2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
Structured Licensure Roadmap

CPA Evolution ISC 4-Week Study Plan

A rigorous 4-week preparation schedule calibrated to the AICPA CPA Evolution ISC Content Specification Outline. Combines weekly core study objectives, milestone targets, and an essential First-5-Minute Prometric Dump Sheet.

Practice 82Q Simulator →Browse Complete Study Guide →

Weekly Study Agendas & Checkpoints

Week 1: 18–22 HoursMilestone Target

Area I: Enterprise Architecture, Cloud Models & Data Governance

Curriculum Focus: Master cloud service models (IaaS/PaaS/SaaS shared responsibility matrix), enterprise ERP structures, data classification tiers (Public, Internal, Confidential, Restricted), Master Data Management (MDM), and ETL data integrity pipelines.

🎯 Target Milestone: Complete 20 Area I data governance questions; achieve 80%+ on cloud security responsibility questions.
Week 2: 20–24 HoursMilestone Target

Area I: ITGCs, Application Controls & SDLC Change Management

Curriculum Focus: COSO Internal Control framework (17 principles), IT General Controls (logical access, change management, computer operations), segregation of duties (developer vs. release engineer), automated application controls, and three-way matching.

🎯 Target Milestone: Complete 25 ITGC practice questions; review ITGC vs. application controls distinction tables.
Week 3: 22–26 HoursMilestone Target

Area II: Cybersecurity (NIST CSF 2.0), IAM & Privacy Regulations

Curriculum Focus: NIST CSF 2.0 six core functions (Govern, Identify, Protect, Detect, Respond, Recover), Zero Trust architecture, IAM/MFA/PAM controls, symmetric (AES-256) vs. asymmetric (RSA/ECC) cryptography, TLS handshakes, GDPR/CCPA privacy rights, and BCDR metrics (RTO vs. RPO).

🎯 Target Milestone: Complete 30 Area II questions; take 25Q diagnostic exam in under 50 minutes.
Week 4: 22–26 HoursMilestone Target

Area III: SOC Engagements (SSAE 18/21) & Full Exam Simulation

Curriculum Focus: SOC 1 (ICFR / AT-C 320) vs. SOC 2 (TSC / AT-C 205) vs. SOC 3, Type 1 vs. Type 2 testing horizons, 5 Trust Services Criteria (Security mandatory), Complementary User Entity Controls (CUECs), subservice organization methods (carve-out vs. inclusive), and auditor reporting opinions.

🎯 Target Milestone: Complete full 82-Question 240-Minute CPA ISC Mock Exam; achieve 75%+ scaled score benchmark.
Exam Center Scratch Paper Strategy

The First-5-Minute Prometric Dump Sheet

As soon as your Prometric countdown begins, write down these high-yield frameworks and distinctions on your scratch paper:

1. SOC Engagement Decision Tree

  • SOC 1 (AT-C 320): Direct impact on financial reporting (ICFR). Restricted use.
  • SOC 2 (AT-C 205): Security, availability, privacy. Restricted use.
  • SOC 3 (AT-C 205): Summary of SOC 2 for general public / marketing use.
  • Type 1: Point in time (design only).
  • Type 2: Period of time (≥6 mos; design + operating effectiveness).

2. 5 Trust Services Criteria (TSP 100)

  • Security (Common Criteria): Always mandatory in every SOC 2.
  • Availability: System operational per SLA/agreement.
  • Processing Integrity: Complete, valid, accurate, timely.
  • Confidentiality: Protected confidential info (contracts, IP).
  • Privacy: Personal information (PII) collected/used/retained.

3. BCDR & Cryptography Essentials

  • RTO (Recovery Time Objective): Maximum tolerable downtime.
  • RPO (Recovery Point Objective): Maximum tolerable data loss.
  • Symmetric: Single secret key (AES-256). Fast, bulk data.
  • Asymmetric: Public/private keypair (RSA, ECC). Signatures, key exchange.
  • Digital Signature: Sender encrypts hash with Private Key → Receiver decrypts with Public Key (integrity + non-repudiation).

4. COSO ITGC & NIST CSF 2.0

  • COSO (CRIME): Control Environment, Risk Assessment, Control Activities, Info & Comm, Monitoring.
  • NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover.
  • CUECs: Controls that service org requires user entities to implement for system controls to work.
  • SDLC SoD: Developers must NEVER possess write/deploy access to Production environments.