagement under the SOC model, SSAE 18 governs that work unless a later codified amendment changes the applicable sections.[3][7]
There is no express extraterritorial test in SSAE 18 itself. In practice, it can cover non-U.S. service organizations if they obtain a U.S.-style SOC report from a CPA firm working under the AICPA standards, which is common for global outsourcing and cloud providers.[1][3]
No formal statutory exemption regime appears in the standard itself. The main practical exclusions are that the framework is not a general cybersecurity law and does not apply unless a practitioner is issuing an attestation report in scope.[1][3]
Core Requirements
- Obtain and evaluate management’s assertion The service organization must provide a written assertion, and the practitioner evaluates whether the controls described are fairly presented and suitably designed for the stated objective.[1]
- Assess risk and obtain sufficient evidence SSAE 18 strengthened the requirement to understand the service organization, identify risks that controls may not address, and gather evidence sufficient to support the opinion.[1]
- Identify and test subservice organization impacts Practitioners must consider outsourced portions of the system and determine how complementary or carve-out controls at subservice organizations affect the opinion.[1]
- Evaluate complementary user entity controls The report must identify user-entity controls that are necessary for the service organization’s control objectives to be met, because those controls affect the validity of the overall control environment.[1]
- Report clearly on the system, controls, and criteria The SOC report must describe the system, the relevant control objectives or trust services criteria, the testing performed, and any exceptions or limitations in a way that users can rely on.[1][3]
- Apply current quality-management requirements For engagements beginning on or after 15 December 2025, practitioners must align attestation quality-management processes with the newer AICPA amendments that apply to SSAE engagements.[12]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | SSAE 18 issued | April 2016 | AICPA published the clarified and recodified attestation standard.[11] | | SSAE 18 effective for reports | 1 May 2017 | Applies to practitioners’ reports dated on or after this date.[1][11] | | Quality-management amendments effective | 15 December 2025 | Applies to engagements beginning on or after this date.[12] | | Current codified listing reflected | August 2026 | AICPA still lists SSAE 18-based attestation sections as current.[3] |
Maximum fines: SSAE 18 itself does not set government fines or statutory penalty amounts.[1][3]
Other sanctions: The practical consequences are a modified, adverse, or qualified SOC report; inability to satisfy customer due-diligence requirements; breach of contractual commitments to obtain SOC reporting; and potential loss of business or remediation costs if the auditor cannot support the opinion.[1][3]
How to Comply
- Map the in-scope service and system Define exactly which services, platforms, locations, and subservice organizations fall inside the SOC boundary, and document what is excluded.
- Build the control framework around the report type For SOC 1, map controls to financial reporting objectives; for SOC 2, map them to the trust services criteria, especially security, availability, processing integrity, confidentiality, and privacy.[1][3]
- Perform a gap assessment against SSAE 18 expectations Review risk assessment, vendor oversight, evidence retention, management assertion readiness, and complementary user entity controls before fieldwork begins.[1]
- Align control design to recognized frameworks Use ISO 27001 for information-security governance, NIST CSF 2.0 for risk and security outcomes, and ISO 42001 where AI systems are in scope and control objectives need structured AI governance.
- Document subservice-organization dependencies Decide whether to use a carve-out or inclusive approach, obtain upstream assurance where needed, and preserve evidence for third-party controls that support the report.[1]
- Prepare the management assertion early Treat the assertion as a formal deliverable, not a post-audit formality, because the practitioner’s opinion depends on it.[1]
- Test operating effectiveness on a realistic schedule Retain logs, change records, access reviews, incident tickets, and vendor monitoring evidence long enough to support the lookback period of the engagement.
- Monitor AICPA amendments and quality-management updates Check whether later SSAEs or conforming amendments change the applicable AT-C sections for the engagement period, especially for engagements beginning after 15 December 2025.[3][12]
Related Regulations
SOX / ICFR overlaps with SOC 1 because both focus on internal control over financial reporting, but SOC 1 is a service-organization attestation report while SOX obligations attach to public-company reporting and governance.
GDPR can overlap with SOC 2 privacy and confidentiality controls because both touch personal-data handling, but GDPR is a statutory privacy regime with direct legal obligations and penalties.
HIPAA Security Rule overlaps with SOC 2 security criteria for healthcare data environments, but HIPAA imposes entity-specific safeguards and breach obligations beyond attestation reporting.
ISO/IEC 27001 overlaps operationally because it provides an information-security management system model, but it is a certification standard rather than an SSAE attestation regime.
NIST CSF 2.0 overlaps as a control-design framework, but it is voluntary guidance and not a substitute for the attestation evidence required under SSAE 18.
FAQ
Does SSAE 18 apply to companies outside the United States?
Yes, if they engage a CPA firm to issue a SOC 1 or SOC 2 report under the AICPA attestation standards. SSAE 18 is not limited by geography in its practical use, because global cloud, outsourcing, and managed-service providers often obtain SOC reports for international customers.[1][3]
Is SSAE 18 still current in 2026?
Yes. The AICPA’s current codified listing still reflects SSAE 18-based attestation sections as current as of August 2026, alongside later amendments that do not replace the core SOC 1 control-report framework.[3]
What changed from SSAE 16 to SSAE 18?
SSAE 18 added stronger requirements around risk assessment, subservice organizations, and the practitioner’s understanding of the service organization and its control environment.[1] It became effective for reports dated on or after 1 May 2017.[1][11]
Are there legal fines for not having SSAE 18 compliance?
No direct statutory fine is set by SSAE 18 itself. The more common consequence is a weaker or modified SOC report, which can prevent a vendor from meeting procurement or contractual assurance requirements.[1][3]
Does SSAE 18 require SOC 2?
No. SSAE 18 is the attestation standard underlying SOC reports, while SOC 2 is one type of report that uses the trust services criteria for security, availability, processing integrity, confidentiality, and privacy.[1][3]
What should organizations watch for in 2026?
Organizations should watch the AICPA’s codified attestation updates, including the 15 December 2025 quality-management amendments and the status of any proposed conforming amendments issued in 2026.[12][7]
Sources
- AICPA — SSAEs currently effective
- SSAE No. 18 PDF
- Journal of Accountancy — Clarified attestation standards issued
- Journal of Accountancy — Proposed attestation changes: What CPAs should know
- MICPA — Amendment to the attestation standards for consistency with quality management
- TCSA — SSAE 18 (AT-C 320): The Standard Behind SOC 1 Reports
- TCSA — SSAE 18 vs SSAE 21: Which Standard Is Current in 2026?
- Scrut — What is SSAE 18? Requirements, reports, and audit guide
Put it into practice
- Generate the policy: ISO 27001 policy generator (generatepolicy.com)
- Buy the policy pack: ISO 27001 Complete Bundle (cyberpolicy.shop)
- Build it yourself: Pillar 01 Companion — The Living ISMS (ciso.diy)