Skip to content
compliancebase

SOC 2 Common Criteria Changes: What the 2022 Points of Focus Update Actually Changed

June 12, 2026 · ComplianceBase Editorial, Independent security compliance reference editors; frameworks cited to primary sources (AICPA TSC, ISO/IEC 27001, GDPR, HIPAA)

A practical read on the 2022 Revised Points of Focus for the 2017 Trust Services Criteria — what changed for SaaS evidence, and what did not.

The AICPA’s 2017 Trust Services Criteria remain the examination criteria for SOC 2. In 2022, AICPA published Revised Points of Focus — guidance that clarifies how examiners and management think about control design and evidence. The criteria identifiers (CC1–CC9 and category criteria) did not become a brand-new framework; the update sharpened expectations.

What did not change

  • You still need a system description, suitable controls, and — for Type II — operating effectiveness over a period.
  • Security remains the baseline category; Availability, Confidentiality, Processing Integrity, and Privacy are additive.
  • A SOC 2 report is still an attestation, not a certification badge.

Primary source: AICPA Trust Services Criteria with 2022 Revised Points of Focus.

What teams feel in practice

Points of Focus call out themes SaaS auditors already sampled aggressively:

  • Logical access inventories that include service accounts and admin planes (CC6.1)
  • Change linkage from ticket → commit → deploy (CC8.1)
  • Detection and response that is more than a dusty IR PDF (CC7 family)

If your program was already evidence-driven, the 2022 refresh is documentation hygiene. If you were checklist-shopping, PoF language makes weak operating evidence harder to hide.

How to use this on ComplianceBase

Disclaimer: Educational only — not legal advice or an audit opinion. Prefer AICPA primary text when resolving criterion wording.