AICPA Advances 2026 Attestation Changes for SOC 2
Updated:
August 26, 2026
AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22, 2026.
The ASB issued its main exposure draft on February 26, 2026 and a related conforming-amendments draft in March. Public comments closed on June 30, 2026, with 23 responses submitted. AICPA now lists the project at the “Discuss Comment Letters” stage following its August 2026 deliberations.
What Did AICPA Advance In Its 2026 Attestation Standards Project?
AICPA advanced a broad revision of its attestation standards that would update the common rules practitioners use across examination and review engagements. The project is intended to address newer assurance subjects, reduce inconsistent practices and update baseline requirements that have become increasingly important as attest work expands beyond traditional financial information.
The ASB released two connected exposure drafts. The February proposal revises common concepts, examination engagements and review engagements while creating new provisions for sustainability assurance. The March proposal makes conforming changes across other AT-C sections so those standards work with the revised baseline structure.
AICPA’s current project page shows that the exposure-draft phase has ended. The ASB discussed comment letters in August 2026, moving the project one stage closer to a possible final standard. Final approval has not occurred.
Has AICPA Finalized The 2026 Attestation Changes?
AICPA has not finalized the 2026 attestation changes. The proposals remain under ASB review after the June 30, 2026 comment deadline, and AICPA currently classifies the project as being in the “Discuss Comment Letters” stage rather than the “Final Standard” stage.
That distinction is important for SOC 2 teams. Organizations do not have a new 2026 SOC 2 requirement to implement from these exposure drafts today. The ASB can revise, remove or clarify provisions after considering stakeholder comments before voting on final standards.
The comment process produced 23 responses from accounting firms, professional associations and government audit organizations. Respondents included PwC, KPMG, EY, Grant Thornton, RSM, Deloitte, BDO, the Government Accountability Office, the Defense Contract Audit Agency and the National Association of State Boards of Accountancy.
Why Could The 2026 Attestation Changes Affect SOC 2?
The 2026 proposals could affect SOC 2 because SOC 2 is an assertion-based examination performed under AICPA attestation standards. AICPA describes a SOC 2 engagement as an examination of a service organization’s system description and controls relevant to security, availability, processing integrity, confidentiality or privacy.
AICPA’s attestation standards use a building-block structure. AT-C section 105 provides concepts that apply across attestation engagements, while the 200-series standards provide requirements based on the level of service. Proposed AT-C section 205 governs assertion-based examination engagements.
That connection means revisions to the baseline examination standards can flow into the methodology CPA firms use for SOC 2 work, even though the exposure drafts are not written as a standalone SOC 2 update. The underlying SOC 2 reporting framework still determines how a service organization’s system and relevant controls are presented for examination.
Which Attestation Sections Would AICPA Change?
The February 2026 exposure draft proposes revisions to three baseline AT-C sections and introduces two sustainability-specific sections. The March proposal contains conforming amendments to several existing sections.

AT-C 105 is particularly significant since AICPA states that it applies to all attestation engagements. The proposed AT-C 205 revisions are more directly relevant to reasonable-assurance examination work.
The conforming amendments include AT-C 320, which covers examinations of service-organization controls relevant to user entities’ internal control over financial reporting. That section should not be confused with the Trust Services Criteria used for SOC 2. The broader SOC 2 implication comes from changes to the baseline attestation and examination standards.
How Could The Proposed Rules Change SOC 2 Examination Work?
The proposed rules could change SOC 2 examination work through more detailed requirements for evidence evaluation and examination risk assessment. AICPA proposes bringing parts of AT-C 205 closer to the evidence principles used under AU-C 500 when practitioners perform comparable procedures.
Proposed AT-C 205 addresses the relevance and reliability of information used as evidence. It contains provisions concerning information prepared with a management specialist and information reported on by another individual. The proposal is intended to create greater consistency in what practitioners treat as evidence during attestation work.
The examination provisions would strengthen risk-assessment procedures as well. Practitioners would perform procedures at the level appropriate to the subject matter and consider fraud, suspected fraud and noncompliance or suspected noncompliance with laws or regulations that affect the subject matter.
For SOC 2 programs, the practical effect could be greater attention to the quality, completeness and reliability of evidence supporting control operation. Organizations with clearly documented SOC 2 controls and supporting evidence may be better positioned when auditor methodologies place greater emphasis on the reliability of information used during examination procedures.
The final requirements may differ from the exposure draft, so these potential SOC 2 effects should be treated as preparation considerations rather than current audit obligations.
