Requesting SSAE-18 SOC Reports
KA-11419
0
07/24/2026 22:16 PM
1.0
Overview
This article explains how to request Statement on Standards for Attestation Engagements No. 18 (SSAE-18), Service Organization Controls 1 (SOC 1), Service Organization Controls 2 (SOC 2), Bridge/Gap Letters, and related compliance reports for Authorize.net.
Use this information when your organization needs formal compliance documentation for:
- Internal audits
- Vendor risk reviews
- Regulatory or compliance requirements
- Customer or partner due diligence
Report Types Available
Authorize.net can provide the following audit and compliance reports, subject to eligibility and verification:
SSAE-18
SSAE-18 refers to the professional attestation standards used by independent auditors to evaluate controls at service organizations. Authorize.net undergoes annual independent validation under SSAE-18 standards.
SOC 1
SOC 1 reports evaluate controls relevant to a customer's financial reporting. These reports are typically requested by finance, audit, or accounting teams.
SOC 2
SOC 2 reports evaluate controls related to trust service categories, including:
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
These reports are commonly requested for vendor risk, security, and compliance reviews.
SAS 70
SAS 70 is a legacy term and is no longer issued. If your organization requests a SAS 70 report, request the current SSAE-18 / SOC report instead.
Bridge or Gap Letter
A Bridge Letter, also called a Gap Letter, helps cover the period between the end date of the most recent SOC report and a later date needed for audit or review purposes.
Authorize.net reports follow the Visa fiscal year:
- Fiscal year begins: October 1
- Fiscal year ends: September 30
Bridge or Gap Letters are commonly requested when auditors need coverage through calendar year-end.
Who Can Request Reports
The following parties may request SSAE-18, SOC 1, SOC 2, and Bridge/Gap Letters:
- Account Owners
- Account Administrators
- Resellers
- Partners
Requestors should generally hold a title of Senior Manager or above and may be subject to verification.
Requesting a Report
To request a report, submit a Support Case and include the following information:
- Providing your full name.
- Providing your job title (Senior Manager or above).
- Providing your company name, including DBA if applicable.
- Providing a physical mailing address (P.O. Boxes are not accepted).
- Providing your email address.
- Providing your telephone number.
- Providing your Payment Gateway ID or Reseller ID.
- Specifying the report type requested, if known (for example: SOC 1, SOC 2, or Bridge Letter).
A digital copy of the report is typically provided through the associated Support Case.
Common Questions
- What reports are available?
- Authorize.net can provide SSAE-18, SOC 1, SOC 2, and Bridge/Gap Letters, subject to eligibility and verification.
- Is SAS 70 still available?
- No. SAS 70 is a legacy term and is no longer issued. Request the current SSAE-18 / SOC report instead.
- How will I receive the report?
- A digital copy is typically provided through the associated Support Case.
- Who can request these reports?
- Account Owners, Account Administrators, Resellers, and Partners may submit requests. Requestors should hold a title of Senior Manager or above.
- Can I use a P.O. Box?
- No. A physical mailing address is required. P.O. Boxes are not accepted.
- How often does Authorize.net undergo validation?
- Authorize.net undergoes annual independent validation under SSAE-18 standards.
- When should I request a Bridge or Gap Letter?
- Request a Bridge or Gap Letter when your auditors need coverage between the end date of the most recent SOC report and a later date, such as calendar year-end. Authorize.net's fiscal year ends September 30, so Bridge/Gap Letters are frequently used to cover the period through December 31.
Glossary
SSAE – Statement on Standards for Attestation Engagements
- SOC – Service Organization Controls
- SOC 1 – Report on controls relevant to customer financial reporting
- SOC 2 – Report on controls related to security, availability, processing integrity, confidentiality, and privacy
- SAS 70 – Legacy audit report terminology replaced by current SOC reporting
- DBA – Doing Business As
- ID – Identifier
- Bridge / Gap Letter – Letter covering the period between the latest report end date and a later review date
Related Resources
Was this article helpful?
