What the AICPA’s 2026 Attestation Proposals Mean for SOC 2

October 1, 2026

Written by:

Brad Lyons
Team of professionals during a meeting reviewing papers and computer reports
  • The AICPA’s Auditing Standards Board has proposed revisions to AT-C sections 105, 205, and 210, the attestation standards SOC 2 examinations are performed under.
  • The proposals focus on how practitioners evaluate evidence, how risk assessment accounts for fraud and noncompliance, and how practitioners use information from management’s specialists and other parties.
  • The 2017 Trust Services Criteria are not changing under these proposals.
  • Nothing is final. As proposed, the revised standards would apply to engagements beginning on or after June 15, 2029.

The AICPA’s Auditing Standards Board is revising the attestation standards that SOC 2 examinations are performed under. According to Bright Defense, the board issued an exposure draft on February 26, 2026, proposing revisions to AT-C sections 105, 205, and 210, along with new sections for sustainability reporting. A conforming-amendments draft followed in March, and the comment period closed June 30 with 23 responses.

The Proposals Raise the Bar on Evidence and Risk

Bright Defense reports that the proposals would raise the bar on how practitioners evaluate evidence, aligning those requirements more closely with the evidence principles in AU-C 500. They would also expand risk assessment so practitioners consider fraud and noncompliance that could affect the subject matter. The drafts also clarify how practitioners use information prepared with a management specialist and information another party has reported on.

The Criteria Stay Put While the Examination Work Shifts

For SOC 2 programs, the effect lands on how an examination is done rather than on what gets tested. AT-C 105 sets the baseline for attestation engagements generally, and AT-C 205 governs examination engagements, so changes to either carry into SOC 2 methodology. The 2017 Trust Services Criteria stay in place; Bright Defense notes the 2026 proposals do not replace or revise them. The practical shift is likely to show up in how closely auditors scrutinize the reliability of the evidence they receive, including system-generated reports and third-party SOC reports.

Nothing Is Final, and 2029 Is the Proposed Start

Nothing is final yet. Bright Defense reports the project was still at the “Discuss Comment Letters” stage as of August 22, 2026, and the board deliberated in August without voting on a final standard. As proposed, the changes would apply to engagements beginning on or after June 15, 2029. For most organizations on an annual cycle, that puts the first SOC 2 examination under the revised standards at least two audits away.

author avatar
Brad Lyons Senior Practice Director, Cybersecurity & Compliance
Oversees audit and assessment operations at 360 Advanced. He has spent 15 years performing SOC 1, SOC 2, HIPAA, PCI DSS and HITRUST examinations and assessments, after managing IT attestation engagements at the CPA firm Lurie, LLP.

Leave a Comment