AICPA SOC 3
Trust Services Criteria for general use reporting
AICPA SOC 3 is a compliance framework from United States with 13 domains and 22 controls that map to 17 other frameworks. The largest domains are Common Criteria (9 controls), Scope (2 controls), Assertion (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Assertion
| Code | Title |
|---|---|
| SOC3-MGMT-ASSERT | Management Assertion |
Common Criteria
| Code | Title |
|---|---|
| SOC3-CHANGE-MGT | Change Management |
| SOC3-COMMS | Communication |
| SOC3-CONTROL-ENV | Control Environment |
| SOC3-INCIDENT-MGT | Incident Response |
| SOC3-LOGICAL-ACCESS | Logical Access |
| SOC3-MONITORING | Monitoring Controls |
| SOC3-RISK-ASSESS | Risk Assessment Process |
| SOC3-VENDOR | Vendor and Subservice Management |
| SOC3-VULN-MGT | Vulnerability Management |
Confidentiality
| Code | Title |
|---|---|
| SOC3-DATA-PROTECT | Data Protection |
Criteria
| Code | Title |
|---|---|
| SOC3-TSC | Trust Services Criteria Coverage |
Distribution
| Code | Title |
|---|---|
| SOC3-MARKETING-USE | Marketing and Distribution |
Report Purpose
| Code | Title |
|---|---|
| SOC3-PURPOSE | General Use Trust Services Report |
Reporting
| Code | Title |
|---|---|
| SOC3-AUDITOR-OPINION | Auditor Opinion |
Scope
| Code | Title |
|---|---|
| SOC3-BOUNDARY | System Boundary |
| SOC3-PERIOD | Reporting Period |
TSC Availability
| Code | Title |
|---|---|
| SOC3-AVAILABILITY | Availability Criteria |
TSC Confidentiality
| Code | Title |
|---|---|
| SOC3-CONFID | Confidentiality |
TSC PI
| Code | Title |
|---|---|
| SOC3-PROC-INTEG | Processing Integrity |
TSC Privacy
| Code | Title |
|---|---|
| SOC3-PRIVACY | Privacy Criteria |
TSC Security
| Code | Title |
|---|---|
| SOC3-SECURITY | Common Criteria Security |
Your Compliance Coverage
If you comply with AICPA SOC 3, you already cover:
SOC 2
59%
13 controls mapped
Compare →ISO 31000:2018
14%
3 controls mapped
Compare →ISO/IEC 23894:2023
9%
2 controls mapped
Compare →+ 14 more: ISO 27018:2019 (9%), ISO 27002:2022 (9%)
See all 17 mapped frameworks ↓Maps to 17 other frameworks
What is AICPA SOC 3 and who does it apply to?
AICPA SOC 3 is a compliance framework from United States with 13 domains and 22 controls. Trust Services Criteria for general use reporting It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does AICPA SOC 3 actually require?
AICPA SOC 3 has 22 controls organised across 13 domains. The largest domains are Common Criteria (9 controls), Scope (2 controls), Assertion (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of AICPA SOC 3 do I already cover?
AICPA SOC 3 maps to 17 other compliance frameworks. The top mapping partners are SOC 2 (59% coverage), ISO 31000:2018 (14% coverage), ISO/IEC 23894:2023 (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement AICPA SOC 3?
Start your AICPA SOC 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AICPA SOC 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required