SOC 2 anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents

  • AICPA Trust Services Criteria (2017, revised 2022) โ€” full TSC document.
  • SSAE 18 โ€” current attestation standard.
  • AT-C section 105 โ€” concepts common to all attestation engagements.
  • AT-C section 205 โ€” assertion-based examinations (Type 2).
  • AICPA SOC 2 Reporting Guide โ€” implementation reference for auditors and service organizations.

Operating bodies

  • AICPA (American Institute of Certified Public Accountants) โ€” owner of attestation standards.
  • AICPA Auditing Standards Board (ASB) โ€” develops standards.
  • State boards of accountancy โ€” regulate CPA practice in US states.

Common audit firms

CPA firms with SOC 2 capability:

  • Schellman โ€” large SOC 2 + ISO 27001 + ISO 42001 + HITRUST volume.
  • A-LIGN โ€” similar positioning.
  • Coalfire โ€” security-specialist CPA firm.
  • BSI Americas โ€” UK-headquartered, US operations for SOC 2.
  • Deloitte, KPMG, PwC, EY โ€” Big Four with SOC 2 practices.
  • BPM, BPM SOC, Many others โ€” regional / mid-market.

Adjacent frameworks

  • ISO 27001:2022 โ€” international sibling. Combined audits common.
  • HITRUST CSF โ€” healthcare-broadened US framework.
  • PCI DSS โ€” payment card industry.
  • HIPAA Security Rule โ€” US healthcare.
  • FedRAMP โ€” US federal cloud.
  • NIST CSF 2.0 โ€” voluntary US framework.

Mapping resources

  • AICPA TSC mapping to ISO 27001 โ€” available.
  • TSC mapping to HITRUST โ€” available.
  • TSC mapping to PCI DSS โ€” available.
  • Various vendor-published mapping documents.

Reference resources

  • aicpa-cima.com โ€” AICPA-CIMA combined site; SOC resources.
  • CPA firm publications โ€” Schellman, A-LIGN, others publish substantial SOC 2 content.
  • Various SaaS GRC platforms (Drata, Vanta, Secureframe, Tugboat Logic, others) โ€” SOC 2 readiness tooling.

See also