Skip to main content
Category: SOC Reporting

Description Criteria

Also known as: DC, SOC 2 Description Criteria, Description Criteria for a SOC 2 Report
Simply put

Description Criteria are the AICPA-established benchmarks used to prepare and evaluate the written description of a service organization's system that appears in a SOC 2 report. This system description explains the boundaries of the report and covers the people, processes, and technology involved in delivering the services. It provides readers with useful, credible information about how the organization's system is designed and operated.

Formal definition

The Description Criteria are the criteria established by the AICPA (published in the 2018 Description Criteria, with revised implementation guidance) for use in preparing and evaluating the service organization's system description within a SOC 2 examination conducted under SSAE 18. The description sets out the boundaries of the system covered by the report and typically addresses elements such as the types of services provided, the principal service commitments and system requirements, and the components of the system (infrastructure, software, people, procedures, and data). Management is responsible for preparing the description in accordance with these criteria, and the CPA (service auditor) evaluates whether the description is presented in accordance with the Description Criteria as part of the attestation. The Description Criteria are distinct from the Trust Services Criteria, which address the suitability of design and, in a Type II examination, the operating effectiveness of controls; the description covers only the system and period within the defined scope and does not itself guarantee freedom from breaches or events outside that scope.

Why it matters

In a SOC 2 examination, the system description is the narrative foundation on which the entire report rests. Before a reader can meaningfully interpret whether controls were suitably designed or operating effectively, they must understand what system was examined, where its boundaries lie, and which services, commitments, and components are in scope. The Description Criteria exist to make that narrative consistent and credible: they give management a common benchmark for what a complete and accurate description must address, and they give the service auditor (a licensed CPA) a defined basis for evaluating whether the description is fairly presented. Without such criteria, descriptions could vary so widely in completeness and framing that reports would be difficult to compare or rely upon.

The Description Criteria also matter because they shape how boundaries and limitations are communicated. A SOC 2 report attests only to the controls and the period within the defined scope; it does not guarantee that no breach or adverse event occurred, particularly for matters outside the described system or review period. A well-constructed description makes those boundaries explicit, so that customers, vendor-risk teams, and other stakeholders understand precisely what the report does and does not cover. Overstating scope or omitting relevant system components can mislead readers about the assurance they are actually receiving.

For the organizations relying on these reports, the description is frequently the first place a reviewer looks to judge relevance. Depending on scope, an incomplete or misleading system description can undermine confidence in an otherwise favorable report, prompting follow-up questions, additional due diligence, or requests for reissuance. Because management is responsible for preparing the description in accordance with the Description Criteria, the quality of this narrative directly reflects the rigor of the organization's own understanding of its system.

Who it's relevant to

Compliance and GRC managers
Those responsible for preparing or coordinating a SOC 2 examination use the Description Criteria as the benchmark for drafting the system description, ensuring it accurately captures the services, commitments, system components, and boundaries in scope. Because management owns the description, these professionals must confirm it is complete and fairly presented before the auditor's evaluation.
Service auditors (CPA firms)
The service auditor evaluates whether the system description is presented in accordance with the Description Criteria as part of the attestation. This work is separate from testing controls against the Trust Services Criteria, and both must be addressed for a SOC 2 report to be issued.
Vendor-risk and procurement teams
Readers of a SOC 2 report typically turn first to the system description to determine whether the report is relevant to their needs, understanding what system, services, and boundaries were covered. Recognizing that the description defines scope helps these teams avoid over-relying on a report for matters outside the described system or period.
Security engineers and system owners
Technical staff often supply the underlying detail about infrastructure, software, procedures, and data flows that populates the description. Their input helps ensure the described boundaries and components reflect how the system is actually designed and operated.

Inside DC

Purpose in a SOC 2 engagement
The Description Criteria are the AICPA-established benchmarks used to evaluate whether the service organization's description of its system is presented fairly. They govern the content and presentation of the system description that accompanies the auditor's opinion, and are distinct from the Trust Services Criteria used to evaluate the controls themselves.
System description components
The description typically addresses elements such as the types of services provided, the system boundaries and components (infrastructure, software, people, procedures, and data), the principal service commitments and system requirements, and the controls in place to meet the applicable Trust Services Criteria. The precise components depend on scope and the nature of the services.
Relationship to the auditor's opinion
In a SOC 2 examination, the CPA firm opines both on whether the description is presented in accordance with the Description Criteria and on whether the controls are suitably designed (Type I) and operating effectively (Type II) to meet the applicable Trust Services Criteria over the period covered.
Subservice organizations and complementary controls
The description typically discloses how subservice organizations are handled (using the inclusive or carve-out method) and identifies complementary user entity controls and, where relevant, complementary subservice organization controls that are assumed in the design of the system.

