Attestation · Last verified
SOC for Supply Chain
SOC for Supply Chain is an AICPA attestation: an examination report on controls in a production, manufacturing, or distribution system — not a certificate. The AICPA describes it as a "market-driven, flexible, and voluntary reporting framework" for manufacturers, producers, and distribution companies and their customers and business partners.
- Class
- Attestation
- Owner
- AICPA
- Who asks for it
- Voluntary
- Last verified
What it is
SOC for Supply Chain belongs to the AICPA's SOC reporting suite. The AICPA's full subject heading defines the engagement: "Reporting on an Examination of Controls Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy in a Production, Manufacturing, or Distribution System" — the output is an examination report, not a certificate.
The AICPA names the organizations it is designed for: "Manufacturers, producers, and distribution companies (referred to herein as 'organizations')".
On the description the report is built around, the AICPA states: "Description criteria are used by entity management when preparing the description of the entity's system and by the practitioner when evaluating the description."
Who owns it
SOC for Supply Chain is owned and maintained by the AICPA, which publishes the description criteria used in the engagement.
Who asks for it
The AICPA names the audience itself: "organizations, and their customers and business partners". No legal instrument requiring a SOC for Supply Chain report was identified in the sources reviewed as of 31 August 2026.
Sources
- AICPA — SOC for Supply Chain (scheme owner) ↗ — accessed
- AICPA — Learn about SOC for Supply Chain ↗ — accessed
- AICPA — description criteria for a SOC for Supply Chain engagement (download landing page) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.