SOC Cheat Sheet 2026

The 30 highest-yield SOC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

  1. When reporting on the Processing Integrity trust service criterion, which data quality dimension is most directly assessed? Accuracy, completeness, and timeliness of data processing
  2. In SOC practice, what is a needs assessment? A systematic process to identify gaps between current conditions and desired outcomes
  3. What is the purpose of 'walkthrough procedures' in a SOC audit? To confirm that the auditor's understanding of controls matches how they actually operate
  4. Which of the following is a characteristic of 'sufficient' audit evidence under attestation standards? There is enough of it to support the auditor's conclusion
  5. Which digital tool would an auditor most likely review to evaluate a service organization's change management controls? A ticketing system with change request records and approvals
  6. A SOC 2 report's distribution list is restricted to which parties? Existing user entities, prospective user entities with a signed NDA, and their auditors
  7. For a SOC 2 engagement, management of the service organization is responsible for: Preparing the description of the system and providing a written assertion
  8. Which party is responsible for preparing the system description included in a SOC 2 report? Management of the service organization
  9. Which phase comes immediately after evidence gathering in an audit process? Evaluation and reporting
  10. Which COSO framework component is concerned with identifying and analyzing risks to the achievement of organizational objectives? Risk Assessment
  11. Which of the following is an example of a preventive control for information security? Requiring multi-factor authentication before system access
  12. When an auditor traces a transaction from its origination through the system to the final record, this technique is called: Tracing
  13. What does MTTR measure in the context of disaster recovery and system reliability? The average time required to restore a failed system to normal operation
  14. Under CC3.2, an entity is required to analyze risks considering which two dimensions? Likelihood and impact
  15. Which standard governs the performance of a SOC 2 engagement by a CPA firm? SSAE No. 18 AT-C Section 205
  16. In SOC practice, what is a corrective action plan? A documented strategy to address identified compliance deficiencies and prevent recurrence
  17. Which concept best describes the process of identifying improvements to controls based on lessons learned from prior SOC audit cycles? Root cause analysis and remediation tracking
  18. Which AICPA standard governs the performance of SOC 1 engagements? SSAE No. 18 (AT-C Section 320)
  19. Which risk response strategy involves shifting the financial consequences of a risk to a third party, such as through insurance? Risk sharing
  20. Which metric is most relevant when analyzing the effectiveness of an access control related to SOC 2 Security criteria? Rate of unauthorized access attempts that were successfully blocked
  21. A cloud service provider uses infrastructure-as-code (IaC) tools for system deployments. How does this practice support SOC 2 compliance? It enforces consistent, auditable, and repeatable environment configurations
  22. A project team building a SOC compliance roadmap uses a work breakdown structure (WBS). What does the WBS primarily provide? A hierarchical decomposition of project deliverables into manageable components
  23. Which of the following best describes a 'residual risk' in a SOC audit context? The risk that remains after controls have been applied
  24. In a SOC engagement, 'inherent risk' refers to risk: Before considering any controls or risk responses
  25. In SOC practice, what is the purpose of a standard operating procedure (SOP)? To document step-by-step instructions for routine tasks to ensure consistency and quality
  26. Which of the following is an example of a 'logical access' control that would commonly appear as a control objective in a SOC 2 Security category? Multi-factor authentication for system logins
  27. Which risk response strategy is most appropriate when the cost of mitigating a project risk exceeds the potential impact? Accept
  28. When assessing fraud risk under SOC 2, which COSO component does the service organization primarily address? Risk Assessment
  29. What is the primary goal of access control in information security? Restrict unauthorized access
  30. Which Trust Services Criteria category is MANDATORY for every SOC 2 engagement? Security (Common Criteria)
Turn these facts into recall:
Was this helpful?