SOC 2 in 2026: What the 2022 TSC Revision Changed, and What Hasn't
TL;DR
- The AICPA has not released new Trust Services Criteria for 2025 or 2026. The framework in force today is the 2017 TSC with revised points of focus published in September 2023.
- The 2022 revision updated the supplemental guidance that auditors use to interpret individual criteria. It did not add, remove, or renumber the criteria themselves.
- The five Trust Services Criteria categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) are unchanged. Security remains the only mandatory category.
- AICPA published updated implementation guidance for SOC 2 description criteria in July 2025, but this covers how to write a system description, not new control requirements.
- If you encounter a vendor or article claiming "new SOC 2 requirements for 2025/2026," ask them to link to the AICPA source. No such requirements exist as of this writing.
Who this is for
This article is for security engineers, compliance leads, and SaaS founders preparing for a SOC 2 audit who have seen conflicting claims about "2026 updates" and want to know what is actually in the framework. If you are starting SOC 2 for the first time, start with our SOC 2 compliance guide first.
What the AICPA Actually Published

Two things changed between 2022 and today that are worth understanding clearly.
First: the 2022 revised points of focus. In September 2023, the AICPA published the 2017 Trust Services Criteria with Revised Points of Focus, 2022. Points of focus are explanatory examples that help auditors and practitioners understand how a criterion applies in practice. They are not criteria themselves and they do not change what controls you need. What they do affect is how an auditor evaluates whether your controls are designed and operating appropriately.
Second: the 2025 description criteria update. In July 2025, AICPA released revised implementation guidance for the 2018 SOC 2 Description Criteria. This document governs how service organizations write the system description that appears in their SOC 2 report, the section that describes what your system does, its boundaries, and the controls in place. The guidance clarifies how to write a system description that meets current auditor expectations. It does not change the Trust Services Criteria or add new audit requirements.
Neither of these changes introduced new compliance obligations. What they did was sharpen the vocabulary auditors use when evaluating your controls.
The Five Categories Have Not Changed
The Trust Services Criteria have five categories. All five remain exactly as they were in 2017:
| Category | Mandatory? | Who typically includes it |
|---|---|---|
| Security (Common Criteria) | Yes | All SOC 2 reports |
| Availability | No | SaaS companies with uptime SLAs |
| Processing Integrity | No | Payment processors, data pipelines |
| Confidentiality | No | B2B companies handling sensitive data |
| Privacy | No | Companies that collect personal data |
The Security category covers 33 criteria organized across nine control groups: CC1 (Control Environment), CC2 (Communication and Information), CC3 (Risk Assessment), CC4 (Monitoring Activities), CC5 (Control Activities), CC6 (Logical and Physical Access), CC7 (System Operations), CC8 (Change Management), and CC9 (Risk Mitigation).
Nothing in that structure changed with the 2022 revision.
What the 2022 Revision Actually Modified
The 2022 revision updated the points of focus attached to specific criteria, primarily within CC6, CC7, and CC9. Points of focus are illustrative examples, not mandatory controls. An organization can satisfy a criterion without addressing every point of focus, provided it can demonstrate the criterion is met through other means.
Three areas where the 2022 language became more precise:
Logical access (CC6). The revised points of focus added language around access provisioning and de-provisioning for cloud-based systems, and clarified expectations around privileged access reviews. The underlying criterion, that access is restricted to authorized users, did not change.
System monitoring (CC7). The revision added examples related to anomaly detection and incident identification processes. Again, the core criterion (that the organization monitors for and responds to security events) is unchanged.
Vendor and supply chain risk (CC9). The revised guidance added more explicit examples of how to evaluate risk from subservice providers and business partners. The criterion itself, which requires identifying and managing vendor risk, was already in the 2017 framework.
If your last SOC 2 was completed before 2023, your audit firm may reference these updated points of focus in how they frame sample requests. The controls you need are the same. The documentation they expect may be more specific about cloud-native environments.
What Has Not Changed (and Will Not Change Without a New Release)

