Back to Frameworks

AICPA SOC 3

United States
v2023
18 domains
22 controls

Trust Services Criteria for general use reporting

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (18)

AICPA SOC 3: Cybersecurity Controls

0 controls

Technical cybersecurity measures (AICPA SOC 3)

AICPA SOC 3: Incident Management & Reporting

0 controls

Incident handling for financial services (AICPA SOC 3)

AICPA SOC 3: Information Security Governance

0 controls

IT governance for financial institutions (AICPA SOC 3)

AICPA SOC 3: Operational Resilience

0 controls

Business continuity and resilience (AICPA SOC 3)

AICPA SOC 3: Third-Party Risk Management

0 controls

Managing vendor and supplier risks (AICPA SOC 3)

Assertion

1 controls
Controls in the Assertion domain of AICPA SOC 31 controls
CodeTitle
SOC3-MGMT-ASSERTManagement Assertion

Common Criteria

9 controls
Controls in the Common Criteria domain of AICPA SOC 39 controls
CodeTitle
SOC3-CHANGE-MGTChange Management
SOC3-COMMSCommunication
SOC3-CONTROL-ENVControl Environment
SOC3-INCIDENT-MGTIncident Response
SOC3-LOGICAL-ACCESSLogical Access
SOC3-MONITORINGMonitoring Controls
SOC3-RISK-ASSESSRisk Assessment Process
SOC3-VENDORVendor and Subservice Management
SOC3-VULN-MGTVulnerability Management

Confidentiality

1 controls
Controls in the Confidentiality domain of AICPA SOC 31 controls
CodeTitle
SOC3-DATA-PROTECTData Protection

Criteria

1 controls
Controls in the Criteria domain of AICPA SOC 31 controls
CodeTitle
SOC3-TSCTrust Services Criteria Coverage

Distribution

1 controls
Controls in the Distribution domain of AICPA SOC 31 controls
CodeTitle
SOC3-MARKETING-USEMarketing and Distribution

Report Purpose

1 controls
Controls in the Report Purpose domain of AICPA SOC 31 controls
CodeTitle
SOC3-PURPOSEGeneral Use Trust Services Report

Reporting

1 controls
Controls in the Reporting domain of AICPA SOC 31 controls
CodeTitle
SOC3-AUDITOR-OPINIONAuditor Opinion

Scope

2 controls
Controls in the Scope domain of AICPA SOC 32 controls
CodeTitle
SOC3-BOUNDARYSystem Boundary
SOC3-PERIODReporting Period

TSC Availability

1 controls
Controls in the TSC Availability domain of AICPA SOC 31 controls
CodeTitle
SOC3-AVAILABILITYAvailability Criteria

TSC Confidentiality

1 controls
Controls in the TSC Confidentiality domain of AICPA SOC 31 controls
CodeTitle
SOC3-CONFIDConfidentiality

TSC PI

1 controls
Controls in the TSC PI domain of AICPA SOC 31 controls
CodeTitle
SOC3-PROC-INTEGProcessing Integrity

TSC Privacy

1 controls
Controls in the TSC Privacy domain of AICPA SOC 31 controls
CodeTitle
SOC3-PRIVACYPrivacy Criteria

TSC Security

1 controls
Controls in the TSC Security domain of AICPA SOC 31 controls
CodeTitle
SOC3-SECURITYCommon Criteria Security

Maps to 1 other framework

22 total controls
SOC 2
13 source controls mapped|31 target controls covered
59%

Frequently Asked Questions

What is AICPA SOC 3?

AICPA SOC 3 is a compliance framework from United States with 18 domains and 22 controls. Trust Services Criteria for general use reporting It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does AICPA SOC 3 have?

AICPA SOC 3 has 22 controls organised across 18 domains. The largest domains are Common Criteria (9 controls), Scope (2 controls), Assertion (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does AICPA SOC 3 map to?

AICPA SOC 3 maps to 1 other compliance frameworks. The top mapping partners are SOC 2 (59% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with AICPA SOC 3 compliance?

Start your AICPA SOC 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AICPA SOC 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required