Primary documents
- AICPA Trust Services Criteria (2017, revised 2022) โ full TSC document.
- SSAE 18 โ current attestation standard.
- AT-C section 105 โ concepts common to all attestation engagements.
- AT-C section 205 โ assertion-based examinations (Type 2).
- AICPA SOC 2 Reporting Guide โ implementation reference for auditors and service organizations.
Operating bodies
- AICPA (American Institute of Certified Public Accountants) โ owner of attestation standards.
- AICPA Auditing Standards Board (ASB) โ develops standards.
- State boards of accountancy โ regulate CPA practice in US states.
Common audit firms
CPA firms with SOC 2 capability:
- Schellman โ large SOC 2 + ISO 27001 + ISO 42001 + HITRUST volume.
- A-LIGN โ similar positioning.
- Coalfire โ security-specialist CPA firm.
- BSI Americas โ UK-headquartered, US operations for SOC 2.
- Deloitte, KPMG, PwC, EY โ Big Four with SOC 2 practices.
- BPM, BPM SOC, Many others โ regional / mid-market.
Adjacent frameworks
- ISO 27001:2022 โ international sibling. Combined audits common.
- HITRUST CSF โ healthcare-broadened US framework.
- PCI DSS โ payment card industry.
- HIPAA Security Rule โ US healthcare.
- FedRAMP โ US federal cloud.
- NIST CSF 2.0 โ voluntary US framework.
Mapping resources
- AICPA TSC mapping to ISO 27001 โ available.
- TSC mapping to HITRUST โ available.
- TSC mapping to PCI DSS โ available.
- Various vendor-published mapping documents.
Reference resources
- aicpa-cima.com โ AICPA-CIMA combined site; SOC resources.
- CPA firm publications โ Schellman, A-LIGN, others publish substantial SOC 2 content.
- Various SaaS GRC platforms (Drata, Vanta, Secureframe, Tugboat Logic, others) โ SOC 2 readiness tooling.