Latest SOC 2 Updates: Vendor Risk, Monitoring, and Confidentiality

No new version of the SOC 2 framework has been issued for 2026. The AICPA’s 2017 Trust Services Criteria, with the 2022 revised points of focus, remain in effect, and the description criteria in DC Section 200 still govern the system description.1AICPA & CIMA. 2017 Trust Services Criteria (With Revised Points of Focus – 2022) What is changing heading into 2026 sits in practice rather than in the rulebook: auditors are looking harder at vendor and supply-chain risk, continuous monitoring is displacing point-in-time evidence, and confidentiality is showing up in far more reports than it did two years ago. If you are planning a SOC 2 examination for the coming cycle, the relevant SOC 2 updates for 2026 are shifts in auditor expectation and scope, not a new set of criteria to memorize.

What the Framework Still Says

The Trust Services Criteria are designated as TSP Section 100 and cover five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.1AICPA & CIMA. 2017 Trust Services Criteria (With Revised Points of Focus – 2022) Security is mandatory in every report. The other four are chosen based on the services you deliver and the commitments you make to customers. The criteria are built on the seventeen COSO Internal Control Framework principles, and the common criteria within Security are grouped as CC1 through CC9, covering control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation.

The 2022 revisions updated the points of focus rather than the criteria themselves. Points of focus are interpretive examples, not mandatory requirements, but auditors rely on them heavily. The updates addressed cloud shared-responsibility models, remote work and endpoint security, modern authentication such as multi-factor and VPN use, and expectations that service level agreements with cloud providers contain security requirements aligned with your own standards. The description criteria in DC Section 200 also received revised implementation guidance in 2022.2AICPA & CIMA. 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022) Those revisions still set the bar going into 2026.

Vendor and Supply-Chain Risk

Subservice organizations have always been in scope, but they are getting far more auditor attention now. A significant majority of current SOC 2 reports include subservice providers in the system description, reflecting how dependent service organizations have become on third-party infrastructure. When a vendor of yours suffers a breach, your customers will read your SOC 2 report looking for the controls that were supposed to catch it. Updated audit guidance clarifies how to define system boundaries when third-party applications are involved and pushes harder on controls for assessing and monitoring vendor risk.

You handle subservice providers in a report using one of two methods. The carve-out method names the subservice organization, excludes its controls from your report, and describes how you monitor the relationship. The inclusive method incorporates the subservice organization’s controls directly into your report but requires a written assertion from that provider. Most organizations use the carve-out method because obtaining an assertion from a large cloud provider is not practical. Either way, expect the auditor to test how you vet vendors, how you track their security posture over time, and what your SLAs actually require of them.

Continuous Monitoring Replacing Point-in-Time Evidence

The traditional SOC 2 workflow, gathering screenshots and log exports in the weeks before fieldwork, is being replaced by continuous monitoring. Automated tools connect to your cloud infrastructure, identity providers, and endpoint management systems and verify control operation on a daily or hourly basis. Auditors increasingly request evidence of ongoing compliance rather than snapshots assembled for the audit window.

The practical value is speed of detection. Under the older model, a terminated employee who retained access to a production system might not be caught until the next annual review, producing an exception. Automated monitoring flags the same issue within hours, and the timestamped record showing same-day remediation becomes evidence in itself. That compresses the exposure window and reduces the likelihood of findings that could push you toward a qualified opinion. If you are still assembling evidence manually, going into 2026 is a reasonable point to reassess whether that workflow can carry another cycle.

Confidentiality Showing Up in More Reports

Confidentiality is now included in roughly two-thirds of SOC 2 reports, up from about a third two years earlier. Customers increasingly want to see that a service provider has explicit controls around how confidential data is classified, restricted, and disposed of, rather than treating those questions as subsumed under Security. If your last SOC 2 covered only Security, look at what your enterprise customers are asking in their vendor questionnaires. If confidentiality controls keep coming up as follow-up questions, adding the category to your next examination will likely serve you better than answering the same questions ad hoc.

