Skip to main content
Category: SOC Reporting

SOC for Cybersecurity

Also known as: Cyber SOC, SOC for Cybersecurity examination, SOC for Cybersecurity report
Simply put

SOC for Cybersecurity is a framework developed by the AICPA that lets a licensed CPA examine and report on how an organization manages its cybersecurity risks. The result is an attestation report, not a certification, that describes the organization's cybersecurity risk management program and the effectiveness of its related controls. It is intended to give stakeholders greater insight and transparency into an organization's overall cybersecurity posture.

Formal definition

SOC for Cybersecurity is an AICPA attestation framework and engagement type in which an independent CPA reports on an entity's cybersecurity risk management program. In the examination, the auditor evaluates and reports on the description of the entity's cybersecurity risk management program and, depending on scope, the effectiveness of the controls within that program. Unlike a SOC 2 examination, which is oriented toward the Trust Services Criteria and typically addresses controls relevant to a specific system serving user entities, SOC for Cybersecurity is generally entity-wide in orientation and structured to communicate cybersecurity risk management to a broader range of stakeholders. As an attestation, it produces a report rather than a certification, and it attests only to the program and controls within the defined scope; it does not guarantee the absence of cybersecurity incidents or breaches.

Why it matters

SOC for Cybersecurity addresses a gap that more system-specific reporting does not always fill: it gives boards, executives, investors, business partners, and other stakeholders an independent, entity-wide view of how an organization manages its cybersecurity risks. Because the examination is performed by a licensed CPA and results in an attestation report, it lends third-party credibility to management's own description of its cybersecurity risk management program. This can be valuable for organizations that want to communicate their overall posture to a broad audience rather than only to the user entities of a particular system.

The framework matters because it standardizes how cybersecurity risk management is described and reported. Rather than relying on ad hoc questionnaires or self-attestations, stakeholders receive a structured report that covers both the organization's program and, depending on scope, the effectiveness of the controls within it. This transparency can support due diligence, vendor risk assessments, and governance discussions where a consistent, independently examined picture of cybersecurity practices is helpful.

It is important to understand what the report does not do. A SOC for Cybersecurity examination attests only to the cybersecurity risk management program and controls within the defined scope; it does not guarantee that an organization is free from cybersecurity incidents or breaches. As with any attestation, its usefulness depends on the scope management defines and the criteria applied, so readers should evaluate the report's boundaries rather than treat it as an assurance of complete security.

Who it's relevant to

Boards and Executive Leadership
Directors and senior executives who are accountable for cybersecurity governance can use a SOC for Cybersecurity report to obtain an independent, entity-wide description of the organization's cybersecurity risk management program. This can support oversight and strategic discussions, though leaders should recognize that the report reflects only the scope management defined and does not guarantee the absence of incidents.
Investors, Partners, and Other External Stakeholders
Parties evaluating an organization's overall cybersecurity posture, rather than the controls of a single system, may find value in the transparency the report provides. Because it is examined by a licensed CPA, it offers third-party credibility, but readers should assess the defined scope before drawing conclusions about the organization's broader security.
GRC and Compliance Teams
Governance, risk, and compliance professionals may use a SOC for Cybersecurity engagement to communicate their cybersecurity risk management program to a wide audience. Teams already familiar with SOC 2 should note the differences in orientation: SOC 2 is typically system-specific and tied to the Trust Services Criteria, whereas SOC for Cybersecurity is generally entity-wide.
CPA Firms and Independent Auditors
Licensed CPA firms perform these examinations, evaluating and reporting on the description of the cybersecurity risk management program and, depending on scope, the effectiveness of its controls. Practitioners should scope engagements carefully, since the resulting attestation speaks only to the program and controls within the defined boundaries.

Inside SOC for Cybersecurity

Cybersecurity Risk Management Program Description
A narrative prepared by management describing the entity's cybersecurity risk management program, including how it identifies, assesses, and responds to cybersecurity risks. This description is a distinct deliverable from the SOC 2 system description and is intended to communicate program-level information to a broad range of users.
Management's Assertion
A statement by management asserting that the description is presented in accordance with the applicable description criteria and that the controls within the program were effective to achieve the entity's cybersecurity objectives, based on the applicable control criteria.
Practitioner's Opinion
An opinion issued by a licensed CPA firm under the AICPA attestation standards, addressing whether the description is presented in accordance with the description criteria and whether the controls were effective. As an attestation engagement, the outcome is a report and an opinion rather than a certification.
Description Criteria
AICPA-published criteria used to prepare and evaluate the program description. These govern the content and structure of the narrative and are separate from the criteria used to evaluate control effectiveness.
Control Criteria
The criteria against which control effectiveness is evaluated. The Trust Services Criteria are commonly used for this purpose, though the framework permits management to select suitable control criteria depending on scope.
Entity-Wide Scope
SOC for Cybersecurity typically addresses an entity's cybersecurity risk management program at an organizational level, distinguishing it from a SOC 2 examination, which is generally scoped to a specific system or service. The precise boundary is set by scoping decisions.
General-Use Report
The report is generally intended for a broad audience, including boards of directors, analysts, investors, and business partners, in contrast to a SOC 2 report, which is typically restricted to specified parties who understand the system and controls.

Common questions

Answers to the questions practitioners most commonly ask about SOC for Cybersecurity.

Is a SOC for Cybersecurity report the same as a SOC 2 report?
No. Although both are attestation examinations performed by a licensed CPA firm under the AICPA's attestation standards, they serve different purposes and audiences. A SOC 2 report addresses controls relevant to the Trust Services Criteria (with Security as the required Common Criteria) and is typically intended for a defined set of stakeholders such as customers and their auditors. A SOC for Cybersecurity report is a general-use report describing an organization's enterprise-wide cybersecurity risk management program and the effectiveness of its controls. The two use different reporting frameworks and should not be treated as interchangeable.
Does a SOC for Cybersecurity report certify that an organization is secure or free from breaches?
No. A SOC for Cybersecurity engagement results in an attestation report, not a certification, and it does not guarantee freedom from security incidents or breaches. The report expresses an opinion on whether the description of the cybersecurity risk management program is presented in accordance with the description criteria and whether the controls were effective, based on the control criteria and the period or point in time covered. It attests only to what is described and examined and does not warrant that no compromise can occur.
Who is the intended audience for a SOC for Cybersecurity report?
It is generally designed as a general-use report, which typically means a broader audience than a SOC 2 report. Depending on scope and the practitioner's engagement, intended readers can include boards of directors, senior management, analysts, investors, and business partners who need insight into an organization's cybersecurity risk management program. Because distribution and use terms depend on how the engagement is scoped, confirm the intended-use language directly with the engaging CPA firm.
How does a SOC for Cybersecurity report relate to frameworks we may already use, such as SOC 2 or ISO 27001?
A SOC for Cybersecurity engagement can draw on an organization's existing control environment, and work performed for other frameworks may inform readiness. However, satisfying one framework does not automatically satisfy another. Mapping between a cybersecurity risk management program and, for example, ISO 27001's ISMS requirements or SOC 2's Trust Services Criteria is possible but partial, and each engagement or certification is evaluated against its own criteria. Treat any overlap as supporting evidence rather than as automatic coverage.
Can the control criteria used in a SOC for Cybersecurity engagement vary?
Yes. In most engagements, management selects suitable control criteria against which the effectiveness of controls is evaluated, and the description is prepared using description criteria. The specific criteria applied can vary depending on scoping decisions and the practitioner's judgment, so organizations should agree on the description criteria and control criteria with the CPA firm before fieldwork begins to avoid misalignment in the final report.
What should we clarify with the CPA firm before starting a SOC for Cybersecurity examination?
Key items to confirm typically include the boundaries of the cybersecurity risk management program being described, whether the examination addresses a point in time or a period, the description and control criteria to be applied, the intended use and distribution of the report, and how the engagement relates to any other attestation or certification work underway. Because these details depend on the engagement, scope, and the practitioner, document them in the engagement agreement rather than assuming a standard approach.

Common misconceptions

SOC for Cybersecurity produces a certification confirming the entity is secure.
It is an attestation examination performed by a licensed CPA firm under the AICPA attestation standards, resulting in a report and an opinion, not a certification. It does not guarantee freedom from breaches; it addresses only the program and controls covered by the engagement over the period or point in time examined.
SOC for Cybersecurity is just another name for SOC 2.
The two are distinct AICPA engagements. SOC 2 is typically scoped to a specific system or service and its reports are generally restricted-use, while SOC for Cybersecurity addresses an entity-wide cybersecurity risk management program and its reports are generally intended for broad, general-use audiences. They use different description criteria even where both may reference the Trust Services Criteria for control evaluation.
Completing a SOC for Cybersecurity examination satisfies ISO 27001 requirements.
The two frameworks are separate. ISO/IEC 27001 is a certification issued by an accredited certification body against a management system standard, whereas SOC for Cybersecurity is an AICPA attestation. Mapping between them may be partial, and satisfying one does not automatically satisfy the other.

Best practices

Engage a licensed CPA firm early to confirm the applicable description criteria and the control criteria (such as the Trust Services Criteria) that will be used, since these are distinct sets of criteria.
Clearly define the scope and boundaries of the cybersecurity risk management program before the engagement, recognizing that program-level scope differs from the system-level scope typical of a SOC 2 examination.
Prepare management's description and assertion carefully to align with the description criteria, as the practitioner's opinion addresses both the description's presentation and the effectiveness of controls.
Communicate to stakeholders that the report attests only to the program and controls covered over the defined period or point in time and does not guarantee freedom from breaches.
If pursuing multiple frameworks, treat any mapping between SOC for Cybersecurity, SOC 2, and ISO 27001 as partial, and confirm requirements for each separately rather than assuming equivalence.
Leverage the general-use nature of the report to communicate with boards, investors, and business partners, while confirming with the practitioner how the report may appropriately be distributed.