SOC for Cybersecurity
AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.
AICPA cybersecurity risk management reporting framework · AICPA — SOC for Cybersecurity
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
SOC for Cybersecurity is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
AICPA-controlled — the same posture as SOC 1/SOC 2; obtain the description criteria and applicable trust services criteria before verbatim ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Description criteria · Risk management program · Trust services criteria (security) · Management's assertion
- Applies to
- enterprise risk · financial services · critical infrastructure · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
03Version ledger
| AICPA cybersecurity risk management reporting framework | Current edition | date not published |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- FFIEC IT Examination HandbookCurrent booklets (living collection)
Also applies to financial services · The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.
- ISO 223012019 (Amd 1:2024)
Also applies to critical infrastructure · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.
- APRA CPS 2302026 determination (effective 2026-07-01)
Also applies to financial services · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.