Do The 2026 Proposals Change The SOC 2 Trust Services Criteria?
The 2026 attestation proposals do not currently replace or revise the SOC 2 Trust Services Criteria. AICPA continues to publish the 2017 Trust Services Criteria with revised points of focus from 2022 for Security, Availability, Processing Integrity, Confidentiality and Privacy.
The distinction separates two parts of SOC 2. The SOC 2 Trust Services Criteria define the criteria against which relevant controls are evaluated, while the attestation standards govern how the CPA practitioner performs and reports on the examination.
A company therefore should not interpret the 2026 exposure drafts as a new list of SOC 2 controls or new Trust Services Criteria. Changes to examination methodology can affect how evidence is evaluated without changing the underlying criteria used to assess the control environment.
How Could SOC 2 Type I And Type II Reports Be Affected?
Both SOC 2 Type I and Type II examinations could eventually be affected by revisions to the baseline examination standards, while the operational effect may be more visible during evidence-intensive Type II engagements. The proposed rules focus on practitioner evidence evaluation and risk assessment rather than creating a new SOC 2 report category.
A Type I report evaluates control design and implementation at a specified date. A Type II report extends the examination to the operating effectiveness of controls throughout a defined period. The difference between SOC 2 Type I and Type II reports becomes particularly relevant when changes concern evidence reliability, since Type II testing relies on records generated throughout the examination period.
Changes in practitioner evidence requirements could therefore influence populations, logs, tickets, access reviews, approvals and other records requested during either examination. Type II engagements may experience a larger practical effect where auditors need to evaluate evidence collected across several months.
When Would The New AICPA Attestation Standards Take Effect?
The proposed AICPA attestation standards would take effect for engagements beginning on or after June 15, 2029 under the exposure-draft timetable. That date remains proposed and depends on the ASB issuing final standards.
The drafts permit early implementation under specific dependencies. A practitioner adopting a revised 200-series section early would need to implement revised AT-C 105 at the same time. Early adoption of a new or revised 300-series section would require adoption of the other proposed AT-C sections applicable to that engagement.
The long implementation window means SOC 2 organizations do not need to redesign programs in 2026 solely in response to these proposals. The nearer-term priority is tracking the final standard and understanding whether CPA firms begin adjusting methodologies ahead of the mandatory date.
Do The Proposals Create New Legal Requirements For SOC 2 Organizations?
The AICPA exposure drafts do not create a new government compliance mandate or statutory penalty for companies seeking SOC 2 reports. They are proposed professional attestation standards governing practitioner engagements rather than a new federal cybersecurity regulation.
Their business effect can still reach service organizations indirectly. A final change to examination methodology can influence evidence requests, audit planning, documentation expectations and conversations between management and the CPA firm.
Customer contracts and vendor-security requirements may create separate SOC 2 obligations for individual companies. Those commercial requirements are distinct from the ASB’s professional-standard-setting process.
What Should SOC 2 Teams Do About The Proposed 2026 Changes?
SOC 2 teams should monitor the ASB project while strengthening evidence practices that support the current Trust Services Criteria. Preparing around evidence quality and control ownership offers value under existing SOC 2 examinations without treating an exposure draft as a final requirement.

- Track the ASB project status. Monitor whether the board changes the proposals after reviewing the 23 comment responses and when a final SSAE is approved.
- Keep control ownership current. Assign clear owners for controls, evidence collection, remediation and management review.
- Review evidence quality. Confirm that logs, tickets, reports and system-generated records can be traced to the control being tested and cover the required examination period.
- Document evidence sources. Record where evidence originates, who produces it and how completeness or accuracy is checked when those factors are relevant.
- Review examination scope with the CPA firm. Discuss methodology changes before the next reporting cycle when the ASB publishes final standards or auditors begin implementation planning.
- Keep changes versioned. Maintain records showing significant changes to systems, controls, policies and evidence processes during the reporting period.
- Avoid treating the exposure draft as a new control framework. Continue designing the SOC 2 program around the applicable Trust Services Criteria until AICPA publishes a final change affecting those criteria.
How Did Accounting Firms And Government Reviewers Respond?
The ASB received 23 responses to its February and March exposure drafts before the June 30 deadline. The response group included major accounting firms, state CPA societies, government audit organizations and professional bodies, giving the ASB feedback from several parts of the attestation profession.
PwC, KPMG, EY, Grant Thornton, RSM, Deloitte, BDO and CliftonLarsonAllen submitted responses. Government-related respondents included the GAO and Defense Contract Audit Agency, while NASBA submitted feedback from the state-accountancy oversight perspective.
