Skip to main content
Framework library
Framework module · soc-for-cybersecurity

SOC for Cybersecurity

AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.

AICPA cybersecurity risk management reporting framework · AICPA — SOC for Cybersecurity

Standing today
Directory entry

00Answer

from the registry record
What is SOC for Cybersecurity?
AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.
Who does SOC for Cybersecurity apply to?
SOC for Cybersecurity applies to enterprise risk, financial services, critical infrastructure, US, per AICPA — SOC for Cybersecurity.
What is the current version of SOC for Cybersecurity?
The current edition is AICPA cybersecurity risk management reporting framework, issued by AICPA — SOC for Cybersecurity. Source: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-for-cybersecurity.
What does an assessment under SOC for Cybersecurity require?
No control catalog has been ingested for SOC for Cybersecurity yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

SOC for Cybersecurity is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

AICPA-controlled — the same posture as SOC 1/SOC 2; obtain the description criteria and applicable trust services criteria before verbatim ingestion.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Description criteria · Risk management program · Trust services criteria (security) · Management's assertion
Applies to
enterprise risk · financial services · critical infrastructure · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06

03Version ledger

1 edition
AICPA cybersecurity risk management reporting frameworkCurrent editiondate not published

06Related frameworks

scored from registry facts
  1. Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. FFIEC IT Examination HandbookCurrent booklets (living collection)

    Also applies to financial services · The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.

  3. ISO 223012019 (Amd 1:2024)

    Also applies to critical infrastructure · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.

  4. APRA CPS 2302026 determination (effective 2026-07-01)

    Also applies to financial services · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.

SOC for Cybersecurity | ControlFrame