Skip to Content

Tevora Ranks No. 12 on Fast Company's Annual List of the 100 Best Workplaces for Innovators Read Press Release

Dark teal and black gradient

Blog

SOC 2 Updates: What We Know and What We Don’t Know Yet About the Next SOC 2 Changes

SOC 2 has become one of the most important trust signals for SaaS companies, technology providers, and organizations handling customer data. 

So naturally, when people hear that SOC 2 is being updated, the questions start coming quickly: 

  • What is changing? 
  • When will the new SOC 2 requirements take effect? 
  • Will our existing controls still satisfy the standard? 
  • Will we need to change our SOC 2 audit scope? 
  • What will auditors expect from us? 
  • And perhaps most importantly: Do we need to do anything right now? 

The short answer is there are good reasons to pay attention to where SOC 2 is heading, but there is no reason to make major changes based on speculation. Until the AICPA provides firm guidance, dive into our blog to understand what we know, what we don’t know, and what the potential changes could mean for your organization. 

As of August 2026, the AICPA’s published Trust Services Criteria remain the 2017 Trust Services Criteria with Revised Points of Focus—2022. The AICPA also continues to reference the 2018 SOC 2 Description Criteria with Revised Implementation Guidance—2022. 

That means there is not currently a new, officially released set of “SOC 2 2026 requirements” that organizations should immediately rebuild their compliance programs around. However, that doesn’t mean SOC 2 is standing still. 

In this article, we’ll separate what we knowwhat we don’t know yet, and what organizations can do today to prepare for the next evolution of SOC 2. 

The Current State of SOC 2 

Before looking ahead, it’s important to establish where SOC 2 actually stands today. 

SOC 2 examinations evaluate controls related to five Trust Services Categories: 

  • Security 
  • Availability 
  • Processing Integrity 
  • Confidentiality 
  • Privacy 

Security is the foundational criterion for a SOC 2 examination, while the other categories can be included depending on the services an organization provides, its commitments, and the needs of its customers. 

The current framework is based on the AICPA’s 2017 Trust Services Criteria, incorporating revised Points of Focus published for 2022. 

The AICPA’s SOC 2 guidance was also updated to reflect changes in professional standards and implementation guidance, including guidance related to the revised Trust Services Criteria and the revised Description Criteria. 

When we talk about the “next SOC 2 update,” we’re talking about a potential future evolution of this framework, not a currently published replacement that organizations need to implement today. 

What We Know About the Next SOC 2 Updates 

1. SOC 2 will continue evolving with the technology landscape 

This may sound obvious, but it’s important. The technology environment SOC 2 evaluates has changed significantly since the current criteria were established. 

Organizations today rely on: 

  • Artificial intelligence and generative AI 
  • Cloud-native infrastructure 
  • Infrastructure-as-code 
  • SaaS-heavy technology stacks 
  • Automated development pipelines 
  • APIs and interconnected platforms 
  • Remote and distributed workforces 
  • Managed service providers 
  • Complex third-party ecosystems 
  • Continuous deployment 
  • Machine learning systems 
  • Increasingly automated security operations 

The underlying risks associated with these technologies are different from the risks organizations faced when many of the current SOC 2 concepts were originally developed. That creates pressure for compliance frameworks to evolve alongside them. 

However, the existence of new technology does not automatically mean the AICPA has announced a new SOC 2 requirement for that technology. 

2. Third-party risk is becoming increasingly important 

Modern organizations rarely operate entirely within their own environment. 

A typical SaaS company may rely on cloud infrastructure providers, identity platforms, payment processors, monitoring tools, HR systems, AI providers, data processors, and dozens of other vendors. 

That creates a fundamental question: How much of your security posture depends on organizations outside your direct control? 

Third-party risk is already relevant to SOC 2. Organizations need to understand the systems and services that support their operations and consider how those dependencies affect their control environment. 

The direction of travel is clear: vendor risk, supply-chain risk, and dependency management are becoming increasingly difficult to treat as secondary compliance considerations. 

