SOC 2 Common Criteria Changes: What the 2022 Points of Focus Update Actually Changed
A practical read on the 2022 Revised Points of Focus for the 2017 Trust Services Criteria — what changed for SaaS evidence, and what did not.
The AICPA’s 2017 Trust Services Criteria remain the examination criteria for SOC 2. In 2022, AICPA published Revised Points of Focus — guidance that clarifies how examiners and management think about control design and evidence. The criteria identifiers (CC1–CC9 and category criteria) did not become a brand-new framework; the update sharpened expectations.
Primary source: AICPA Trust Services Criteria with 2022 Revised Points of Focus.
What did not change
- You still need a system description, suitable controls, and — for Type II — operating effectiveness over a period.
- Security remains the baseline category; Availability, Confidentiality, Processing Integrity, and Privacy are additive.
- A SOC 2 report is still an attestation, not a certification badge.
- Licensed CPA firms (or equivalent attestation practitioners) still perform examinations under professional standards.
If a vendor claims “new SOC 2 standard — buy our 2022 module,” ask which criterion text changed versus which implementation checklist they repackaged.
What Points of Focus are (and are not)
Points of Focus are non-prescriptive examples that help illustrate how criteria might be addressed. They are not mandatory controls. Auditors still exercise judgment based on your system, risks, and commitments.
Practically, PoF updates shift conversation density — examiners and readiness tools cite refreshed language, and weak programs that relied on generic policy packs face harder questions in walkthroughs.
What teams feel in practice
The 2022 refresh emphasizes themes SaaS auditors already sampled aggressively. If your program was evidence-driven, the update is mostly documentation alignment. If you were checklist-shopping, PoF language makes gaps easier to see.
Logical access and identity
Expect deeper questions on complete user and account inventories, including service accounts, vendor access, and administrative planes. Engineering guide: /controls/soc-2/cc6-1. Blog depth: /blog/engineers-guide-to-cc6-1.
Change management traceability
Points of Focus reinforce linkage from authorized change through implementation — tickets, approvals, tests, deploy records, and emergency change handling. Reference: CC8.1.
Detection, monitoring, and incident response
Monitoring is not satisfied by “we use a SIEM” slides. Examiners look for alert routing, triage, escalation, and closure evidence across the observation window. CC7 family: CC7.1 through CC7.5.
Vendor and subservice organizations
Clarified emphasis on understanding subservice commitments and monitoring complementary controls where carve-out or inclusive methods apply. CC9.2 remains a frequent sample area for SaaS companies hosted on major cloud providers.
Type I vs Type II under refreshed PoF
Type I tests design at a point in time; Type II tests operation across the period. PoF language does not remove the Type II calendar — it raises the bar for what “operating effectiveness” looks like in access, change, and monitoring samples.
Compare examination types: /compare/soc-2-type-1-vs-type-2. Fee bands: /costs/soc-2/type-1 and /costs/soc-2/type-2.
What to update in your program
- Control narratives — map existing controls to current PoF wording without inventing new controls for every bullet.
- System description — ensure boundaries, subservice treatment, and complementary user entity controls reflect actual architecture.
- Evidence calendars — access reviews, change samples, vulnerability management, and IR drills should span the full observation window, not only the month before fieldwork.
- Sales and trust center copy — do not claim “2022 SOC 2 certified”; describe the report type, categories, and period accurately.
Readiness heuristic: /tools/readiness-assessment.
Relationship to automation platforms
GRC platforms updated control libraries to reflect PoF refresh language. That helps organize evidence — it does not replace control operation. Neutral automation cost framing: /costs/soc-2/with-automation.
How to use ComplianceBase for CC depth
- Framework hub: /frameworks/soc-2
- Full Security CC set (33 controls): browse from hub or start at CC1.1
- Cost and timeline heuristics: /tools/soc-2-cost-calculator, /tools/soc-2-timeline-calculator
- What auditors do in Type II fieldwork: /blog/what-auditor-does-soc-2-type-ii
Disclaimer: Educational only — not legal advice or an audit opinion. Prefer AICPA primary text when resolving criterion wording; your CPA firm’s engagement letter governs examination procedures.