AICPA SOC 3
Trust Services Criteria for general use reporting
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
AICPA SOC 3: Cybersecurity Controls
Technical cybersecurity measures (AICPA SOC 3)
AICPA SOC 3: Incident Management & Reporting
Incident handling for financial services (AICPA SOC 3)
AICPA SOC 3: Information Security Governance
IT governance for financial institutions (AICPA SOC 3)
AICPA SOC 3: Operational Resilience
Business continuity and resilience (AICPA SOC 3)
AICPA SOC 3: Third-Party Risk Management
Managing vendor and supplier risks (AICPA SOC 3)
Assertion
| Code | Title |
|---|---|
| SOC3-MGMT-ASSERT | Management Assertion |
Common Criteria
| Code | Title |
|---|---|
| SOC3-CHANGE-MGT | Change Management |
| SOC3-COMMS | Communication |
| SOC3-CONTROL-ENV | Control Environment |
| SOC3-INCIDENT-MGT | Incident Response |
| SOC3-LOGICAL-ACCESS | Logical Access |
| SOC3-MONITORING | Monitoring Controls |
| SOC3-RISK-ASSESS | Risk Assessment Process |
| SOC3-VENDOR | Vendor and Subservice Management |
| SOC3-VULN-MGT | Vulnerability Management |
Confidentiality
| Code | Title |
|---|---|
| SOC3-DATA-PROTECT | Data Protection |
Criteria
| Code | Title |
|---|---|
| SOC3-TSC | Trust Services Criteria Coverage |
Distribution
| Code | Title |
|---|---|
| SOC3-MARKETING-USE | Marketing and Distribution |
Report Purpose
| Code | Title |
|---|---|
| SOC3-PURPOSE | General Use Trust Services Report |
Reporting
| Code | Title |
|---|---|
| SOC3-AUDITOR-OPINION | Auditor Opinion |
Scope
| Code | Title |
|---|---|
| SOC3-BOUNDARY | System Boundary |
| SOC3-PERIOD | Reporting Period |
TSC Availability
| Code | Title |
|---|---|
| SOC3-AVAILABILITY | Availability Criteria |
TSC Confidentiality
| Code | Title |
|---|---|
| SOC3-CONFID | Confidentiality |
TSC PI
| Code | Title |
|---|---|
| SOC3-PROC-INTEG | Processing Integrity |
TSC Privacy
| Code | Title |
|---|---|
| SOC3-PRIVACY | Privacy Criteria |
TSC Security
| Code | Title |
|---|---|
| SOC3-SECURITY | Common Criteria Security |
Maps to 1 other framework
Frequently Asked Questions
What is AICPA SOC 3?
AICPA SOC 3 is a compliance framework from United States with 18 domains and 22 controls. Trust Services Criteria for general use reporting It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does AICPA SOC 3 have?
AICPA SOC 3 has 22 controls organised across 18 domains. The largest domains are Common Criteria (9 controls), Scope (2 controls), Assertion (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does AICPA SOC 3 map to?
AICPA SOC 3 maps to 1 other compliance frameworks. The top mapping partners are SOC 2 (59% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with AICPA SOC 3 compliance?
Start your AICPA SOC 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AICPA SOC 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required