Section 3: 15–25%I12
Trust Services Criteria and SOC 2 Reporting
Exam insight
The trust services criteria define the subject matter of every SOC 2 and SOC 3 engagement, and the ISC exam expects you to know the five categories, which one is always required, and how the criteria are structured. Understanding the components of a SOC 2 report helps you answer questions about what the report contains and who is responsible for each part.
What AICPA wants you to know
- 1Name and describe the five trust services criteria categories.
- 2Explain why security (the common criteria) is always included in a SOC 2 examination.
- 3Distinguish the common criteria from the category-specific (supplemental) criteria.
- 4Describe the role of points of focus in applying the trust services criteria.
- 5Identify the four key components of a SOC 2 report.
- 6Match a customer concern (uptime, data accuracy, confidentiality, personal data) to the correct trust services category.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
The SOC SelectorMatch scenario to report: SOC 1 for financial reporting, SOC 2 restricted, SOC 3 public, then pick the Type and trust services category.The SOC MechanicsKnow the roles and ownership: the service organization writes the description and assertion, the auditor opines, and CUECs sit with the user.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.