The GAO submitted a dedicated June 30, 2026 letter addressing both the main proposed SSAE and the conforming-amendments proposal. AICPA is now considering this feedback and the other comment letters as part of its August 2026 deliberation stage.
No final disposition of the major comment issues has been published in the project status information reviewed as of August 22, 2026.
What Other AICPA Attestation Changes Are Happening In 2026?
A separate AICPA ethics development will change the definition of an “attest engagement team” for engagements beginning on or after December 15, 2026. The Professional Ethics Executive Committee adopted the revised definition in August, with early implementation permitted.
The revised definition explicitly excludes internal auditors, auditor external specialists, practitioner external specialists, referred-to auditors and referred-to practitioners from the attest engagement team. The definition affects how firms apply independence and related ethics requirements.
This PEEC action is separate from the ASB’s proposed revisions to AT-C 105, 205 and 210. The two developments show that AICPA’s 2026 work on attest engagements extends across professional standards and ethics, but they should not be presented as one rulemaking action.
What Costs And Business Risks Could Follow From The Attestation Changes?
The proposed attestation changes could increase preparation work where CPA firms require stronger support for evidence, risk assessments or information used during SOC 2 testing. AICPA has not published a SOC 2 cost estimate tied to the exposure drafts, and the standards remain unfinished.
CPA firms may need to update methodologies, training, templates and practice aids after a final standard is issued. Service organizations could face corresponding changes in audit requests, evidence review and pre-examination discussions.
The largest risk for companies is premature implementation of requirements that may change before final approval. Maintaining clear control ownership, reliable evidence and an accurate system description is more durable than redesigning a program around an unfinished exposure draft.
Changes in testing scope or evidence requirements could eventually affect SOC 2 audit costs, particularly where examinations require additional practitioner time or more extensive evidence preparation. No such cost increase has been quantified by AICPA for the proposed 2026 standards.
What Remains Unclear About The AICPA 2026 Attestation Changes?
The biggest unresolved issue is the final wording of the revised AT-C standards. The ASB is still reviewing comment letters, so provisions concerning evidence, risk assessment, reporting and related subjects can change before issuance.
A second uncertainty is the exact operational effect on SOC 2 examinations. The proposals revise standards that sit beneath many assertion-based examination engagements, but AICPA has not announced a separate 2026 rewrite of the SOC 2 Trust Services Criteria.
A third issue is implementation guidance. A final standard could lead to revisions of AICPA guides, illustrative reports, firm methodologies or other materials used in SOC engagements. The extent and timing of those downstream updates remain unknown.
The proposed June 15, 2029 effective date remains another point to watch. A final standard, transition provisions and implementation timetable need to be confirmed before organizations treat that date as fixed.
How Bright Defense Helps Organizations Prepare For SOC 2 Changes
Bright Defense helps organizations maintain SOC 2 programs built around clear control ownership, documented evidence, remediation and continuous security operations. The current AICPA proposals reinforce the value of maintaining evidence that accurately demonstrates how controls are designed and how they operate.
Organizations do not need to rebuild their SOC 2 programs around an unfinished exposure draft. A stronger approach is to keep the current program audit-ready, follow AICPA’s final decisions and update examination preparation when the revised standards and implementation guidance are confirmed.
Sources Cited In Article
- AICPA & CIMA — ASB Project: Attestation Standards: ESG-Sustainability (current project status, August 2026).
- AICPA & CIMA — Summary Of Comments On Proposed SSAEs On Attest And Sustainability (July 20, 2026).
- Journal of Accountancy — Proposed Attestation Changes: What CPAs Should Know (April 24, 2026).
- Journal of Accountancy — Proposed Revisions To Examination And Review Engagements In The Attestation Standards (May 6, 2026).
- AICPA & CIMA — AICPA Exposure Drafts Of Proposed SASs, SSAEs And SQMSs (2026 exposure-draft record).
- AICPA & CIMA — SOC 2 Reporting On An Examination Of Controls At A Service Organization Relevant To Security, Availability, Processing Integrity, Confidentiality Or Privacy.
- AICPA & CIMA — 2017 Trust Services Criteria With Revised Points Of Focus, 2022.
- U.S. Government Accountability Office — June 30, 2026 Letter On AICPA Attestation Exposure Drafts (June 30, 2026, publicly released July 2, 2026).
- Journal of Accountancy — PEEC Adopts Revised Definition Of “Attest Engagement Team” (August 17, 2026).