That does not mean a future SOC 2 update will necessarily introduce a brand-new “third-party risk” criterion. It does mean organizations should expect greater scrutiny around how they identify, assess, monitor, and manage critical dependencies. 

What We Don’t Know Yet about SOC 2 Changes to come 

There is a difference between reasonable predictions and official requirements. 

1. We don’t know the exact timing of the next major SOC 2 criteria update 

Organizations should be cautious about claims that a specific future date represents the mandatory transition date for a new SOC 2 framework unless that date is supported by an official AICPA publication. The current AICPA materials continue to identify the 2017 Trust Services Criteria with Revised Points of Focus—2022 as the applicable criteria. 

Until the AICPA publishes new criteria and associated transition guidance, organizations should not make major compliance decisions based solely on predictions about when a new version will arrive. 

2. We don’t know exactly what new SOC 2 criteria will look like 

There is plenty of speculation about what future SOC 2 requirements could include. Potential areas of increased emphasis could include: 

  • Artificial intelligence governance 
  • AI security and privacy 
  • Software supply-chain security 
  • Continuous control monitoring 
  • Automated evidence collection 
  • Third-party and fourth-party risk 
  • Cloud security 
  • Identity and access management 
  • Data lineage 
  • Resilience and operational recovery 
  • Secure software development 
  • Automated change management 

These are all reasonable areas to watch. Until the AICPA publishes proposed or final changes, organizations should treat these areas as risk and preparedness considerations. 

3. We don’t know yet how the transition will work. But Tevora will be there to guide you. 

One of the biggest unanswered questions is how the transition to any future SOC 2 framework will actually work. Until the AICPA publishes firm guidance, there is still a lot that remains to be determined, including when changes will take effect, how the transition will work, and what organizations will ultimately need to do. For now, the most helpful approach is to stay informed, continue following the current criteria, and look to your audit partner for guidance as more information becomes available. 

There are still important questions to be answered, including: 

  • Will there be a transition period? 
  • Will existing SOC 2 reports remain valid? 
  • When will audits begin using any updated criteria? 
  • Will organizations be able to choose between the current and updated criteria during a transition? 
  • How will Type 1 and Type 2 examinations be affected? 
  • How will existing controls map to any updated criteria? 
  • Will additional evidence be required? 
  • Will organizations need to update their system descriptions? 

These questions matter, especially when you’re planning your audit timeline and making decisions about your compliance program. 

This is where having an experienced audit partner matters. As your auditors, our role is to monitor developments closely, interpret official guidance when it becomes available, and help you understand exactly what those changes mean for your organization. 

Once the AICPA provides firm updates, we’ll be there to guide you through the transition, including helping you identify any gaps, understand changes to your existing controls, determine what additional evidence may be needed, and plan your next SOC 2 examination appropriately. In the meantime, the best approach is to continue strengthening your existing controls while staying informed about what may be coming next. 

You don’t need to predict the next SOC 2 framework. You need a partner who will help you understand and navigate the changes when the time comes. 

What Should Companies Do Right Now to Prep for a SOC 2 Update? 

The good news is that you don’t need to rebuild your entire SOC 2 program based on speculation. Instead, focus on building a stronger version of what you already have. 

1. Keep your existing SOC 2 program current 

First, make sure your existing controls are working.  

Review: 

  • Policies 
  • Access controls 
  • Risk assessments 
  • Vendor management 
  • Incident response 
  • Change management 
  • Security awareness 
  • Vulnerability management 
  • Business continuity 
  • Disaster recovery 
  • Evidence collection 

A future SOC 2 update won’t make a mature compliance program obsolete. 

If anything, organizations with strong foundational controls should be better positioned to adapt. 

2. Reviewing your AI usage 

Even if your company isn’t an AI company, there’s a good chance your employees are using AI somewhere in the organization. 

Inventory: 

  • AI applications 
  • AI vendors 
  • AI-enabled SaaS products 
  • Customer data processed by AI tools 
  • Internal AI workflows 
  • AI-generated code 
  • Sensitive information entering AI systems 

Then determine whether your existing security, privacy, and vendor-management controls adequately address those uses. 

