Key Takeaways
1. No New SOC 1 or SOC 2 Revisions: SOC 1 still runs on SSAE 18’s AT-C 320, and SOC 2 still runs on the 2017 Trust Services Criteria with the 2022 Points of Focus. Updates to SOC 1 and SOC 2 are anticipated, but the earliest timeline for implementation is likely 2027.
2. The Focus is Audit Rigor: Auditors increasingly expect continuous monitoring evidence, deeper third-party/vendor risk documentation, and tighter mapping between SOC controls and other security frameworks like CMMC, HITRUST, ISO 27001, and PCI DSS.
3. AI is an Area of Focus: Wherever AI or automation touches customer data — model training, AI-assisted support tools, automated decisioning — auditors are asking harder questions, and privacy criteria are increasingly being scoped in as a result.
SOC 1 and SOC 2 remain two of the most requested certifications for service organizations, but neither framework has been revised since 2022 when the Trust Services Criteria was updated. Despite a lack of recent SOC updates, auditors are testing controls more rigorously today in a reflection of the changing threat landscape. Vendor risk management practices are being scrutinized with particular attention paid to the effects of artificial intelligence (AI) and automation on customer data. Organizations preparing for SOC 1 or SOC 2 compliance today can, therefore, expect a tougher audit experience.
No SOC Updates, but Audits are More Rigorous
The System and Organization Controls (SOC) 1 & 2 reports that organizations use to demonstrate the security of their internal business processes have not had a significant update since the Trust Services Criteria was revised in 2022. Since then, the risk landscape has seen dramatic changes thanks to the rapid adoption of advanced artificial intelligence (AI) and automation. Because of these developments, and despite the lack of SOC updates, auditors are focusing their efforts on ensuring that the use of AI and automation is consistent with SOC mandates.
That means organizations pursuing a SOC report must be prepared for a more rigorous audit process. Here’s what you need to know.
What SOC 1 and SOC 2 Actually Cover
Both reports come from the American Institute of Certified Public Accountants (AICPA), but they answer different questions.
SOC 1 evaluates a service organization’s business processes relevant to a client’s internal control over financial reporting (ICFR). It matters most to organizations engaged in services like payroll processing, claims administration, fund administration, and payment processing that could affect a customer’s financial statements. SOC 1 examinations are performed under SSAE 18’s AT-C 320, and the report is an attestation, not a certification in the ISO sense. The most recent SOC 1 updates were the Statement on Standards for Attestation Engagement (SSAE) 18 (2017), SSAE 21 (2022), and SSAE 23 (2025).
SOC 2 evaluates controls against five Trust Services Criteria: security, availability, confidentiality, processing integrity, and privacy. Security is mandatory; the other four are selected based on customer and contractual needs. Like SOC 1, SOC 2 is technically an attestation report issued by a licensed CPA firm, not a certificate. The most recent SOC 2 updates were in the 2022 Revised Points of Focus to the Trust Services Criteria.
Two Frameworks, Two Report Types:
- Type 1 attests that controls are suitably designed as of a single point in time.
- Type 2 attests that controls operated effectively over a defined period, typically three to twelve months. Type 2 reports are what most enterprise buyers now expect before signing a contract.
Current Requirements: The Standards Underneath the Standards
SOC 1
(SOC 1 lineage determines what auditors cite in engagement letters and reports.)
- SSAE 18 (effective May 2017) remains the foundational standard for SOC 1 examinations, codified under AT-C 320.
- SSAE 21 (effective June 2022) revised assertion-based examination guidance (AT-C 205) and introduced direct examinations (AT-C 206) but left AT-C 320 untouched.
- SSAE 23 is the newest amendment, effective for engagements beginning on or after December 15, 2025. It aligns attestation engagements with the AICPA’s quality-management standards (SQMS No. 1), which affects how audit firms themselves must document and manage engagement quality — an indirect but meaningful change for organizations working with smaller or newer audit shops.
SOC 2
- The 2017 Trust Services Criteria remains the governing criteria set.
- The 2022 Revised Points of Focus, published in final form in September 2023, updated the explanatory examples beneath each criterion to reflect newer technologies and threats without changing the criteria themselves.

Newest Best Practices for Certification Preparation
Compliance teams preparing for a 2026 audit cycle are adjusting their approach in several ways:
- Move from Point-in-Time to Continuous Evidence: Quarterly screenshots of configuration settings are increasingly insufficient. Auditors want proof that controls operated every day of the audit window, which typically means investing in compliance automation or continuous control monitoring tooling.
- Treat Vendor Risk Management as a Standing Program: With third-party-linked breaches rising sharply industry-wide, auditors are applying heavier scrutiny to vendor inventories, security questionnaires, and periodic review cadences — not documentation that was last updated over a year ago.
