Attestation · Last verified
SOC for Cybersecurity
SOC for Cybersecurity is an AICPA attestation engagement in which a CPA reports on an organization's enterprise-wide cybersecurity risk management program. The AICPA calls it "a market-driven, flexible, and voluntary reporting framework to help organizations communicate about their cybersecurity" — the output is a report, not a certificate.
- Class
- Attestation
- Owner
- AICPA
- Who asks for it
- Voluntary
- Last verified
What it is
SOC for Cybersecurity belongs to the AICPA's SOC reporting suite. In the AICPA's own words, under it "a CPA reports on an organizations' enterprise-wide cybersecurity risk management program" — the output is an examination report, not a certificate.
The AICPA states its purpose: to "communicate relevant and useful information about the effectiveness of their cybersecurity risk management programs". Through the engagement, "organizations can communicate pertinent information regarding their cybersecurity risk-management efforts and educate stakeholders about the systems, processes and controls they have in place to detect, prevent and respond to breaches".
The engagement is defined in the AICPA attestation guide "Reporting on an Entity's Cybersecurity Risk Management Program and Controls": to "examine and report on an entity's cybersecurity risk management program (SOC for Cybersecurity)".
Who owns it
SOC for Cybersecurity is owned and maintained by the AICPA, which publishes the attestation guide "Reporting on an Entity's Cybersecurity Risk Management Program and Controls".
Who assesses it
The AICPA's own description names the assessor: under the framework "a CPA reports on an organizations' enterprise-wide cybersecurity risk management program". Whether the examination may only be performed by a licensed CPA firm was not verified in the sources reviewed as of 31 August 2026.
Who asks for it
The AICPA names the intended audience itself: "boards of directors, managers, investors, customers and other stakeholders of organizations of all sizes", and elsewhere "management and boards of directors of diverse organizations, and for the benefit of the public interest". No legal instrument requiring a SOC for Cybersecurity report was identified in the sources reviewed as of 31 August 2026.
Sources
- AICPA — SOC for Cybersecurity (scheme owner) ↗ — accessed
- AICPA — SOC for Cybersecurity: information for organizations ↗ — accessed
- AICPA — Learn about SOC for Cybersecurity ↗ — accessed
- AICPA — Reporting on an Entity's Cybersecurity Risk Management Program and Controls (attestation guide) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.