Common questions

Answers to the questions practitioners most commonly ask about DC.

Is the Description Criteria the same thing as the Trust Services Criteria?
No. The Description Criteria and the Trust Services Criteria serve different purposes within a SOC 2 examination. The Description Criteria provide the framework the service organization uses to prepare and present its system description, guiding what information should be included so that the description is fairly presented. The Trust Services Criteria are the control criteria against which the suitability of design (and, in a Type II, the operating effectiveness) of controls is evaluated. In most engagements both are used together, but they address distinct questions: one governs how the system is described, the other governs how the controls are assessed.
Does meeting the Description Criteria mean my controls passed the audit?
Not necessarily. Satisfying the Description Criteria means the system description is presented fairly and completely in accordance with those criteria. It does not, by itself, indicate that the controls were suitably designed or operating effectively. Those conclusions are reached separately by evaluating the controls against the applicable Trust Services Criteria. A description can be fairly presented while the CPA firm still identifies exceptions or deficiencies in the related controls, so the two evaluations should not be conflated.
Who is responsible for preparing the system description that the Description Criteria apply to?
In most SOC 2 engagements, management of the service organization is responsible for preparing the system description and for asserting that it is presented in accordance with the Description Criteria. The CPA firm performing the examination then evaluates that description against those criteria as part of the attestation. Because this is a management responsibility, organizations typically invest effort in drafting the description accurately before the examination fieldwork begins.
What kinds of information does a system description prepared under the Description Criteria typically cover?
Depending on scope, a system description commonly addresses elements such as the types of services provided, the boundaries of the system, the principal service commitments and system requirements, the components of the system (such as infrastructure, software, people, procedures, and data), relevant control activities, and how the system is affected by factors like subservice organizations. The exact content varies by engagement and the criteria selected, and management tailors the description to the system actually covered.
How does the Description Criteria interact with the review period in a Type II examination?
In a Type II examination, the system description is typically prepared to reflect the system as it operated throughout the defined review period, whose length is set by scoping decisions rather than fixed by the criteria. Because a Type II assesses operating effectiveness over that period, the description should fairly represent the system during that timeframe, including any relevant changes. In a Type I, the description generally reflects the system as of a specified point in time consistent with the point-in-time nature of that report.
How should we handle subservice organizations when applying the Description Criteria?
When preparing the system description, service organizations typically disclose how subservice organizations are treated, most commonly using either the inclusive method (where the subservice organization's relevant controls are included in the description and scope) or the carve-out method (where those controls are excluded from the scope but disclosed). The choice depends on scope and engagement decisions. The Description Criteria guide how these arrangements should be presented so that report users understand the boundaries; keep in mind that a SOC 2 report attests only to the controls and system boundaries actually covered.

Common misconceptions

The Description Criteria and the Trust Services Criteria are the same thing.
They are separate sets of criteria. The Description Criteria govern how the system description is presented and whether it is fairly stated, while the Trust Services Criteria (Security as the required Common Criteria, plus optional Availability, Processing Integrity, Confidentiality, and Privacy) are used to evaluate whether the controls meet the selected categories.
Meeting the Description Criteria means the SOC 2 report guarantees the organization is secure and breach-free.
A SOC 2 report attests only to the fairness of the description and to the controls and period covered. It does not guarantee freedom from breaches or cover matters outside the defined scope, criteria, and review period.
The Description Criteria have an equivalent in ISO/IEC 27001.
The Description Criteria are specific to SOC 2 attestation examinations performed under the AICPA framework. ISO/IEC 27001 is a management system certification built on ISMS requirements in clauses 4 through 10 with reference controls in Annex A selected via a Statement of Applicability; it has no direct counterpart to the SOC 2 Description Criteria, and mapping between the frameworks is only partial.

Best practices

Confirm that the system description addresses each required element under the Description Criteria, including system boundaries, principal service commitments, system requirements, and the controls mapped to the applicable Trust Services Criteria.
Clearly define and document the scope of the system before drafting the description, since the components covered depend on scoping decisions and set the boundary of what the resulting report attests to.
Decide early whether subservice organizations will be presented using the inclusive or carve-out method, and describe complementary user entity controls consistently with that choice.
Keep the description consistent with the actual controls and evidence, so the auditor can opine that the description is fairly presented and, in a Type II engagement, that controls operated effectively over the review period.
Engage the CPA firm performing the examination early to align on how the Description Criteria will be applied to your particular services and scope, rather than assuming a single universal format.
Review and update the description for each examination period to reflect changes in services, boundaries, or commitments, since the description reflects only the system and period covered.