- Align SOC Controls with Complementary Frameworks: Organizations pursuing SOC reports often operate under other security standards like ISO 27001, CMMC, HITRUST, and PCI DSS as well. Aligning SOC controls with these frameworks can reduce duplicative work and streamline operational efficiencies.
- Include AI Privacy Criterion if Those Systems Touch Customer Data: Organizations processing personal data with AI or using that data for algorithmic training should include SOC 2’s optional privacy criterion in anticipation of ensuring compliance with new or expected laws and regulations.
- Vet Your Audit Firm’s Testing Rigor Before Engagement: The rise of fast, low-cost SOC 2 providers has raised industry concerns about report quality and objectivity. Before engagement, ask prospective auditors which specific criteria they’ll test and what evidence format they expect — particularly for cloud configuration controls.
- Build Continuous Education into Your Compliance Calendar: Because interpretive guidance shifts more often than the criteria themselves, checking the AICPA’s published guidance on a recurring basis rather than relying on secondhand vendor summaries helps compliance teams stay ahead of audit expectations.
Preparing for AI-Driven SOC Updates
The most consistent theme across recent SOC updates is that AI and automation have become a genuine audit focus rather than a side note. Wherever a service organization uses AI to touch customer data through machine learning models trained on client information, AI-assisted support or ticketing tools, or automated decisioning systems, auditors are now asking pointed questions about how that data is governed, who can access it, and what guardrails exist around model outputs. Organizations that treat this as an afterthought tend to struggle during fieldwork, because auditors increasingly expect documented evidence of AI-specific risk assessments, not just general IT control narratives that predate AI adoption.
Practically, preparing for this shift starts with inventorying every system and workflow where AI or automation interacts with in-scope data, then mapping those systems to existing control objectives. If an organization uses AI for tasks like anomaly detection, customer support automation, or internal decision support, it should be able to show how access to training data and model outputs is restricted, logged, and reviewed. This is also where scoping in SOC 2’s Privacy criterion becomes more compelling. As regulatory regimes like the EU AI Act tighten expectations for high-risk AI systems, having a privacy-scoped SOC 2 report gives customers greater assurance that AI-related risks are being managed properly.
Finally, organizations should treat readiness for AI-related scrutiny as an ongoing discipline rather than a pre-audit sprint. That means building AI and automation risk reviews into the same continuous-monitoring cadence used for other controls, briefing the audit firm early on which AI tools are in scope, and keeping policy documentation current as new AI capabilities are adopted. Given how quickly this area is evolving, staying ahead of the next round of SOC updates will likely depend less on reacting to a new AICPA criteria set and more on proactively demonstrating that AI-related risk is already being managed with the same rigor as traditional IT controls.
What’s on the Horizon for SOC and SOC Updates?
Several signals suggest more substantial change could be coming, even though nothing has been finalized. Engaging with an objective, outside advisory firm for a thorough SOC assessment based on current best practices increases your likelihood of success and can help to anticipate likely updates as they develop. Here are some things to keep in mind:
- SOC 1 Updates and SOC 2 Updates: Industry observers note that it has now been nearly a decade since the core Trust Services Criteria were introduced, and the pace of change in cloud computing, AI, and cyber threats is fueling speculation that a more substantial AICPA update could eventually follow the 2022 points-of-focus revision. At present no such overhaul has been announced or scheduled.
- Continued Scrutiny of Low-Cost SOC 2 Providers: Concerns about report quality and auditor objectivity from rapid-certification vendors may prompt the AICPA to tighten guidance around engagement quality — a trend SSAE 23’s quality-management alignment already reflects on the SOC 1 side.
- Deeper Integration with Complementary Frameworks: Expect continued convergence between SOC 2 reporting and frameworks like ISO 27001, CMMC, HITRUST, and PCI DSS. For organizations operating in Europe, alignment with the EU AI Act should be considered.
- No Confirmed Timeline for SOC Updates: Organizations should treat any vendor claim of new SOC 1 updates or SOC 2 updates for 2026 or 2027 with caution absent a citation to an official AICPA publication. A reliable IT compliance and risk advisory firm like IS Partners will remain up to date with the AICPA and not use high-pressure tactics when engaged with customers.
If you have any questions about SOC best practices, your current SOC readiness, or about potential SOC 1 updates or SOC 2 updates, contact IS Partners for more information.
What Should You Do Next?
Audit Evidence-Collection Processes: Identify where you currently rely on periodic screenshots or manual spot checks and prioritize automating those processes to ensure they align with best practices.
Refresh Your Documentation: Vendor inventories, updated security questionnaires, and a documented review cadence must be current. This is one of the most scrutinized control areas in current audits.
Talk to your Audit Firm: Whether you have an existing relationship or are evaluating prospective audit firms, ask them about AI-related scope, including which Trust Services Criteria they’ll test, what evidence format they expect, and whether your use of AI or automation warrants scoping in the Privacy criterion.









