Attestation · Last verified

SOC for Cybersecurity

SOC for Cybersecurity is an AICPA attestation engagement in which a CPA reports on an organization's enterprise-wide cybersecurity risk management program. The AICPA calls it "a market-driven, flexible, and voluntary reporting framework to help organizations communicate about their cybersecurity" — the output is a report, not a certificate.

Class
Attestation
Owner
AICPA
Who asks for it
Voluntary
Last verified

What it is

SOC for Cybersecurity belongs to the AICPA's SOC reporting suite. In the AICPA's own words, under it "a CPA reports on an organizations' enterprise-wide cybersecurity risk management program" — the output is an examination report, not a certificate.

The AICPA states its purpose: to "communicate relevant and useful information about the effectiveness of their cybersecurity risk management programs". Through the engagement, "organizations can communicate pertinent information regarding their cybersecurity risk-management efforts and educate stakeholders about the systems, processes and controls they have in place to detect, prevent and respond to breaches".

The engagement is defined in the AICPA attestation guide "Reporting on an Entity's Cybersecurity Risk Management Program and Controls": to "examine and report on an entity's cybersecurity risk management program (SOC for Cybersecurity)".

Who owns it

SOC for Cybersecurity is owned and maintained by the AICPA, which publishes the attestation guide "Reporting on an Entity's Cybersecurity Risk Management Program and Controls".

Who assesses it

The AICPA's own description names the assessor: under the framework "a CPA reports on an organizations' enterprise-wide cybersecurity risk management program". Whether the examination may only be performed by a licensed CPA firm was not verified in the sources reviewed as of 31 August 2026.

Who asks for it

The AICPA names the intended audience itself: "boards of directors, managers, investors, customers and other stakeholders of organizations of all sizes", and elsewhere "management and boards of directors of diverse organizations, and for the benefit of the public interest". No legal instrument requiring a SOC for Cybersecurity report was identified in the sources reviewed as of 31 August 2026.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"SOC for Cybersecurity." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/soc-for-cybersecurity

All frameworks & audits →