SOC 2 Common Criteria Changes: What the 2022 Points of Focus Update Actually Changed
A practical read on the 2022 Revised Points of Focus for the 2017 Trust Services Criteria — what changed for SaaS evidence, and what did not.
The AICPA’s 2017 Trust Services Criteria remain the examination criteria for SOC 2. In 2022, AICPA published Revised Points of Focus — guidance that clarifies how examiners and management think about control design and evidence. The criteria identifiers (CC1–CC9 and category criteria) did not become a brand-new framework; the update sharpened expectations.
What did not change
- You still need a system description, suitable controls, and — for Type II — operating effectiveness over a period.
- Security remains the baseline category; Availability, Confidentiality, Processing Integrity, and Privacy are additive.
- A SOC 2 report is still an attestation, not a certification badge.
Primary source: AICPA Trust Services Criteria with 2022 Revised Points of Focus.
What teams feel in practice
Points of Focus call out themes SaaS auditors already sampled aggressively:
- Logical access inventories that include service accounts and admin planes (CC6.1)
- Change linkage from ticket → commit → deploy (CC8.1)
- Detection and response that is more than a dusty IR PDF (CC7 family)
If your program was already evidence-driven, the 2022 refresh is documentation hygiene. If you were checklist-shopping, PoF language makes weak operating evidence harder to hide.
How to use this on ComplianceBase
- Hub: /frameworks/soc-2
- Type I vs II: /compare/soc-2-type-1-vs-type-2
- Cost/timeline heuristics: /tools/soc-2-cost-calculator, /tools/soc-2-timeline-calculator
Disclaimer: Educational only — not legal advice or an audit opinion. Prefer AICPA primary text when resolving criterion wording.