2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
High-Yield Exam-Day Synthesis

CPA Evolution ISC Cram Cheat Sheet

Master the most heavily tested IT controls, cybersecurity architectures, SOC engagement rules, and attestation standards on the CPA Evolution ISC discipline exam. Structured into 6 high-yield tables with exam traps and pro tips.

Practice 82Q Simulator →4-Week Study Plan →

SOC 1 vs. SOC 2 vs. SOC 3 Master Comparison Matrix

SOC Standards Core
Report TypeGoverning StandardCore Subject Matter / ScopeIntended Audience & DistributionDetailed Testing Disclosed?
SOC 1SSAE No. 18 (AT-C 320)Internal Control over Financial Reporting (ICFR). Focuses on transactions affecting general ledgers.Restricted Use: User entity management, user entity financial statement auditors.Yes (Type 2 details all controls, tests, and results).
SOC 2SSAE 18 (AT-C 105/205) + TSP Section 100Trust Services Criteria (Security mandatory; Availability, Processing Integrity, Confidentiality, Privacy optional).Restricted Use: Management, existing customers, regulators, prospective customers under NDA.Yes (Type 2 details all controls, tests, and results).
SOC 3SSAE 18 (AT-C 105/205) + TSP Section 100Trust Services Criteria (same criteria as SOC 2).General Use: Unrestricted public distribution. Used for marketing, websites, seal display.No (Summary report only; omits detailed test descriptions and results).
SOC for CybersecurityAICPA Cybersecurity FrameworkEnterprise-wide cybersecurity risk management program (broad entity-level governance).General or Specified Use: Board of directors, audit committees, investors, business partners.No (Reports on program description and control criteria effectiveness).
💡 CPA ISC Pro Tip: On the CPA ISC exam, if the outsourced system impacts the user entity's general ledger, balance sheet, or financial statements (e.g. payroll, loan servicing), choose SOC 1. If it involves technology, cloud hosting, SaaS, or data privacy without direct ICFR impact, choose SOC 2.

SOC Type 1 vs. Type 2 Examination Standards

Attestation Types
AttributeType 1 ExaminationType 2 ExaminationAudit Impact / Practical Value
Time HorizonAs of a specific point in time (e.g., as of September 30).Throughout a specified period of time (minimum 6 months, typically 12 months).Type 2 provides longitudinal assurance that controls operated continuously over time.
Suitability of DesignTested and reported.Tested and reported.Both evaluate whether controls are designed appropriately to achieve criteria.
Operating EffectivenessNOT tested or reported.TESTED and reported in detail.Type 1 provides ZERO evidence of operating effectiveness. External auditors require Type 2.
Testing ProceduresInquiry, inspection of design documents, walkthrough of one transaction.Inquiry, observation, inspection of samples throughout period, and reperformance.Inquiry alone is NEVER sufficient in a Type 2 examination.
Bridge / Gap LettersNot applicable (point in time).Applicable (covers gap between period-end and user's fiscal year-end, max 3 months).Bridge letters are signed by service organization management, NOT the CPA firm.
💡 CPA ISC Pro Tip: Remember that a Type 1 report cannot be used by financial statement auditors to reduce control risk below maximum because operating effectiveness was never tested.

AICPA Trust Services Criteria (TSC) 5 Categories

Trust Services Core
TSC CategoryCode SeriesMandatory or Optional?Core Objective / ScopeKey Control Focus Areas
Security (Common Criteria)CC1.1 – CC9.2MANDATORY in all SOC 2 reportsInformation and systems are protected against unauthorized access, unauthorized disclosure, and damage.COSO 17 principles, logical access (MFA/IAM), physical security, change management, firewalls, encryption.
AvailabilityA1.1 – A1.3Optional add-onInformation and systems are available for operation and use to meet entity commitments.Capacity planning, environmental controls (UPS/HVAC/generators), data backups, BCP/DRP testing, RTO/RPO.
Processing IntegrityPI1.1 – PI1.5Optional add-onSystem processing is complete, valid, accurate, timely, and authorized to meet objectives.Input validation (limit/range checks), error handling, automated run-to-run reconciliation, batch totals.
ConfidentialityC1.1 – C1.2Optional add-onInformation designated as confidential is protected as committed or agreed (B2B).Data classification, encryption in transit/at rest, access restrictions on business IP, NDA enforcement.
PrivacyP1.1 – P8.1Optional add-onPersonal information (PII) is collected, used, retained, disclosed, and disposed of per GAPP (B2C).Notice, choice/consent, collection limitation, use/retention, access, disclosure to 3rd parties, quality, monitoring.
💡 CPA ISC Pro Tip: Never confuse Confidentiality with Privacy! Confidentiality protects organizational data, trade secrets, and intellectual property. Privacy protects Personally Identifiable Information (PII) belonging to natural persons based on GAPP.

