AICPA SOC for Cybersecurity: Complete Guide

Introduction

Boards, investors, and regulators now treat cybersecurity risk as a first-order business question — and proving your security posture to external stakeholders has become a contractual and regulatory expectation, not just a best practice. A 2025 Gartner survey found that 90% of non-executive directors lacked confidence in their organization's cybersecurity value proposition. Internal claims alone cannot close that gap.

AICPA SOC for Cybersecurity is the framework built specifically for this challenge. It gives any organization — manufacturers, government contractors, non-profits, technology companies — a way to obtain an independent, CPA-attested evaluation of its cybersecurity risk management program. The result is a structured report shareable publicly with customers, investors, and regulators without restriction.

This guide covers what SOC for Cybersecurity is, how it compares to SOC 1 and SOC 2, what auditors evaluate, who needs this report, and how to prepare.


Key Takeaways

  • SOC for Cybersecurity is general-use — any organization can share it publicly; SOC 2 is restricted
  • Auditors evaluate two criteria sets: a nine-element Description Criteria narrative and your chosen Control framework
  • Organizations already pursuing NIST 800-171, CMMC, or ISO 27001 have a meaningful head start
  • SOC 2 and SOC for Cybersecurity serve different audiences and can complement each other
  • Most organizations fall short on Description documentation, not control implementation

What Is AICPA SOC for Cybersecurity?

SOC for Cybersecurity is an attestation standard published by the American Institute of Certified Public Accountants (AICPA) on April 15, 2017. The framework was a direct response to growing marketplace concern about cyberattacks and organizational accountability. "SOC" now stands for System and Organization Controls, a broader definition than the original "Service Organization Controls."

How SOC for Cybersecurity Expanded Beyond Service Organizations

Earlier SOC reporting was built for service organizations — companies whose IT systems processed data on behalf of clients. SOC for Cybersecurity deliberately broke that boundary. Any entity — a manufacturer, non-profit, or defense contractor — can obtain an independent evaluation of its cybersecurity risk management program. The subject of the examination is the organization itself, not a specific customer-facing system.

The examination produces a report in which an independent CPA firm evaluates two things:

  • Whether management's description of its cybersecurity risk management program is complete and accurate
  • Whether controls within that program are effectively designed and operating

That report is general-use, meaning it can be distributed to customers, partners, investors, and regulators without a confidentiality agreement or distribution restriction. In practice, that means an organization can share its cybersecurity assurance with any stakeholder — without negotiating separate disclosure terms for each audience.

No Proprietary Controls Required

SOC for Cybersecurity doesn't impose its own control library. Organizations measure themselves against recognized frameworks they may already be working toward, such as NIST Cybersecurity Framework (CSF) or the AICPA's own Trust Services Criteria.

The AICPA publishes an explicit mapping between the 2017 Trust Services Criteria and NIST CSF, making it practical for organizations to assess existing controls before selecting a framework for the examination.


SOC for Cybersecurity vs. SOC 1 and SOC 2

These three reports are frequently confused — but they cover fundamentally different scopes and serve entirely different audiences.

Attribute SOC 1 SOC 2 SOC for Cybersecurity
Subject Controls relevant to customer financial reporting Controls over a specific service system Enterprise-wide cybersecurity risk management program
Who qualifies Service organizations only Service organizations only Any organization
Criteria used Financial reporting control objectives Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) Description Criteria + suitable control criteria
Report use Restricted to specified users Restricted-use General-use
Primary audience Financial auditors, user entities Clients, regulators (under NDA or access controls) Investors, board, supply chain partners, public

SOC 1 versus SOC 2 versus SOC for Cybersecurity comparison chart infographic

A Common Misconception

SOC 2 and SOC for Cybersecurity are not interchangeable. A company may carry a SOC 2 report covering a specific cloud platform — addressing how that system handles security and availability — while having no independent evaluation of its broader organizational cybersecurity program. Organizations in regulated industries, particularly those managing sensitive customer data or defense contracts, often need both: SOC 2 to satisfy client and procurement requirements for a specific system, and SOC for Cybersecurity to demonstrate enterprise-wide program maturity to boards, investors, and supply chain partners.


