Skip to main content
Category: SOC Reporting

Subject Matter

Also known as: Subject Matter of an Attestation Engagement
Simply put

In an attestation engagement such as SOC 2, the subject matter is the thing that is being measured or evaluated against a set of standards. For SOC 2, this is typically a service organization's system and the controls within it, which are assessed against the applicable Trust Services Criteria. The subject matter defines what the resulting report actually covers and, by extension, what it does not.

Formal definition

Under the AICPA attestation framework (SSAE 18, AT-C), the subject matter is the phenomenon that is measured or evaluated against suitable criteria in an examination, review, or agreed-upon-procedures engagement. In a SOC 2 examination, the subject matter is generally the service organization's system relevant to the selected Trust Services Criteria categories (Security is required; Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope), with the description of the system and the suitability of design of controls addressed in a Type I engagement and, additionally, operating effectiveness over a defined review period in a Type II engagement. The subject matter, together with the applicable criteria and the scope defined during the engagement, delimits what the practitioner opines on; the resulting report attests only to the controls and, for Type II, the period covered, and does not extend to matters outside the defined subject matter. This concept is distinct from the certification model of ISO/IEC 27001, where an accredited certification body certifies conformity of an ISMS against clauses 4 through 10, with reference controls selected via a Statement of Applicability.

Why it matters

Subject matter is the concept that determines the boundaries of a SOC 2 report. Because the subject matter defines what is being measured against the applicable criteria, it also defines what the report does not cover. A reader who understands the subject matter understands the limits of the assurance being provided: a SOC 2 examination attests only to the service organization's system and the controls within the defined scope, assessed against the selected Trust Services Criteria. It does not extend to systems, processes, or time periods that fall outside that defined subject matter.

Misunderstanding subject matter is a common source of misplaced reliance. A SOC 2 report is not a general warranty that an organization is secure or free from breaches; it is a practitioner's opinion on a specific subject matter measured against suitable criteria. Only the Security category (the Common Criteria) is required, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and included based on scope. If a customer needs assurance over availability but the report's subject matter only addressed Security, the report will not answer that question, regardless of how favorable the opinion is.

The concept also clarifies a frequent point of confusion between frameworks. The attestation model built around subject matter and suitable criteria under SSAE 18 is distinct from the ISO/IEC 27001 certification model, in which an accredited certification body certifies conformity of an information security management system against clauses 4 through 10. Because these are structurally different mechanisms, satisfying one does not automatically satisfy the other, and the scope of what each covers must be evaluated on its own terms.

Who it's relevant to

Compliance and GRC managers
Those defining the scope of a SOC 2 engagement rely on the subject matter concept to determine which system boundaries and Trust Services Criteria categories the report will cover. Getting the subject matter right ensures the resulting report answers the questions stakeholders actually need answered.
Auditors and CPA practitioners
Practitioners performing attestation engagements must identify the subject matter and the suitable criteria before forming an opinion, since these together define what the report opines on and what falls outside it. Precise scoping of the subject matter is foundational to a defensible examination.
Customers and vendor risk teams reviewing reports
Readers evaluating a SOC 2 report to assess a vendor should first identify the subject matter and criteria covered, because a favorable opinion applies only within those boundaries. This helps avoid over-reliance and clarifies whether the report addresses the specific concerns, such as availability or confidentiality, relevant to the relationship.
Professionals comparing frameworks
Those weighing SOC 2 against ISO/IEC 27001 benefit from understanding subject matter because it highlights the structural difference between an attestation opinion on a defined subject matter and a certification of ISMS conformity. Recognizing this distinction supports realistic expectations about what each outcome covers and why mapping between them is only partial.

Inside Subject Matter

Subject Matter (attestation context)
In AICPA attestation standards (SSAE 18, AT-C section 105), the subject matter is the phenomenon that is measured or evaluated against suitable criteria in an examination, review, or agreed-upon-procedures engagement. In a SOC 2 examination, the subject matter is typically the service organization's system and the suitability of design (and, in a Type II, operating effectiveness) of controls relevant to the applicable Trust Services Criteria over the period or point in time covered.
Suitable Criteria
The benchmarks against which the subject matter is measured or evaluated. For a SOC 2 engagement, the criteria are the Trust Services Criteria, of which Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional depending on scope. Subject matter has meaning only in relation to the criteria applied to it.
Responsible Party's Assertion
In many attestation engagements, management (the responsible party) provides a written assertion about the subject matter measured against the criteria. In a SOC 2 report, this typically takes the form of management's description of the system and its assertion about controls, which the practitioner then examines.
Scope Boundary of the Subject Matter
The subject matter is bounded by the defined system, the selected Trust Services Criteria, and the reporting period or point in time. It attests only to what is described and covered, and does not extend to systems, criteria, or periods outside the defined scope.
Analogous Concept in ISO/IEC 27001
ISO 27001 does not use the term 'subject matter'; instead, an accredited certification body audits an Information Security Management System (ISMS) against the requirements in clauses 4 through 10, with Annex A reference controls selected via a Statement of Applicability. The comparable notion of 'what is being evaluated' is the defined scope of the ISMS rather than a formally defined 'subject matter'.

