Description Criteria
Description Criteria are the AICPA-established benchmarks used to prepare and evaluate the written description of a service organization's system that appears in a SOC 2 report. This system description explains the boundaries of the report and covers the people, processes, and technology involved in delivering the services. It provides readers with useful, credible information about how the organization's system is designed and operated.
The Description Criteria are the criteria established by the AICPA (published in the 2018 Description Criteria, with revised implementation guidance) for use in preparing and evaluating the service organization's system description within a SOC 2 examination conducted under SSAE 18. The description sets out the boundaries of the system covered by the report and typically addresses elements such as the types of services provided, the principal service commitments and system requirements, and the components of the system (infrastructure, software, people, procedures, and data). Management is responsible for preparing the description in accordance with these criteria, and the CPA (service auditor) evaluates whether the description is presented in accordance with the Description Criteria as part of the attestation. The Description Criteria are distinct from the Trust Services Criteria, which address the suitability of design and, in a Type II examination, the operating effectiveness of controls; the description covers only the system and period within the defined scope and does not itself guarantee freedom from breaches or events outside that scope.
Why it matters
In a SOC 2 examination, the system description is the narrative foundation on which the entire report rests. Before a reader can meaningfully interpret whether controls were suitably designed or operating effectively, they must understand what system was examined, where its boundaries lie, and which services, commitments, and components are in scope. The Description Criteria exist to make that narrative consistent and credible: they give management a common benchmark for what a complete and accurate description must address, and they give the service auditor (a licensed CPA) a defined basis for evaluating whether the description is fairly presented. Without such criteria, descriptions could vary so widely in completeness and framing that reports would be difficult to compare or rely upon.
The Description Criteria also matter because they shape how boundaries and limitations are communicated. A SOC 2 report attests only to the controls and the period within the defined scope; it does not guarantee that no breach or adverse event occurred, particularly for matters outside the described system or review period. A well-constructed description makes those boundaries explicit, so that customers, vendor-risk teams, and other stakeholders understand precisely what the report does and does not cover. Overstating scope or omitting relevant system components can mislead readers about the assurance they are actually receiving.
For the organizations relying on these reports, the description is frequently the first place a reviewer looks to judge relevance. Depending on scope, an incomplete or misleading system description can undermine confidence in an otherwise favorable report, prompting follow-up questions, additional due diligence, or requests for reissuance. Because management is responsible for preparing the description in accordance with the Description Criteria, the quality of this narrative directly reflects the rigor of the organization's own understanding of its system.
Who it's relevant to
Inside DC
Common questions
Answers to the questions practitioners most commonly ask about DC.