Understanding SOC Reports and Why They Do Not Apply to Sage 300

4 minute read time.

At this time of year, we typically receive several requests for SOC-related certifications relating to Sage 300. To help clarify these requests, it is useful to understand what SOC reports are, when they apply, and why they are generally not applicable to Sage 300.

What Are SOC Reports?

SOC (System and Organization Controls) reports are independent assurance reports developed by the American Institute of Certified Public Accountants (AICPA). They are designed to evaluate controls operated by service organizations and provide assurance to customers, auditors, and stakeholders regarding those controls. [aicpa-cima.com], [aicpa-cima.com]

There are three primary SOC report types:

SOC 1

SOC 1 reports focus on controls that are relevant to a customer's Internal Control over Financial Reporting (ICFR). These reports are primarily used by auditors and finance teams to assess whether a service organization's controls could impact the accuracy of a customer's financial statements. [aicpa-cima.com], [aicpa-cima.com]

SOC 2

SOC 2 reports focus on a service organization's controls relating to one or more of the AICPA Trust Services Criteria:

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

These reports are commonly requested when evaluating cloud-hosted applications and Software-as-a-Service (SaaS) providers. [aicpa-cima.com]

SOC 3

SOC 3 reports cover the same Trust Services Criteria as SOC 2 but provide a high-level summary suitable for public distribution. Unlike SOC 2 reports, SOC 3 reports do not contain detailed control descriptions, testing procedures, or audit results. [aicpa-cima.com]

Type I vs Type II Reports

Both SOC 1 and SOC 2 reports may be issued as either:

  • Type I – Assesses whether controls are suitably designed at a specific point in time.
  • Type II – Assesses both the design and operating effectiveness of controls over a defined review period.

Because Type II reports evaluate how controls operated over time, they generally provide a higher level of assurance than Type I reports. [aicpa-cima.com]

Why SOC Reports Do Not Apply to Sage 300

While SOC reports are frequently associated with software solutions, they are fundamentally designed to assess the controls of a service organization, not the software itself. This distinction is important when considering Sage 300.

Sage 300 is a packaged ERP application that is typically installed and operated within a customer's own environment, whether on physical servers, virtual servers, or infrastructure managed by the customer or their chosen hosting provider. Sage does not operate the customer's Sage 300 environment, manage access to customer data, administer backups, or control the underlying infrastructure.

Because of this deployment model, Sage's published position is that SOC 1, SSAE 16, and SSAE 18 reporting does not apply to Sage 300 and other packaged software products. Sage specifically identifies Sage 300 as a software solution rather than a service organization. [us-kb.sage.com]

Consequently, Sage does not provide a SOC 1 report for Sage 300. A SOC 1 examination is intended for organizations that provide and operate services affecting a customer's financial reporting controls, rather than software publishers that license applications for customers to operate themselves. [aicpa-cima.com], [aicpa-cima.com]

How Sage Intacct Differs

To illustrate the distinction, consider Sage Intacct.

Unlike Sage 300, Sage Intacct is a cloud-based Software-as-a-Service (SaaS) financial management solution hosted and operated by Sage. Because Sage manages the application, infrastructure, security controls, backups, and availability of the service, Sage makes SOC 1 and SOC 2 reports available for Sage Intacct customers. [intacct.com], [sage.com]

This difference highlights the key principle behind SOC reporting: SOC reports are intended to evaluate the controls of the organization providing and operating the service, rather than the software product itself. [aicpa-cima.com], [aicpa-cima.com]

What Auditors Typically Review in a Sage 300 Environment

The appropriate audit evidence depends largely on how Sage 300 is deployed.

Customer-Hosted Environments

Where a customer operates Sage 300 on its own infrastructure, auditors will typically assess the organization's own IT and business controls, such as:

  • User access management
  • Password policies
  • Backup and recovery procedures
  • Change management processes
  • Database security controls
  • Network security measures

The customer is responsible for implementing and maintaining these controls within their environment.

Third-Party Hosted Environments

Where Sage 300 is hosted by a private cloud or third-party hosting provider, customers may need to obtain SOC reports or other compliance documentation directly from the hosting provider. This is because the hosting provider manages the underlying infrastructure, operating systems, security controls, and related operational processes. [aicpa-cima.com], [aicpa-cima.com]

Application-Level Controls

Auditors may also evaluate controls implemented within Sage 300 itself, including:

  • Security groups and user permissions
  • Segregation of Duties
  • Approval workflows
  • Posting Journals and audit trails
  • Operational procedures surrounding transaction processing

These controls can help demonstrate that appropriate governance and oversight exist within the application, even though the application itself is not covered by a SOC report.

Conclusion

SOC reports provide assurance over the controls operated by service organizations. While these reports are common for cloud-hosted and SaaS solutions, they are generally not applicable to traditional on-premises software products such as Sage 300.

Because Sage 300 is packaged software that customers or their hosting providers operate and manage, the responsibility for infrastructure, security, access management, backup procedures, and other operational controls resides with those parties. As a result, auditors will typically focus on the controls implemented by the customer and any third-party hosting provider rather than seeking a SOC report for Sage 300 itself.

By contrast, cloud solutions such as Sage Intacct are operated as managed services by Sage and therefore have SOC reports available to provide assurance over the controls governing the service environment. [intacct.com], [sage.com]