The Two Core Criteria Auditors Evaluate

The SOC for Cybersecurity examination is organized around two distinct criteria sets. Understanding both before entering a readiness process is essential — these aren't just formalities, they define the scope of what gets tested.

Description Criteria

Management must produce a narrative description of its cybersecurity risk management program. This is not a list of controls. It's a structured disclosure that auditors verify for completeness and accuracy.

The AICPA requires the description to address nine specific elements:

  1. Nature of the entity's business and operations
  2. Nature of information at risk
  3. Cybersecurity risk management program objectives
  4. Factors that significantly affect inherent cybersecurity risks
  5. Cybersecurity risk governance structure
  6. Cybersecurity risk assessment process
  7. Cybersecurity communications and quality of cybersecurity information
  8. Monitoring of the cybersecurity risk management program
  9. Cybersecurity control processes

Nine AICPA SOC for Cybersecurity Description Criteria elements numbered list infographic

This description is the foundation of the entire report. If it's incomplete or inaccurate, the auditor will note exceptions — and exceptions in the description undermine the credibility of everything that follows. In practice, policies exist and controls exist. What's usually missing is the coherent narrative that connects governance, risk assessment, monitoring, and control processes into a single documented picture — one that holds up when an auditor reads it line by line.

Control Criteria

Organizations select a recognized control framework as the benchmark against which auditors test control effectiveness. There are no SOC for Cybersecurity-specific controls. Common options include:

  • NIST Cybersecurity Framework (CSF) — broadly applicable, voluntary, increasingly referenced in regulatory guidance
  • AICPA Trust Services Criteria — Security, Availability, and Confidentiality categories apply in cybersecurity contexts
  • NIST SP 800-171 — relevant for organizations already handling Controlled Unclassified Information

For defense contractors and DIB companies, that third option matters most. Organizations already pursuing CMMC or NIST 800-171 compliance have controls documented, tested, and — in many cases — assessed by third parties. Those controls don't automatically satisfy SOC for Cybersecurity requirements, but they give gap analysis a defined starting point: existing documentation, prior assessment records, and control language already mapped to NIST.


Who Should Get a SOC for Cybersecurity Report?

SOC for Cybersecurity was intentionally designed for any organization, not just technology companies or service providers. The categories that benefit most include:

  • Healthcare systems, financial institutions, and data processors handling sensitive data at scale
  • Companies responding to enterprise procurement requirements — buyers now routinely ask for documented proof of cybersecurity posture before signing contracts
  • Defense contractors and DIB organizations — pairing this report with CMMC or NIST 800-171 compliance strengthens competitive procurement positions
  • Companies in markets where independently verified attestation is rare — the report becomes a concrete differentiator, not just a compliance checkbox

The Supply Chain Angle

Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled from 15% to 30% year over year. That figure is reshaping how organizations evaluate suppliers. Because SOC for Cybersecurity produces a general-use report, it becomes a practical tool in third-party risk management — organizations can request it from vendors and share it with customers without restriction.

For enterprise buyers and boards, having that report on file is becoming standard due diligence — the kind of documentation procurement teams ask for before a contract moves forward.


Key Benefits of a SOC for Cybersecurity Report

Independent Validation That Carries Weight

Internal claims about security posture carry diminishing credibility with sophisticated buyers and regulators. A CPA-attested report provides something self-assessments cannot: independent verification by a qualified third party operating under professional standards. That distinction matters in competitive procurements, due diligence processes, and regulatory reviews — and it communicates assurance without exposing sensitive internal configurations.

Audit Preparation Forces Internal Discipline

The preparation process itself has organizational value. To produce the Description Criteria narrative and demonstrate control effectiveness, organizations must:

  • Document governance structures that often exist informally
  • Map risk assessment processes to written procedures
  • Collect and retain evidence systematically, not reactively
  • Identify control gaps before an auditor does

Control gaps that surface during examination preparation get fixed before a breach or audit finding forces the issue. The IBM 2024 Cost of a Data Breach Report put the global average breach cost at $4.88 million, with the industrial sector averaging $5.56 million. Finding a gap during prep costs a fraction of what it costs after an incident.