How to Adjust Your Audit Preparation

The formal audit engagement is governed by SSAE 18, specifically AT-C Section 205 for examination engagements, but most of the work sits with your team in the months before fieldwork. The system description under DC Section 200 remains the foundational document.2AICPA & CIMA. 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022) It must describe the services you provide, how data flows through your systems, the principal commitments you make to users, and clear system boundaries covering people, processes, infrastructure, and software in scope. It has to be relevant, objective, measurable, and complete. Completeness is where organizations stumble: leaving out a significant system component or failing to disclose a subservice organization creates a scope problem the auditor will catch during fieldwork.

Given where auditor attention is moving, three preparation shifts matter for a 2026 cycle. First, revisit your subservice organization inventory and confirm the system description names each one, states the method you use (carve-out or inclusive), and describes the monitoring controls you rely on. Second, if you have not moved toward continuous evidence collection, at least map which controls could reasonably be automated and which will still require sampled manual evidence from across the observation period. For a Type 2 engagement the auditor will pull change management tickets, access review records, and incident logs from multiple months, not a single date.3AICPA & CIMA. System and Organization Controls: SOC Suite of Services Third, decide whether Confidentiality belongs in your trust categories this cycle. Adding it mid-engagement is not workable; the decision needs to happen before the observation period starts.

Management’s written assertion is not a formality. It is a signed declaration that the system description is fairly presented and that controls were suitably designed (Type 1) or both designed and operating effectively over the period (Type 2). It becomes part of the final report, and inaccuracies in it undermine the engagement.

Exceptions, Opinions, and What Tighter Scrutiny Means

Finding exceptions does not mean the engagement failed. An exception is a deviation from expected results when the auditor tests a specific control. A single late access review out of twelve monthly reviews will not automatically produce a qualified opinion; the auditor evaluates whether the exception is isolated or systemic, and whether compensating controls address the underlying risk.

Where the shift toward continuous monitoring and closer vendor scrutiny lands is in the volume and pattern of exceptions. Point-in-time evidence tends to hide small failures until the annual review surfaces them together, which is exactly the pattern that pushes an opinion from unqualified to qualified. Automated monitoring surfaces those failures individually, with a remediation record attached, which is a very different story for the auditor to read.

After testing, the auditor issues one of four opinions:

  • Unqualified: controls were designed and operating effectively.
  • Qualified: most criteria were met, but one or more controls fell short of specific requirements.
  • Adverse: controls failed to meet criteria in a way that is material and pervasive.
  • Disclaimer: the auditor could not obtain sufficient evidence to form an opinion.

When exceptions are confirmed, you draft a management response acknowledging the issue, stating the root cause, and describing the corrective action with a remediation timeline. That response is published in the report alongside the exception, so specificity matters. “We implemented automated access review reminders on [date] and assigned quarterly validation to [role]” reads very differently to a customer than “we will improve our process.” A qualified opinion signals compliance gaps to customers, and their auditors may be unable to rely on your controls without additional testing of their own. In finance or healthcare, that can trigger regulator scrutiny as well.

Report Validity and Bridge Letters

A SOC 2 report does not technically expire, but industry practice treats it as current for twelve months from the end of the reporting period. Most organizations run their Type 2 audit annually and time issuance so the new report lands before the previous one goes stale. Final reports are usually delivered within thirty to sixty days after fieldwork concludes, and they are restricted-use documents intended for your organization, current and prospective customers, their auditors, business partners subject to risks from your system, and regulators with sufficient knowledge of the subject matter. A SOC 3 report is the general-use, shareable version if you need something for marketing.

Gaps between reporting periods, or between your report’s end date and a customer’s fiscal year-end, are covered by a bridge letter. In it, management states that no material changes have occurred to the control environment since the report period ended, or describes any changes and their impact. Bridge letters should not stretch past about three months. If the gap is longer than that, a new audit is the appropriate path rather than a longer letter.

One Boundary Worth Naming

SOC 2 is not required by law. No federal statute or industry regulation mandates a report. Compliance is market-driven: customers, procurement teams, and enterprise partners request it as proof that a service provider handles data responsibly. That matters for how you interpret the 2026 shifts. Tighter auditor expectations are not being imposed by a regulator; they are being pulled through by what customers want to see in the reports they read. Treating those expectations as optional is possible, but the practical result shows up in stalled enterprise sales and vendor questionnaires you cannot answer cleanly.