SOC 1 - This is a detailed report over financial and audit controls for an organization. It is detailed, and thus sensitive. It might be requested of an organization that processes financial data (such as a payroll company)
SOC 1 Type 1 - This is a SOC 1 report but scoped to a particular date. Because it is a date instance, it is not as telling as a Type 2.
SOC 1 Type 2 - This is a SOC 1 report but scoped to a particular date range. Because it covers a date range instead of an individual date, it is a more thorough and telling report.
SOC 2 - This is a detailed report on organizational controls that cover the areas of security, availability, processing integrity, and confidentiality or privacy. You might provide this to a perspective client to prove your security posture before selling your Cloud Services.
SOC 2 Type 1 - This is a SOC 2 report for a given date instance. It proves compliance at a given time
SOC 2 Type 2 - This is a SOC 2 report for a given date range (minimum 6 months) and thus proves that the organizational controls listed are operational and enforced. (This is a better report than the type 1, and more expensive)
SOC 3 - This is the same as a SOC 2 except that it is is a much more generalized/short/less sensitive document. This is intended to be more of a public facing document.
SOC 1 Type 1 - This is a SOC 1 report but scoped to a particular date. Because it is a date instance, it is not as telling as a Type 2.
SOC 1 Type 2 - This is a SOC 1 report but scoped to a particular date range. Because it covers a date range instead of an individual date, it is a more thorough and telling report.
SOC 2 - This is a detailed report on organizational controls that cover the areas of security, availability, processing integrity, and confidentiality or privacy. You might provide this to a perspective client to prove your security posture before selling your Cloud Services.
SOC 2 Type 1 - This is a SOC 2 report for a given date instance. It proves compliance at a given time
SOC 2 Type 2 - This is a SOC 2 report for a given date range (minimum 6 months) and thus proves that the organizational controls listed are operational and enforced. (This is a better report than the type 1, and more expensive)
SOC 3 - This is the same as a SOC 2 except that it is is a much more generalized/short/less sensitive document. This is intended to be more of a public facing document.