web
You’re offline. This is a read only version of the page.
close

What can we help you with?


KA-11419


0

07/24/2026 22:16 PM

1.0

Overview

This article explains how to request Statement on Standards for Attestation Engagements No. 18 (SSAE-18), Service Organization Controls 1 (SOC 1), Service Organization Controls 2 (SOC 2), Bridge/Gap Letters, and related compliance reports for Authorize.net.

Use this information when your organization needs formal compliance documentation for:

  • Internal audits
  • Vendor risk reviews
  • Regulatory or compliance requirements
  • Customer or partner due diligence

Report Types Available

Authorize.net can provide the following audit and compliance reports, subject to eligibility and verification:

SSAE-18

SSAE-18 refers to the professional attestation standards used by independent auditors to evaluate controls at service organizations. Authorize.net undergoes annual independent validation under SSAE-18 standards.

SOC 1

SOC 1 reports evaluate controls relevant to a customer's financial reporting. These reports are typically requested by finance, audit, or accounting teams.

SOC 2

SOC 2 reports evaluate controls related to trust service categories, including:

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

These reports are commonly requested for vendor risk, security, and compliance reviews.

SAS 70

SAS 70 is a legacy term and is no longer issued. If your organization requests a SAS 70 report, request the current SSAE-18 / SOC report instead.

Bridge or Gap Letter

A Bridge Letter, also called a Gap Letter, helps cover the period between the end date of the most recent SOC report and a later date needed for audit or review purposes.

Authorize.net reports follow the Visa fiscal year:

  • Fiscal year begins: October 1
  • Fiscal year ends: September 30

Bridge or Gap Letters are commonly requested when auditors need coverage through calendar year-end.

Who Can Request Reports

The following parties may request SSAE-18, SOC 1, SOC 2, and Bridge/Gap Letters:

  • Account Owners
  • Account Administrators
  • Resellers
  • Partners

Requestors should generally hold a title of Senior Manager or above and may be subject to verification.

Requesting a Report

To request a report, submit a Support Case and include the following information:

  1. Providing your full name.
  2. Providing your job title (Senior Manager or above).
  3. Providing your company name, including DBA if applicable.
  4. Providing a physical mailing address (P.O. Boxes are not accepted).
  5. Providing your email address.
  6. Providing your telephone number.
  7. Providing your Payment Gateway ID or Reseller ID.
  8. Specifying the report type requested, if known (for example: SOC 1, SOC 2, or Bridge Letter).

A digital copy of the report is typically provided through the associated Support Case.

Common Questions

  • What reports are available?
    • Authorize.net can provide SSAE-18, SOC 1, SOC 2, and Bridge/Gap Letters, subject to eligibility and verification.
  • Is SAS 70 still available?
    • No. SAS 70 is a legacy term and is no longer issued. Request the current SSAE-18 / SOC report instead.
  • How will I receive the report?
    • A digital copy is typically provided through the associated Support Case.
  • Who can request these reports?
    • Account Owners, Account Administrators, Resellers, and Partners may submit requests. Requestors should hold a title of Senior Manager or above.
  • Can I use a P.O. Box?
    • No. A physical mailing address is required. P.O. Boxes are not accepted.
  • How often does Authorize.net undergo validation?
    • Authorize.net undergoes annual independent validation under SSAE-18 standards.
  • When should I request a Bridge or Gap Letter?
    • Request a Bridge or Gap Letter when your auditors need coverage between the end date of the most recent SOC report and a later date, such as calendar year-end. Authorize.net's fiscal year ends September 30, so Bridge/Gap Letters are frequently used to cover the period through December 31.

Glossary

  • SSAE – Statement on Standards for Attestation Engagements

  • SOC – Service Organization Controls
  • SOC 1 – Report on controls relevant to customer financial reporting
  • SOC 2 – Report on controls related to security, availability, processing integrity, confidentiality, and privacy
  • SAS 70 – Legacy audit report terminology replaced by current SOC reporting
  • DBA – Doing Business As
  • ID – Identifier
  • Bridge / Gap Letter – Letter covering the period between the latest report end date and a later review date

Related Resources

 



Was this article helpful?


Articles Recommended for You