Common questions

Answers to the questions practitioners most commonly ask about Subject Matter.

Does 'subject matter' have a specific meaning in AICPA attestation engagements, or is it just a general term?
It has a defined meaning within the AICPA attestation framework. Under the SSAE 18 attestation standards, subject matter refers to the phenomenon that is measured or evaluated against suitable criteria in an examination, review, or agreed-upon-procedures engagement. In a SOC 2 examination, the subject matter is typically the service organization's controls relevant to the selected Trust Services Criteria, evaluated as to design (Type I) or as to design and operating effectiveness over a defined review period (Type II). It is not merely a colloquial descriptor.
Is the subject matter of a SOC 2 examination the same as the scope of an ISO 27001 certification?
No, and treating them as equivalent can cause errors. In a SOC 2 examination the subject matter is the service organization's controls evaluated against the applicable Trust Services Criteria for the categories in scope. An ISO 27001 certificate, by contrast, covers a defined scope of an information security management system assessed against clauses 4 through 10, with Annex A reference controls selected through a Statement of Applicability. Mapping between the two is possible but partial, and defining subject matter for one does not automatically define scope for the other.
Who is responsible for defining the subject matter in a SOC 2 engagement?
In most engagements the service organization (management) is responsible for identifying the subject matter and the criteria against which it is measured, typically through management's description of its system and its assertion. The service auditor, a licensed CPA firm, then examines that subject matter against the suitable criteria. The precise boundaries depend on scoping decisions made during engagement planning.
How does the choice of Trust Services Criteria affect the subject matter?
The selected criteria directly shape the subject matter of the examination. Security, the Common Criteria, is the only required category; Availability, Processing Integrity, Confidentiality, and Privacy are optional and chosen based on scope. Adding a category expands the controls that become part of the subject matter under examination, so the criteria you select determine what the auditor evaluates.
Does the subject matter differ between a SOC 2 Type I and a Type II report?
The controls in scope may be the same, but what is evaluated about them differs. A Type I assesses the suitability of the design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions rather than being fixed. The subject matter for a Type II therefore encompasses evidence of operation across that period.
What are the limitations of how subject matter is defined in a SOC 2 report?
A SOC 2 report attests only to the controls and the period covered by the defined subject matter. It does not extend to controls outside the stated scope, does not guarantee freedom from breaches, and does not speak to periods before or after the review window. Readers should confirm which Trust Services Criteria and which review period the subject matter covers before relying on the report, since these boundaries vary by engagement.

Common misconceptions

'Subject matter' is an informal term with no formal definition in the SOC 2 or AICPA context.
AICPA attestation standards (AT-C section 105 under SSAE 18) explicitly define subject matter as the phenomenon measured or evaluated against suitable criteria in an examination, review, or agreed-upon-procedures engagement. In SOC 2, it is a defined and central concept, not merely a colloquial one.
The subject matter of a SOC 2 examination is the same as the ISO 27001 subject of certification.
The two frameworks describe what is evaluated differently. A SOC 2 subject matter is the system and controls measured against the Trust Services Criteria and produces a report, while ISO 27001 evaluates an ISMS against clauses 4-10 (with Annex A controls selected via a Statement of Applicability) and produces a certificate. Mapping between them is partial, and satisfying one does not automatically satisfy the other.
A SOC 2 opinion on the subject matter guarantees the organization is free from security breaches.
The examination attests only to the controls, criteria, and period (or point in time) within the defined subject matter and scope. It does not guarantee freedom from breaches or address anything outside the boundaries described in the report.

Best practices

Define the subject matter precisely before the engagement, including the system boundary, the selected Trust Services Criteria (Security is required; others are optional based on scope), and the point in time or review period.
Confirm that suitable criteria are agreed with the practitioner, since subject matter has meaning only when measured against defined criteria.
Prepare management's assertion and system description carefully, as the subject matter examined typically flows from what management describes and asserts.
State scope limitations explicitly so readers understand the subject matter attests only to the controls, criteria, and period covered and does not extend beyond them.
When comparing to ISO 27001, treat the ISMS scope as the analogous concept rather than assuming an equivalent 'subject matter', and remember that mapping between the frameworks is only partial.
Revisit the defined subject matter and scope for each reporting cycle, since scoping decisions, not fixed rules, determine what is included and the length of any Type II period.