Boundaries of the System
The boundaries of the system describe exactly which parts of an organization's services, infrastructure, people, and processes are covered by a SOC 2 examination. Defining these boundaries makes clear what the resulting report does and does not address. Anything outside the stated boundaries is not evaluated by the auditor.
In a SOC 2 examination performed under the AICPA's SSAE 18 standard, the boundaries of the system delineate the components in scope for evaluation against the applicable Trust Services Criteria, typically encompassing the infrastructure, software, people, procedures, and data used to provide the services covered by the engagement. The boundaries are established through scoping decisions and are described in the system description, framing the population of controls the service auditor assesses for suitability of design (Type I) and, where applicable, operating effectiveness over the review period (Type II). Because the report attests only to the controls and period within the defined boundaries, components, services, or subservice organizations excluded from those boundaries are outside the scope of the auditor's opinion; the specific treatment of subservice organizations (for example, inclusive versus carve-out methods) depends on scoping decisions for the particular engagement.
Why it matters
The boundaries of the system determine what a SOC 2 report actually covers, and by extension what it does not. A reader who assumes a report speaks to an organization's entire operating environment may draw unwarranted conclusions if only a single product line or a subset of infrastructure was in scope. Because the auditor's opinion extends only to the controls and the period within the defined boundaries, precisely scoped boundaries are what allow customers, prospects, and their own auditors to interpret the report correctly rather than reading assurance into areas that were never evaluated.
For the service organization, boundary decisions shape both the effort required and the usefulness of the resulting report. Boundaries that are drawn too narrowly may fail to cover the services customers most care about, prompting follow-up questions or bridge requests; boundaries drawn too broadly can expand the population of controls under examination and increase the burden of demonstrating suitability of design and, in a Type II, operating effectiveness over the review period. The treatment of subservice organizations is a common source of confusion here, since whether a dependency is presented under an inclusive or carve-out approach affects what falls inside the auditor's opinion, and that choice depends on scoping decisions for the particular engagement.
It is worth emphasizing what boundaries do not do: a SOC 2 report attests only to the controls and period within the stated scope and does not guarantee that no incidents occurred, nor does it evaluate anything outside those boundaries. Clear boundary definitions protect all parties by preventing the report from being read as broader assurance than it provides.
Who it's relevant to
Inside Boundaries of the System
Common questions
Answers to the questions practitioners most commonly ask about Boundaries of the System.