[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-253260-105":3,"detail-sidebar-cat-1-en-105":80,"doc-detail-253260-en":126},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":73,"head_meta":75,"extra_data":77,"updated_unix":79},105,"en","illustrative-type-2-soc-2sm-report-reporting-on-security-and-availability-using-csa-ccm-and-tsp-section-100a-example","Illustrative Type 2 SOC 2SM Report - Reporting on Security and Availability Using CSA CCM and TSP Section 100A - Example","","Illustrative Type 2 SOC 2SM reporting guidance for service organizations describing how to present trust services principles, criteria, controls, and auditor tests. The document explains that the illustrative format is not prescriptive, and that actual engagements must tailor the principles, included controls, and test procedures to specific facts. It also specifies that the example uses CSA Cloud Controls Matrix (CCM) Version 1.4 and referenced Trust Services Principles and Criteria versions, highlighting the need to identify the correct versions in the management assertion and auditor report.",{"@graph":14,"@context":72},[15,34,55],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/template/","Template",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/template/general/","General",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/template/illustrative-type-2-soc-2sm-report-reporting-on-security-and-availability-using-csa-ccm-and-tsp-section-100a-example/253260/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/illustrative-type-2-soc-2sm-report-reporting-on-security-and-availability-using-csa-ccm-and-tsp-section-100a-example/253260.png","ImageObject",442,249,{"name":42,"@type":43},"Chumphorn","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-09-20","2026-09-13",true,{"@type":52,"interactionType":53,"userInteractionCount":30},"InteractionCounter",{"@type":54},"ViewAction",{"@type":56,"mainEntity":57},"FAQPage",[58,64,68],{"name":59,"@type":60,"acceptedAnswer":61},"What is the purpose of the illustrative Type 2 SOC 2SM report format?","Question",{"text":62,"@type":63},"It provides an example structure showing required components, but it is meant to be illustrative rather than prescriptive. Real SOC 2SM engagements should organize and present required information in formats tailored to the service organization.","Answer",{"name":65,"@type":60,"acceptedAnswer":66},"Which criteria and versions does the illustrative report use?",{"text":67,"@type":63},"The example uses the CSA Cloud Controls Matrix (CCM) Version 1.4 and the Trust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2009). The practitioner should ensure the correct current versions are identified for the management assertion and auditor report.",{"name":69,"@type":60,"acceptedAnswer":70},"What sections are included in the illustrative SOC 2SM Type 2 report?",{"text":71,"@type":63},"The report includes sections for management’s description and assertion (Section 1), the independent service auditor’s report (Section 2), the service organization’s system description and supporting topics (Section 3), the applicable principles/criteria and associated controls with test results (Section 4), and other information not covered by the auditor’s report (Section 5).","https://schema.org",{"og:url":32,"og:type":74,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":76,"canonical":32},"index,follow",{"doc_id":78,"site_id":7},253260,1789264960,{"code":4,"msg":81,"data":82},"success",[83,88,93,98,103,108,113,118,123],{"id":84,"doc_module":22,"doc_module_name":25,"category_name":85,"show_sort_weight":86,"slug":87},11,"Presentations",90,"presentations",{"id":89,"doc_module":22,"doc_module_name":25,"category_name":90,"show_sort_weight":91,"slug":92},12,"Resumes",80,"resumes",{"id":94,"doc_module":22,"doc_module_name":25,"category_name":95,"show_sort_weight":96,"slug":97},14,"Invoices",70,"invoices",{"id":99,"doc_module":22,"doc_module_name":25,"category_name":100,"show_sort_weight":101,"slug":102},15,"Posters",60,"posters",{"id":104,"doc_module":22,"doc_module_name":25,"category_name":105,"show_sort_weight":106,"slug":107},16,"Social Media",50,"social-media",{"id":109,"doc_module":22,"doc_module_name":25,"category_name":110,"show_sort_weight":111,"slug":112},17,"Forms",40,"forms",{"id":114,"doc_module":22,"doc_module_name":25,"category_name":115,"show_sort_weight":116,"slug":117},18,"Letters",30,"letters",{"id":119,"doc_module":22,"doc_module_name":25,"category_name":120,"show_sort_weight":121,"slug":122},21,"Paper Templates",5,"papers-templates",{"id":124,"doc_module":22,"doc_module_name":25,"category_name":29,"show_sort_weight":4,"slug":125},158,"general-158",{"code":4,"msg":81,"data":127},{"doc_id":78,"user_id":128,"nickname":42,"user_avatar":129,"doc_module":22,"category_id":124,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":26,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":135,"language":136,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":12,"update_tm":79,"read_time":84},2336475401981,"https://ap-avatar.wpscdn.com/avatar/22000c94efd8d5204d?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786935347598174694","April 2014  \nFinancial Reporting Center  \nIllustrative Type 2 SOC 2SM Report with the Criteria in the Cloud Security Alliance (CSA)  \nCloud Controls Matrix  \n(CCM)  \nThe AICPA guide Reporting on Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy (SOC 2SM) specifies the components of a SOC 2SM report and the information to be included in each component, but it does not specify the format for these reports. Service organizations and service auditors may organize and present the required information in a variety of formats. The format of the illustrative type 2 SOC 2 report presented in this document is meant to be illustrative rather than prescriptive. The illustrative report contains all of the components of a type 2 SOC 2 report; however, for brevity, it does not include everything that might be described in a type 2 SOC 2 report. Ellipses ( ... ) or notes to readers indicate places where detail has been omitted.  \nThe trust services principle(s) being reported, the controls specified by the service organization, and the tests performed by the service auditor are presented for illustrative purposes only. They are not intended to represent the principles that would be addressed in every type 2 SOC 2 engagement, orthe controls, or tests of controls, that would be appropriate for all service organizations. The trust services principles on which the report is based, the controls a service organization would include in its description, and the tests of controls a service auditor would perform for a specific type 2 SOC 2 engagement will vary based on the specific facts and circumstances of the engagement. Accordingly, it is expected that actual type 2 SOC 2 reports will address different principles and include different controls and tests of controls that are tailored to the service organization that is the subject of the engagement.  \nThe Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) Version 1.4 is used for the purpose of this illustrative report. The CSA periodically issues new criteria. The practitioner should identify the CCM version being used as criteria in management’s assertion and the service auditor’s report.  \nTrust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2009) is used for the purpose of this illustrative report. The AICPA periodically issues new Trust Services Principles and Criteria. The practitioner should identify the current Trust Services Principles and Criteria version for management’s assertion and the service auditor’s report.  \n[aicpa.org/FRC](aicpa.org/FRC)  \nIllustrative Type 2 SOC 2SM Report: Reporting on the Security and Availability of a System Using the Criteria for Security and Availability in Section 100A, Trust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA, Technical Practice Aids) and on the Controls of a System Using the Criteria in the Cloud Security Alliance Cloud Controls Matrix  \nIn the following illustrative type 2 SOC 2 report, the service auditor is reporting on  \n• the fairness of the presentation of the service organization’s description of its system based on the description criteria identified in management’s assertion; and  \n• the suitability of the design and operating effectiveness of its controls relevant to security and availability based on the criteria for security and availability in TSP Section 100A, Trust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA, Technical Practice Aids) and, the suitability of the design and operating effectiveness of its controls in meeting the criteria in the CCM.  \n[aicpa.org/FRC](aicpa.org/FRC)  \nDescription of Example Cloud Service Organization’s Infrastructure Services System Relevant to Security and Availabil","cbCaigi85qR1J91O","https://ap.wps.com/l/cbCaigi85qR1J91O","pdf",954712,31,"English","# Overview\n## Illustrative nature and tailoring of actual reports\n# Criteria and matrix versions\n## CSA Cloud Controls Matrix (CCM)\n## AICPA Trust Services Principles and Criteria\n# Illustrative Type 2 SOC 2SM report structure\n## Section 1—Management assertion\n## Section 2—Independent service auditor’s report\n## Section 3—Service organization description\n## Section 4—Applicable principles, criteria, CCM criteria, controls and test results\n## Section 5—Other information not covered by the auditor’s report","[{\"question\":\"What is the purpose of the illustrative Type 2 SOC 2SM report format?\",\"answer\":\"It provides an example structure showing required components, but it is meant to be illustrative rather than prescriptive. Real SOC 2SM engagements should organize and present required information in formats tailored to the service organization.\"},{\"question\":\"Which criteria and versions does the illustrative report use?\",\"answer\":\"The example uses the CSA Cloud Controls Matrix (CCM) Version 1.4 and the Trust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2009). The practitioner should ensure the correct current versions are identified for the management assertion and auditor report.\"},{\"question\":\"What sections are included in the illustrative SOC 2SM Type 2 report?\",\"answer\":\"The report includes sections for management’s description and assertion (Section 1), the independent service auditor’s report (Section 2), the service organization’s system description and supporting topics (Section 3), the applicable principles/criteria and associated controls with test results (Section 4), and other information not covered by the auditor’s report (Section 5).\"}]","Illustrative Type 2 SOC 2SM Report - Reporting on Security and Availability Using CSA CCM and TSP Section 100A - Example | PDF"]