Several things about SOC 2 are fixed until AICPA formally updates the framework, which they have not announced:
The criteria identifiers. CC1.1 through CC9.8, A1.1 through A1.3, PI1.1 through PI1.5, C1.1 through C1.2, and P1.0 through P8.1 are the current criteria. No new criteria have been added.
The attestation model. SOC 2 is an attestation, not a certification. An independent CPA firm issues an opinion on your controls. No government body approves SOC 2 reports. AICPA sets the framework; licensed CPA firms apply it. This is different from ISO 27001, which involves a third-party certification body issuing a certificate.
Type 1 vs. Type 2 distinction. Type 1 assesses control design at a point in time. Type 2 assesses design and operating effectiveness over a period (typically 6 to 12 months). Both remain options. Neither has changed in scope or structure.
The role of the service auditor. The CPA firm examining your controls is a service auditor, not a certifier. Their report expresses an opinion; it does not certify you as compliant. A qualified or adverse opinion does not mean you are barred from operating. It means specific controls were found not to be suitably designed or operating effectively.
Why You're Seeing "2026 Updates" Content
There is a pattern in the compliance content space where writers date articles to the current year and frame ongoing audit practice evolution as official framework changes. "What auditors are asking in 2026" is a legitimate topic. "New SOC 2 requirements for 2026" is not accurate unless AICPA has announced them.
Three things that are genuinely changing in the audit landscape, but are not framework changes:
GRC platform evidence expectations. Many audit firms now prefer or require automated evidence exports from platforms like Vanta, Drata, or Secureframe over point-in-time screenshots. This is an audit firm practice preference, not an AICPA requirement. It varies by firm.
AI system controls. If your service organization uses AI models in production, auditors are increasingly asking how you control access, monitor outputs, and manage risk, primarily because this maps to existing CC6 and CC7 criteria applied to a new technology context. The NIST AI Risk Management Framework 1.0, released in January 2023, provides a vocabulary for this that some audit narratives now reference.
Vendor evidence collection. Auditors are more consistently enforcing the CC9.2 expectation that organizations review and retain evidence of subservice provider SOC 2 reports during the audit window. This was always in the criteria; enforcement varies by firm and has tightened as vendor chains have grown.
None of these constitute official AICPA updates. If your audit firm raises any of them, ask them to map the expectation to the specific criterion. They should be able to point to a CC or A or P criterion number.
What to Do With This Information
If you are preparing for a SOC 2 audit in 2026, three practical things follow from the above:
Use the current published document. The authoritative reference is the 2017 Trust Services Criteria with Revised Points of Focus, 2022, published September 2023. Any article or vendor describing SOC 2 requirements should be traceable back to this document.
Ask your audit firm what they are testing against. Different firms apply points of focus with different strictness. Before signing an engagement letter, ask: which criteria will you test? What evidence format do you expect for cloud configuration controls? Do you require continuous monitoring exports? Getting this in writing avoids surprises during fieldwork.
In practice, teams preparing for a first SOC 2 most often discover this gap late: their audit firm arrives expecting automated evidence exports from Vanta or Drata, while the team has been collecting point-in-time screenshots. Neither approach is wrong under the TSC, but the mismatch creates rework in the final weeks before the report is issued. The pre-engagement conversation described above takes thirty minutes and saves three to four weeks of scrambling during fieldwork.
The description criteria update matters if you are writing a new report. If your last SOC 2 was completed before July 2025, your system description may not reflect the revised guidance. This does not invalidate your existing report, but it is worth reviewing before your next audit cycle so the description matches how your system actually operates.
For a full breakdown of what each criterion requires, see our SOC 2 Trust Services Criteria guide. For auditor selection, see how to choose a SOC 2 auditor.
Mini-FAQ

Has AICPA announced new Trust Services Criteria for 2025 or 2026?
No. As of May 2026, the current framework is the 2017 TSC with revised points of focus published in September 2023. AICPA has not announced a new version or a scheduled update.
Is there a difference between the 2017 TSC and the "2022 revision"?
The 2022 revision updated the supplemental points of focus, illustrative examples that help auditors interpret criteria. The criteria identifiers, categories, and control requirements are the same as in 2017. The document is officially titled "2017 Trust Services Criteria with Revised Points of Focus, 2022."
What did AICPA publish in July 2025?
Updated implementation guidance for SOC 2 description criteria. This document helps service organizations write the system description section of their SOC 2 report. It is not a change to Trust Services Criteria.
My audit firm told me there are new 2026 requirements. Is that accurate?
Ask them to point to the specific AICPA document. They may be describing evolving audit firm practices (evidence format preferences, stricter sampling for cloud controls) rather than formal framework changes. Both are real, but the distinction matters. Audit firm practices vary; the AICPA framework applies uniformly.
When will SOC 2 next be formally updated?
AICPA has not published a timeline for a new TSC version. Monitor aicpa-cima.com for announcements.
Does SOC 2 cover AI systems?
Existing criteria, primarily CC6 and CC7, already apply to AI systems used in production. AICPA has not published AI-specific criteria. Some practitioners map SOC 2 controls to the NIST AI RMF for additional structure, but this is optional and not a requirement.
Sources:
- AICPA, "2017 Trust Services Criteria with Revised Points of Focus, 2022," published September 30, 2023. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2 (accessed 2026-05-12)
- AICPA, "2018 SOC 2 Description Criteria (With Revised Implementation Guidance, 2022)," published July 9, 2025. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2 (accessed 2026-05-12)
- NIST, "AI Risk Management Framework 1.0," released January 26, 2023. https://www.nist.gov/itl/ai-risk-management-framework (accessed 2026-05-12)
Last reviewed: 2026-05-12. This article was prepared by the Security Compliance Guide Editorial Team. We use AI to draft initial summaries of publicly available cybersecurity compliance documentation, then verify every claim against primary sources before publication. We are not licensed auditors, attorneys, or compliance consultants. For binding decisions, consult a qualified professional. See our editorial standards for full sourcing rules.
