59% of AICPA SOC 3 you already have
SOC 2 already covers about 59% of AICPA SOC 3, leaving
9 of 22 controls as genuinely new work.
Already covered 13
Likely covered 0
New work 9
What is genuinely new work
Nothing in SOC 2 reaches these. This is the list to scope.
SOC3-AUDITOR-OPINIONAuditor Opinion
SOC3-BOUNDARYSystem Boundary
SOC3-DATA-PROTECTData Protection
SOC3-MARKETING-USEMarketing and Distribution
SOC3-MGMT-ASSERTManagement Assertion
SOC3-PERIODReporting Period
SOC3-PURPOSEGeneral Use Trust Services Report
SOC3-SECURITYCommon Criteria Security
SOC3-TSCTrust Services Criteria Coverage
Show the 13 you already have
SOC3-AVAILABILITYAvailability Criteria
SOC3-CHANGE-MGTChange Management
SOC3-CONFIDConfidentiality
SOC3-CONTROL-ENVControl Environment
SOC3-INCIDENT-MGTIncident Response
SOC3-LOGICAL-ACCESSLogical Access
SOC3-MONITORINGMonitoring Controls
SOC3-PRIVACYPrivacy Criteria
SOC3-PROC-INTEGProcessing Integrity
SOC3-RISK-ASSESSRisk Assessment Process
SOC3-VENDORVendor and Subservice Management
SOC3-VULN-MGTVulnerability Management
How this is calculated
Already covered means a mapping runs from a control in SOC 2 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition