Service
Policies, controls & evidence
A security program you can repeat and prove
Compliance readiness
Get your controls, evidence, and system description ready for a SOC 2 examination by an independent, licensed CPA firm that you select and engage directly.
2017 Trust Services Criteria (With Revised Points of Focus – 2022)
Criteria issued in 2017; points of focus revised in 2022
As of 2026-09-26 the AICPA has not issued revised criteria. The 2022 revision changed the points of focus, not the criteria. SOC 2 examinations are performed under AICPA attestation standards AT-C 105 and AT-C 205.
SOC 2 is an attestation report on a service organization's controls, issued by a licensed CPA firm after an examination and measured against the AICPA Trust Services Criteria. It isn't a certification.
In a SOC 2 examination, a licensed CPA firm gives an opinion on your description of your system and on whether your controls are suitably designed to meet the applicable criteria, which cover security, availability, processing integrity, confidentiality, and privacy. A Type 2 report adds an opinion on whether those controls operated effectively over a period.
Your management is responsible for the system, its controls, and the description of the system. The CPA firm examines them; it doesn't build them.
A SOC 2 Type 1 report and a Type 2 report start from the same place: the CPA firm's opinion on your system description and on whether your controls are suitably designed to meet your service commitments and system requirements, based on the applicable Trust Services Criteria. A Type 2 report adds an opinion on whether those controls operated effectively, and it includes the service auditor's detailed description of its tests of controls and their results.
A Type 1 report speaks to a single date. A Type 2 report covers a period of time, so its tests show how controls worked in practice, including any exceptions. Which one you need usually depends on what your customers ask for, and the CPA firm you engage agrees the report date or period with you during scoping.
| Question | Type 1 report | Type 2 report |
|---|---|---|
| What the opinion covers | The system description and the suitability of control design | The system description, the suitability of control design, and the operating effectiveness of controls |
| Time frame | As of a specific date | Throughout a period of time |
| Tests of controls in the report | Not included | A detailed description of the service auditor's tests of controls and their results |
| Who issues it | A licensed CPA firm acting as service auditor | A licensed CPA firm acting as service auditor |
Sources: AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
Read the full guide: SOC 2 Type 1 vs Type 2: which report do you need?
The AICPA's 2017 Trust Services Criteria are organized into five categories: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 examination can report on one category or on several together.
Each criterion comes with points of focus that describe its important characteristics. The AICPA says using the criteria doesn't require assessing whether every point of focus is addressed, so they work as guidance rather than a checklist. The points of focus were revised in 2022; the criteria themselves date from 2017.
Every category builds on the common criteria, a shared set numbered CC1 through CC9. For security, the common criteria are the complete set. Availability, processing integrity, confidentiality, and privacy each add their own criteria on top of them: the A, PI, C, and P series. The common criteria cover:
Source: AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
Read the full guide: SOC 2 Trust Services Criteria explained, CC1 to CC9
The AICPA's System and Organization Controls suite includes three reports for service organizations, and they answer different questions. All three come from a CPA firm's examination under AICPA attestation standards.
Sources: AICPA: System and Organization Controls (SOC) suite of services; AICPA & CIMA: SOC 3, SOC for Service Organizations: Trust Services Criteria for General Use Report; AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
A SOC 2 report follows a predictable structure. The AICPA's illustrative report shows the main parts: the service auditor's report, management's assertion, the description of the system, and, in a Type 2 report, the tests of controls and their results.
The system description is management's document, prepared against the AICPA's 2018 description criteria (DC 200). The criteria ask it to cover:
Sources: AICPA & CIMA: Illustrative SOC 2 report with illustrative system description; AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022)
Readiness is the work you do before a CPA firm starts its examination. The same seven steps as the full checklist guide, in the order that saves rework:
Sources: AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); AICPA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
Read the full guide: SOC 2 readiness checklist: how to prepare for your report
Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
SOC 2 readiness — preparation for an examination performed by an independent licensed CPA firm.
Under the AICPA Code of Professional Conduct, a CPA firm impairs its independence if it designs, implements, or maintains the controls it examines, prepares the system description, or decides which recommendations to implement (ET 1.295.030 and 1.295.145). No safeguard fixes that. The Code's relief for attestation engagements (ET 1.297.030) covers only services unrelated to what's examined, and readiness work always relates to it. Keeping readiness work separate from the examination avoids the conflict.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Every engagement begins with a written scope and proposal.
Confirm which services and systems are in scope, which Trust Services Criteria apply, and whether a Type 1 or Type 2 report fits what your customers ask for.
Compare your current controls and evidence with the criteria and points of focus, and rate each gap by risk and effort.
Agree on a prioritized plan. Your team decides on and implements the changes; we advise and review.
Review evidence samples and walk through key controls, so your team knows what a CPA firm is likely to ask for.
Prepare a readiness summary you can share with the CPA firm you select. That firm plans and performs its own examination.
From $10,000
Typical scoped range: $10,000 to $25,000
One-time project
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
No. SOC 2 is an attestation report: a licensed CPA firm examines your system description and controls and expresses an opinion on them. In an April 2026 Journal of Accountancy podcast, an AICPA vice president said that SOC 2 is not a certification. There's also no AICPA-issued or state-recognized individual SOC 2 certification, and no individual credential authorizes anyone to issue a SOC 2 report.
A Type 1 report gives the CPA firm's opinion on your system description and on whether your controls are suitably designed to meet the applicable criteria. A Type 2 report adds an opinion on whether those controls operated effectively over a period. Your customers' requirements usually decide which one you need, and scoping is the time to confirm it.
Only within limits. The AICPA Code lets a CPA firm give an examination client advice and recommendations if management makes every decision and a written understanding is in place before the work starts (ET 1.295.040). A firm that designs, implements, or maintains the controls it examines, or prepares the system description, impairs its independence, and no safeguard fixes that. Using a separate readiness firm keeps that question off the table.
Confirm that the firm and the people who will sign the report are licensed, using the state board of accountancy or NASBA's CPAverify search. CPAverify doesn't include Hawaii or New Mexico, so check those boards directly. You can also look up the firm's peer review enrollment in the AICPA Peer Review Public File, or ask the firm for its latest peer review report.
As of 2026-09-26, the current criteria are the AICPA's 2017 Trust Services Criteria with revised points of focus from 2022, used with the 2018 SOC 2 Description Criteria (revised implementation guidance, 2022). The 2022 revision changed the points of focus, not the criteria. Check the AICPA's criteria page for any later revision before you plan the work.
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.