What is SOC 1?
SOC 1 is an attestation report on the controls at a service organization that are relevant to its user entities’ internal control over financial reporting. The AICPA calls it a "report on controls at a service organization relevant to user entities’ internal control over financial reporting", which is a mouthful, so everyone says SOC 1. It is performed under the attestation standard SSAE 18, specifically AT-C section 320, by a licensed CPA firm, and the deliverable is a report carrying that firm’s opinion.
The phrase that matters is "user entities". A user entity is a customer that relies on your service in a way that affects its own financial statements: you run their payroll, administer their fund, process their payments, calculate their claims or host the system their ledger depends on. Their auditors have to form a view on controls they cannot see, because those controls live inside your organization. A SOC 1 report is how they get that view without auditing you themselves.
Like every SOC report, SOC 1 is not a certification. Nobody is "SOC 1 certified" and there is no certificate to frame. What you have, after the examination, is a report: a description of your system, the control objectives you set, the controls behind them, the tests the auditor performed and the opinion they reached. That report is the product, and it is what your customers’ auditors actually read.
From SAS 70 to SSAE 18 and ISAE 3402
SOC 1 replaced SAS 70, the older standard many finance teams still name out of habit, when the AICPA reorganized service-organization reporting in 2011. SSAE 16 came first, and SSAE 18 superseded it in 2017, so a current SOC 1 report is an SSAE 18 report. Outside the United States the equivalent is ISAE 3402 from the IAASB, and a service organization with customers on both sides of the Atlantic often has its auditor issue one report that satisfies both standards. If a customer asks for "your SAS 70", a SOC 1 is what they mean.