For more information on how to improve your existing policies for AI Considerations read our datasheet here.  

3. Strengthening your vendor risk program 

Take a close look at your critical vendors. 

Ask: 

  • Which vendors have access to customer data? 
  • Which vendors are critical to service availability? 
  • Which vendors have privileged access? 
  • Which vendors process sensitive information? 
  • Which vendors use sub processors? 
  • How frequently are vendors reviewed? 
  • What happens when a critical vendor experiences an incident? 

Again, these aren’t necessarily new SOC 2 requirements, but good risk management, and increasingly important as organizations become more dependent on third parties. 

For more information on shielding your organization from the risks of external vendors check out our datasheet here.  

4. Talk to your service auditor 

Your service auditor is one of the best places to get practical guidance about how emerging developments may affect your next examination. 

Ask them: 

  • What changes are you watching? 
  • Are you seeing increased scrutiny in particular control areas? 
  • Are customers asking for additional evidence? 
  • Are there emerging expectations around AI? 
  • Are you seeing changes in third-party risk assessments? 
  • What should we start doing now? 

The Future of SOC 2 Is Likely to Be More Continuous, Not Less 

Even without knowing the exact details of the next SOC 2 update, one trend is difficult to ignore. Security and compliance are becoming increasingly continuous. 

Organizations can’t realistically secure a modern cloud environment by checking it once a year. It can be difficult to manage third-party risk with a spreadsheet that gets updated annually. They can’t meaningfully govern AI by writing a policy and never reviewing how employees actually use AI. 

The organizations best positioned for the future of SOC 2 will likely be those that make security and compliance part of their normal operating model. 

Don’t Wait for the Next SOC 2 Update 

Organizations that will be ahead of the new SOC 2 framework will be improving their compliance program early. The exact next version may not be known yet, but the direction of modern security is clear. 

Organizations should be building programs that are: 

  • Continuous 
  • Risk-based 
  • Automated where possible 
  • Evidence-driven 
  • Cloud-aware 
  • AI-aware 
  • Focused on third-party risk 
  • Integrated into everyday operations 

Final Takeaway 

As of August 2026, the AICPA’s published Trust Services Criteria remain the 2017 criteria with Revised Points of Focus—2022

While organizations should continue to watch for future updates and guidance, there is no need to put security improvements on hold while waiting for the next version of SOC 2. The right approach is to make thoughtful, risk-based improvements that strengthen your security and compliance program today while keeping your organization prepared to adapt to future requirements. 

That means evaluating new technologies, strengthening existing controls, monitoring emerging risks, and making changes in a way that is secure, documented, and aligned with your organization’s needs, even when the future SOC 2 requirements aren’t yet defined. 

When the AICPA provides updated guidance, your existing program should give you a strong foundation to evaluate what’s changed, identify any gaps, and make any necessary adjustments 

Tevora Can Help 

SOC audits are a great way to ensure that an organization’s systems and processes comply with industry standards. However, the audit should be more than just a compliance exercise. It can also give organizations valuable insights into their security posture and help identify potential risks or weaknesses in their controls.  

Organizations should take advantage of this opportunity to meet compliance requirements and improve their security posture. A SOC audit should be seen as an opportunity to review, refine and enhance the organization’s security controls and processes.  

By taking a proactive approach to SOC audits, organizations can ensure compliance and stronger security for their business. Doing so will help build trust with customers, partners and vendors and give them peace of mind that their data is secure. 

If you’re looking for assistance in performing a SOC Audit or Assessment, contact Tevora at (833) 292-1609 or email us at [email protected].  

Authors

Ashli Pfeiffer
Managing Director, Compliance & Audit
Ashli is a Managing Director of the information security consulting and compliance services at Tevora. She manages the practices devoted to SOC compliance, and Information Security or GRC Consulting. 
View Bio   More Posts By This Author