The Field Reference Built for SOC 2 Practitioners — Not the Organizations Being Audited Every SOC 2 guide on the market is written for the company trying to get certified. This one is written for the people conducting the examination. The SOC 2 Audit Field Guide: Practitioner Edition covers all 64 Trust Services Criteria across all five trust services categories — organized the way an auditor thinks, not the way the standard reads. Every criterion page gives you what the criterion is actually testing for, what satisfied looks like in a real service organization environment, exactly what evidence to gather for Type I and Type II, and the common deficiencies that show up repeatedly across engagements. What's Inside Every Criterion Page Plain-language explanation — what the criterion requires beyond the TSC statement Key Points of Focus — the 2022 revised points of focus that help evaluate control design and effectiveness What Satisfied Looks Like — observable, verifiable conditions, not policy statements Evidence to Gather — specific artifacts for Type I design testing and Type II operating effectiveness, clearly distinguished Common Deficiencies — the gaps that actually show up, with risk significance ratings Auditor Notes — field-tested evaluation techniques and judgment guidance Complete Coverage — All 5 Trust Services Categories Security (Common Criteria) — CC1 through CC9: Control environment, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation (33 criteria) Availability — A1: Capacity management, environmental protections, and recovery plan testing (3 criteria) Processing Integrity — PI1: Completeness, accuracy, timeliness, authorization, and output delivery (5 criteria) Confidentiality — C1: Confidential information identification, handling, and disposal (2 criteria) Privacy — P1–P8: Notice, consent, collection, use, access, disclosure, quality, and enforcement (20+ criteria) Six Practitioner Supplements How to Use This Guide — including Type I vs. Type II distinctions and how the five categories differ Quick Reference — criteria counts, highest-risk criteria by finding rate, testing approach by control type Scoping and Planning Reference — system definition, in-scope vs. out-of-scope, subservice organizations SOC 2 Reporting Guide — report structure, opinion types, exceptions vs. deficiencies, CUECs and CSOCs Common Findings Reference — the most frequently observed deficiencies organized by category Glossary — 20+ SOC 2 program terms including Type I, Type II, CUECs, CSOCs, and carve-out method Written for CPA practitioners, internal auditors, and security professionals conducting or preparing for SOC 2 Type I and Type II examinations. Based on the 2017 AICPA Trust Services Criteria with 2022 revised points of focus.