Subject Matter
In an attestation engagement such as SOC 2, the subject matter is the thing that is being measured or evaluated against a set of standards. For SOC 2, this is typically a service organization's system and the controls within it, which are assessed against the applicable Trust Services Criteria. The subject matter defines what the resulting report actually covers and, by extension, what it does not.
Under the AICPA attestation framework (SSAE 18, AT-C), the subject matter is the phenomenon that is measured or evaluated against suitable criteria in an examination, review, or agreed-upon-procedures engagement. In a SOC 2 examination, the subject matter is generally the service organization's system relevant to the selected Trust Services Criteria categories (Security is required; Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope), with the description of the system and the suitability of design of controls addressed in a Type I engagement and, additionally, operating effectiveness over a defined review period in a Type II engagement. The subject matter, together with the applicable criteria and the scope defined during the engagement, delimits what the practitioner opines on; the resulting report attests only to the controls and, for Type II, the period covered, and does not extend to matters outside the defined subject matter. This concept is distinct from the certification model of ISO/IEC 27001, where an accredited certification body certifies conformity of an ISMS against clauses 4 through 10, with reference controls selected via a Statement of Applicability.
Why it matters
Subject matter is the concept that determines the boundaries of a SOC 2 report. Because the subject matter defines what is being measured against the applicable criteria, it also defines what the report does not cover. A reader who understands the subject matter understands the limits of the assurance being provided: a SOC 2 examination attests only to the service organization's system and the controls within the defined scope, assessed against the selected Trust Services Criteria. It does not extend to systems, processes, or time periods that fall outside that defined subject matter.
Misunderstanding subject matter is a common source of misplaced reliance. A SOC 2 report is not a general warranty that an organization is secure or free from breaches; it is a practitioner's opinion on a specific subject matter measured against suitable criteria. Only the Security category (the Common Criteria) is required, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and included based on scope. If a customer needs assurance over availability but the report's subject matter only addressed Security, the report will not answer that question, regardless of how favorable the opinion is.
The concept also clarifies a frequent point of confusion between frameworks. The attestation model built around subject matter and suitable criteria under SSAE 18 is distinct from the ISO/IEC 27001 certification model, in which an accredited certification body certifies conformity of an information security management system against clauses 4 through 10. Because these are structurally different mechanisms, satisfying one does not automatically satisfy the other, and the scope of what each covers must be evaluated on its own terms.
Who it's relevant to
Inside Subject Matter
Common questions
Answers to the questions practitioners most commonly ask about Subject Matter.