The Service and Organization Controls (SOC) 1 report is based on the Auditing Standards Board of the American Institute of Certified Public Accountants (AICPA) SSAE 18, which evaluates the service organization’s internal controls relevant to financial reporting. This report is beneficial for organizations that rely on Google Cloud services to support their financial reporting process.
Looking for Google Cloud and Google Workspace SOC 1 reports? Customers can request the reports at their convenience via Compliance Reports Manager.
Google Cloud regularly undergoes third-party audits for our products, systems, and infrastructure related to this standard. The SOC 1 reports are generated by an objective third party attesting to a set of assertions made by Google Cloud about its controls. The audit firm’s evaluation includes comprehensive testing of the design and operating effectiveness of the controls within the audit period.
Customers may use the SOC 1 report to assess the risks arising from interactions with the assessed Google Cloud and Google Workspace services throughout the period.
The core Google Cloud and Google Workspace SOC 1 Type II reports are issued quarterly and can be downloaded via the Compliance Reports Manager. The coverage periods and issuance dates for these reports are:
We issue separate SOC 1 Type II reports for a small subset of Google Cloud products, including Bare Metal Solution, BigQuery Omni, Google Cloud NetApp Volumes, and Google Cloud VMware Engine. These reports are issued semi-annually or annually and customers can obtain them by contacting sales or support.
Bridge letters are attestations made by the management of the service provider, in this case, Google Cloud, and are intended to “bridge” the gap from the end date of the SOC report to the customer’s period end date. Bridge letters summarize material changes or issues identified within the internal control environment beyond the period end date of the most recent SOC report. Bridge letters are available for SOC 1 and SOC 2 reports.
Google Cloud creates monthly bridge letters with each letter designed to cover the period since the most recent SOC report. For example, Google Cloud issues a bridge letter in early January to cover the look-back period of November 1 to December 31, which extends the coverage period of the previously issued SOC report with a period end date of October 31.
SOC bridge letters for the core Google Cloud and Google Workspace SOC 1 reports are available on Compliance Reports Manager for the periods ending March 31, June 30, September 30, and December 31 and can be downloaded directly. If a bridge letter covering a different period end date or product scope is required, please contact sales or support.
Google Cloud’s independent auditors are Ernst & Young LLP and Coalfire.
A SOC 1 Type I report covers the design of the service organization's controls at a specific point in time. A SOC 1 Type II report covers the design and operating effectiveness of the service organization's controls over a period of time. For example, a SOC 1 Type I may assess the service organization’s controls as of today, but a SOC 1 Type II assesses the service organization’s controls within the past six months. Google Cloud only issues SOC 1 Type II reports.
Below are Google Cloud services that are in scope for SOC 1.
Where we are simplifying the name of our service, we have also included its former name in parentheses.
Artificial Intelligence (AI) and Machine Learning (ML)
Agent Conversation on Gemini Enterprise Agent Platform (Formerly Vertex AI Conversation)
Agent Search on Gemini Enterprise Agent Platform (Formerly Vertex AI Search)
AI Platform Deep Learning Container
Contact Center as a Service (CCaaS)
Conversational Agents (formerly Dialogflow)
CX Insights (formerly Conversational Insights)
Gemini Enterprise (including Agentspace)
Gemini Enterprise Agent Platform Colab Enterprise (Vertex AI Colab Enterprise)
Gemini Enterprise Agent Platform (formerly Vertex AI Platform)
Gemini Enterprise Agent Platform Workbench Instances (formerly Vertex AI Workbench Instances)
Gemini Enterprise for Customer Experience (formerly Conversational AI and Contact Center AI)
Generative AI on Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI)
Ray on Gemini Enterprise Agent Platform (formerly Ray on Vertex)
Application Programming Interface (API) Management
Compute
Data Analytics
Data Studio (formerly Looker Studio)
Google Cloud Managed Service for Apache Kafka
Knowledge Catalog (formerly Dataplex)
Managed Service for Apache Airflow (formerly Cloud Composer)
Managed Service for Apache Spark (formerly Dataproc)
Databases
Developer Tools
Healthcare and Life Sciences
Cloud Healthcare API (formerly Cloud Healthcare)
Hybrid and Multi-cloud
GKE Config Sync (formerly Config Sync)
Management Tools
Media and Gaming
Migration
BigQuery Data Transfer Service
Networking
Cloud Intrusion Detection System (Cloud IDS)
Cloud NAT (Network Address Translation)
Cloud Next Generation Firewall (Cloud NGFW)
Operations
Security and Identity
Cloud External Key Manager (Cloud EKM)
Cloud HSM (Hardware Security Module)
Cloud Key Management Service (KMS)
Cloud Run Functions (formerly Cloud Functions)
Cyber Insurance Hub (formerly RIsk Manager)
Google Security Operations (SIEM)
Google Security Operations (SOAR)
GTI for Google Security Operations
Identity & Access Management (IAM)
Key Access Justifications (KAJ)
Managed Service for Microsoft Active Directory (AD)
Organization Policy Service (formerly Cloud Org Policy)
Resource Manager (formerly Resource Manager API)
Sensitive Data Protection (including Cloud Data Loss Prevention)
Storage
Google Cloud NetApp Volumes (GCNV)
Firebase
Firebase Machine Learning (ML)
Firebase Performance Monitoring
Other
Start building on Google Cloud with $300 in free credits and 20+ always free products.