Framework overlap

Does SOC 2 cover AICPA SOC 3?

You hold SOC 2 and have been told to do AICPA SOC 3. Here is how much overlaps, control by control.

59% of AICPA SOC 3 you already have

SOC 2 already covers about 59% of AICPA SOC 3, leaving 9 of 22 controls as genuinely new work.

Already covered 13 Likely covered 0 New work 9

What is genuinely new work

Nothing in SOC 2 reaches these. This is the list to scope.

SOC3-AUDITOR-OPINION
Auditor Opinion
SOC3-BOUNDARY
System Boundary
SOC3-DATA-PROTECT
Data Protection
SOC3-MARKETING-USE
Marketing and Distribution
SOC3-MGMT-ASSERT
Management Assertion
SOC3-PERIOD
Reporting Period
SOC3-PURPOSE
General Use Trust Services Report
SOC3-SECURITY
Common Criteria Security
SOC3-TSC
Trust Services Criteria Coverage
Show the 13 you already have
SOC3-AVAILABILITY
Availability Criteria
SOC3-CHANGE-MGT
Change Management
SOC3-COMMS
Communication
SOC3-CONFID
Confidentiality
SOC3-CONTROL-ENV
Control Environment
SOC3-INCIDENT-MGT
Incident Response
SOC3-LOGICAL-ACCESS
Logical Access
SOC3-MONITORING
Monitoring Controls
SOC3-PRIVACY
Privacy Criteria
SOC3-PROC-INTEG
Processing Integrity
SOC3-RISK-ASSESS
Risk Assessment Process
SOC3-VENDOR
Vendor and Subservice Management
SOC3-VULN-MGT
Vulnerability Management

How this is calculated

Already covered means a mapping runs from a control in SOC 2 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition