Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this SOC 2 Readiness Practitioner Certification register is built
This trust page is the citation register for the SOC 2 Readiness Practitioner Certification course. It cites 28 authorities across 8 statutory instruments, drawn from the legal basis snapshot above (SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only). Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.).
Primary sources: AICPA Trust Services Criteria 2017 (2022 PoF) (14 entries), SOC 2 Platform Vendor (4 entries), AICPA AT-C Section (3 entries).
Every claim in every SOC 2 Readiness Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
AT-C 105 Concepts Common to All Attestation , Common concepts across attestation engagements 01 Apr 2016
AT-C 205 Examination Engagements , Examination engagement standard (SOC 2) 01 Apr 2016
AT-C 320 SOC 1 Reporting on Service Org Controls , SOC 1 reporting section (contrast for SOC 2) 01 Apr 2016
DC-100 Description Criteria for SOC 2 , AICPA Description Criteria for SOC 2 reports 01 Jan 2018
SSAE 18 Attestation Standards (April 2016) , Statement on Standards for Attestation Engagements No. 18 01 Apr 2016
2017 TSC with Revised Points of Focus (2022) , Current operative TSC document 15 Dec 2022
Availability TSC (A-series) , Availability Trust Services Criterion 15 Dec 2022
CC1 Control Environment , Common Criteria CC1 governance and org structure 15 Dec 2022
CC2 Communication and Information , Common Criteria CC2 15 Dec 2022
CC3 Risk Assessment , Common Criteria CC3 15 Dec 2022
CC4 Monitoring Activities , Common Criteria CC4 15 Dec 2022
CC5 Control Activities , Common Criteria CC5 15 Dec 2022
CC6 Logical and Physical Access Controls , Common Criteria CC6 15 Dec 2022
CC7 System Operations , Common Criteria CC7 15 Dec 2022
CC8 Change Management , Common Criteria CC8 15 Dec 2022
CC9 Risk Mitigation , Common Criteria CC9 15 Dec 2022
Confidentiality TSC (C-series) , Confidentiality Trust Services Criterion 15 Dec 2022
Privacy TSC (P-series) , Privacy Trust Services Criterion 15 Dec 2022
Processing Integrity TSC (PI-series) , Processing Integrity Trust Services Criterion 15 Dec 2022
COSO Internal Control Framework 2013 , COSO 2013 (underlies CC1 through CC5) 14 May 2013
COSO GenAI Internal Control Guidance (Feb 2026) , Non-authoritative GenAI guidance mapped to COSO 2013 01 Feb 2026
ISO/IEC 27001:2022 , ISO Information Security Management Systems standard 25 Oct 2022
Freshworks Trust Portal , Freshworks security and SOC 2 posture (public) 01 Jan 2024
Zoho Trust Page , Zoho security and compliance page (public) 01 Jan 2024
Vanta SOC 2 platform , Vanta compliance automation platform 01 Jan 2018
Drata SOC 2 platform , Drata compliance automation platform 01 Jan 2020
Secureframe SOC 2 platform , Secureframe (quote-only, US-focused) 01 Jan 2020
Sprinto SOC 2 platform , Sprinto (India-registered, DPDP-integrated) 01 Jan 2020
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.