Average data breach cost comparison by sector highlighting industrial and global figures

Regulatory Alignment Evidence

When properly scoped, a SOC for Cybersecurity report can serve as supporting documentation for regulatory compliance efforts. Frameworks with tightening documentation requirements — including HIPAA (under HHS's proposed 2024 Security Rule amendments), the FTC Safeguards Rule, and SEC cybersecurity disclosure obligations — can all draw on a well-scoped examination as supporting evidence. Organizations should work directly with their auditor to ensure relevant regulatory requirements are explicitly addressed in the examination scope.


How to Prepare for a SOC for Cybersecurity Examination

Step 1: Define Scope and Select Your Control Framework

Start by identifying which control criteria best match your existing program and regulatory environment. Organizations already working within CMMC or NIST 800-171 should assess whether those controls align with acceptable SOC for Cybersecurity criteria before selecting a framework — there's no reason to build a parallel control structure if existing controls can be mapped and tested.

Consider:

  • What frameworks is your organization already audited against?
  • What frameworks do your customers or regulators recognize?
  • Does the AICPA's published crosswalk between Trust Services Criteria and NIST CSF offer a useful starting point?

Step 2: Build and Document the Description Criteria

This step is where most organizations underestimate the effort required. All nine description elements must be documented in auditor-ready form before the examination begins. Policies and controls often exist — the documented narrative connecting them to a coherent cybersecurity risk management program frequently does not.

Building this capability internally — rather than reconstructing it before every audit cycle — is where teams create lasting readiness. QMS Learning's Defense Cybersecurity Readiness pathway (covering CMMC, NIST 800-171, ISO 27001, and SOC 2, with a pilot cohort opening Q3 2026) is built for exactly this purpose.

The platform's AI Workbench generates SSP sections, POA&M entries, and compliance artifacts. The Controlled Document Management System captures the revision history and acknowledgment logs that auditors require as objective evidence.

Step 3: Conduct a Pre-Assessment Readiness Review

Documentation is a starting point, not a finish line. Before engaging an auditing firm, run an internal gap analysis to confirm controls are actually operating as described:

  • Test whether controls are operating as described, not just documented on paper
  • Verify that evidence is systematically collected and retained — not assembled reactively before an audit
  • Identify description elements that need strengthening before auditors see them

Auditors will test whether controls actually operated as described over the relevant period. Policies on paper don't satisfy that standard. Evidence of operation — training records, monitoring logs, meeting minutes, system configurations — does.


Frequently Asked Questions

What is the AICPA SOC for Cybersecurity?

SOC for Cybersecurity is an attestation framework created by the AICPA in 2017 that allows any organization — not just service providers — to obtain an independent CPA evaluation of its enterprise-wide cybersecurity risk management program. The result is a general-use report that can be shared with customers, investors, and regulators without restriction.

What is the difference between SOC 1 and SOC 2 AICPA?

SOC 1 focuses on controls over financial reporting and applies to service organizations that affect customer financial statements. SOC 2 evaluates security and operational controls for a specific service system using the Trust Services Criteria — and is restricted-use, shared only with specified users. SOC for Cybersecurity differs from both by covering enterprise-wide cybersecurity risk management for any type of organization.

Is SOC 2 difficult?

SOC 2 preparation is demanding — it requires documented controls, evidence collection, and a period of operating effectiveness before an examination. SOC for Cybersecurity adds the complexity of producing a comprehensive nine-element Description Criteria narrative. Both processes reward organizations that build documentation progressively rather than assembling it under audit pressure.

Who needs a SOC for Cybersecurity report?

Any organization handling sensitive data can benefit, but the report is especially relevant for defense contractors, enterprise technology vendors, financial services companies, and organizations whose customers or regulators require third-party verification of cybersecurity practices. It's also a practical tool for vendor assessment in third-party risk management programs.

How long does a SOC for Cybersecurity examination take?

The examination itself typically runs 8–12 weeks, but most organizations spend 3–6 months on readiness preparation before the formal engagement begins. Gap analysis, documentation, and evidence collection all happen before the auditor steps in — and that groundwork determines how smoothly the examination runs.

Can a SOC for Cybersecurity report satisfy other regulatory requirements?

When properly scoped, it can serve as supporting evidence for regulatory compliance efforts — including HIPAA, FTC Safeguards Rule, and SEC disclosure obligations. It does not automatically satisfy any of these requirements on its own. Organizations should work with their auditor to ensure the relevant regulatory requirements are explicitly addressed within the examination scope.