COSO Internal Control 17 Principles & ITGC Mapping

COSO & ITGC
COSO ComponentKey PrincipleIT General Control (ITGC) DomainSpecific Control Implementation
Control EnvironmentPrinciple 5: Enforces AccountabilitySecurity Governance & OrganizationClear IT reporting lines to Board, acceptable use policies, background checks, mandatory security training.
Risk AssessmentPrinciple 8: Assesses Fraud RiskFraud & Vulnerability ManagementThreat modeling (STRIDE), vulnerability scanning, penetration testing, evaluating management override risks.
Control ActivitiesPrinciple 11: General Controls Over TechnologyProgram Changes & Environment SegregationStrict logical isolation between Dev, Test, and Prod; mandatory CAB review; tested rollback plans.
Control ActivitiesPrinciple 11: General Controls Over TechnologyAccess to Programs and DataPrinciple of least privilege, MFA/FIDO2, privileged access management (PAM), quarterly user access reviews.
Control ActivitiesPrinciple 11: General Controls Over TechnologyComputer OperationsAutomated batch job scheduling, dependency halting upon abort, tape/cloud backup rotation, offsite storage.
Information & Comm.Principle 13: Uses Relevant InformationData Quality & Master DataSingle-point ERP entry, master data dual authorization, automated data pipeline run-to-run balancing.
Monitoring ActivitiesPrinciple 16: Evaluates Internal ControlSecurity Operations & AuditSIEM log correlation, Database Activity Monitoring (DAM), independent internal and external SOC audits.
💡 CPA ISC Pro Tip: COSO Principle 11 is the direct anchor for ITGCs. On the exam, when asked which COSO principle mandates technology change control, access control, and IT operational controls, the answer is always Principle 11.

NIST Cybersecurity Framework 2.0 Core Functions & Controls

Cybersecurity Core
CSF 2.0 FunctionCodeStrategic PurposeKey Categories & Control Activities
GovernGVEstablish and monitor the organization's cybersecurity risk management strategy, expectations, and policy.Organizational Context, Risk Management Strategy, Cybersecurity Supply Chain Risk (C-SCRM), Roles & Policy.
IdentifyIDUnderstand cybersecurity risk to systems, people, assets, data, and capabilities.Asset Management (CMDB), Business Environment, Risk Assessment, Improvement Feedback.
ProtectPRSafeguard delivery of critical services and contain/counteract potential impact.Identity Management & Access Control (IAM/MFA), Awareness Training, Data Security (Encryption), Platform Security.
DetectDEDiscover and analyze potential cybersecurity attacks and compromises.Continuous Security Monitoring, Adverse Event Analysis, Anomaly & Baseline Deviation Detection (SIEM/IDS).
RespondRSTake action regarding a detected cybersecurity incident.Incident Management, Incident Analysis, Incident Containment, Eradication, Incident Communication.
RecoverRCRestore assets and operations impacted by a cybersecurity incident.Incident Recovery Plan Execution, System Restoration from Immutable Backups, Public Communication, Lessons Learned.
💡 CPA ISC Pro Tip: Govern (GV) is the brand new 6th function introduced in NIST CSF 2.0 (2024). It encompasses organizational governance, executive oversight, and third-party supply chain risk management.

Cryptographic Protocols, Keys & Disaster Recovery Metrics

Technical Safeguards
Mechanism / ConceptStandard / FormulaKey Technical CharacteristicsExam Pitfall / Distinction
Symmetric EncryptionAES-256 / GCMSingle shared secret key for encryption and decryption. Fast, hardware-accelerated. Ideal for bulk data at rest.Key distribution is difficult across open networks; storing keys alongside ciphertext destroys security.
Asymmetric EncryptionRSA-4096 / ECCPublic key encrypts, private key decrypts. Solves key distribution. Slow. Used for digital handshakes (TLS).Never used for bulk database encryption due to massive CPU overhead; used in hybrid encryption.
Digital SignaturesRSA / ECDSA + SHA-256Hash document, encrypt hash with sender's private key. Verified with sender's public key.Provides Integrity, Authenticity, and Non-Repudiation. Does NOT provide confidentiality (not encrypted).
Cryptographic HashingSHA-256 / SHA-3One-way mathematical function; fixed-length digest. Irreversible and collision-resistant.Hashing is NOT encryption; it cannot be decrypted back into original plaintext.
Recovery Point ObjectiveRPO (Data Loss)Maximum acceptable amount of data loss measured in time (e.g. 15 mins of transactions).Dictates backup frequency and replication architecture (synchronous vs asynchronous).
Recovery Time ObjectiveRTO (Downtime)Maximum acceptable duration of system downtime before acceptable operations resume.Dictates alternate facility choice (Hot site = minutes/hours; Cold site = weeks).
💡 CPA ISC Pro Tip: Remember that a digital signature does NOT encrypt the document itself. The message is readable, but any tampering breaks the signature. To achieve confidentiality AND digital signature, encrypt the message with the recipient's public key AND sign with the sender's private key.