2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
AICPA CPA Evolution 2026 Blueprint Architecture

CPA Evolution ISC Practice Questions & Interactive Simulator

Master the Information Systems and Controls (ISC) discipline of the CPA Evolution model. This exhaustive question bank features 82 scored technical scenario questions across Information Systems and Data Governance, Security, Confidentiality, and Privacy, and SSAE 18/21 SOC Engagements—complete with 4-option distractor autopsies and authoritative standard citations.

Questions82 Scored
Time Limit240 Minutes (4h)
Passing Benchmark75 Scaled Score
Access100% Free & Open

AICPA Content Specification Blueprint & Weight Distribution

Area 1 (40%)32 Questions

Information Systems and Data Governance

Enterprise IT architecture (ERP, cloud IaaS/PaaS/SaaS), data lifecycle governance, master data management, COSO internal control principles,...

Area 2 (40%)32 Questions

Security, Confidentiality, and Privacy

NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover), ISO/IEC 27001, threat landscape and vulnerability ma...

Area 3 (20%)18 Questions

Considerations for System and Organization Controls (SOC) Engagements

SSAE No. 18 / SSAE No. 21 attestation standards, SOC 1 vs. SOC 2 vs. SOC 3 report architectures, Type 1 (point in time) vs. Type 2 (period o...

AICPA CPA Evolution 2026 Discipline Simulation

Official CPA Evolution ISC Exam Simulator

Experience realistic technical scenario questions modeling the Information Systems and Controls (ISC) discipline of the CPA Evolution exam. Master IT Governance, COSO ITGC, NIST CSF 2.0, Zero Trust, SSAE 18/21 SOC 1/2/3 attestation engagements, and Trust Services Criteria.

Full Mock Exam

82-Question Scored Mock

240-minute (4-hour) Prometric timer matching full CPA exam session pacing. Requires official 75 benchmark to pass.

Quick Diagnostic

25-Question Diagnostic

60-minute balanced diagnostic session covering 10 ITGC/Data Gov, 10 Security/Privacy, and 5 SOC Engagement questions.

Frequently Asked Questions: CPA Evolution ISC Discipline

What is the Information Systems and Controls (ISC) discipline in CPA Evolution?

Under the CPA Evolution licensure model established jointly by NASBA and AICPA, all candidates pass three Core sections (AUD, FAR, REG) and choose one Discipline section: Business Analysis and Reporting (BAR), Information Systems and Controls (ISC), or Tax Compliance and Planning (TCP). ISC tests enterprise IT governance, internal controls (ITGC), cybersecurity risk management, privacy regulations, and SOC 1/2/3 attestation reporting.

Why should an accounting or audit professional choose the ISC discipline?

ISC is the premier discipline for professionals interested in IT audit, SOC reporting, internal audit, advisory services, cybersecurity governance, and digital transformation. It focuses heavily on evaluating technical controls, SaaS/cloud vendor risk, and compliance frameworks rather than complex technical financial accounting calculations.

How heavily are SOC engagements tested on CPA ISC?

Area III accounts for 20% of the ISC exam blueprint. Candidates must thoroughly understand SSAE No. 18 / SSAE No. 21 attestation standards, the exact differences between SOC 1, SOC 2, and SOC 3, Type 1 vs. Type 2 test horizons, the five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy), and how Complementary User Entity Controls (CUECs) impact report conclusions.