Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Audit & Certification

Points of Focus

Also known as: Additional Points of Focus
Simply put

In the context of SOC 2, points of focus are illustrative considerations that help organizations and auditors understand what a given control criterion is intended to address. They are explanatory aids rather than a mandatory checklist, so an organization need not implement each one to meet a criterion. The available evidence does not fully detail how points of focus are structured or applied, so readers should verify against the current authoritative source.

Formal definition

Within the SOC 2 framework, which is organized around the Trust Services Criteria spanning the categories of Security, Availability, Confidentiality, Privacy, and Processing Integrity (with Security being the required category), points of focus are descriptive elements associated with individual criteria that illustrate characteristics relevant to meeting those criteria. They are interpretive guidance intended to assist in evaluating whether a criterion is satisfied and are generally not treated as separately auditable requirements; a distinct notion of 'additional points of focus' also exists but is not defined in the evidence provided here. SOC 2 is a voluntary, contractually driven attestation framework rather than a binding regulation, and its criteria and associated points of focus are periodically revised, so this entry should be confirmed against the latest official Trust Services Criteria text. Note that 'points of focus' also carries unrelated meanings in optics and photography that are out of scope for this compliance entry.

Why it matters

Points of focus matter because they shape how organizations and their auditors interpret what a SOC 2 control criterion is actually asking for. Because the Trust Services Criteria are written at a relatively high level, points of focus provide the illustrative detail that helps translate an abstract criterion into concrete, evaluable characteristics. Misunderstanding their role is a common source of friction: a team that treats every point of focus as a mandatory requirement may over-engineer its control environment, while a team that ignores them entirely may struggle to demonstrate that a criterion is genuinely addressed.

The key distinction to keep in mind is that points of focus are interpretive aids, not a checklist. An organization does not need to implement each one to satisfy a criterion, and points of focus are generally not treated as separately auditable requirements. This flexibility is deliberate—it allows the framework to accommodate different organizational sizes, risk profiles, and control designs—but it also places responsibility on the organization and its service auditor to exercise judgment about which considerations are relevant to a given environment.

Because SOC 2 is a voluntary, contractually driven attestation framework rather than a binding regulation, the criteria and their associated points of focus are periodically revised. Readers should confirm any specific interpretation against the latest official Trust Services Criteria text rather than relying on a fixed understanding, and should recognize that application to a particular control environment requires professional judgment.

Who it's relevant to

Compliance and GRC teams
Teams preparing for a SOC 2 examination use points of focus to interpret what each Trust Services Criterion is intended to address and to shape their control environment. Understanding that these are illustrative considerations—not a mandatory checklist—helps avoid both over-engineering and gaps in coverage.
Service auditors
Practitioners performing SOC 2 attestation engagements draw on points of focus to evaluate whether a criterion is satisfied. Because points of focus are generally not treated as separately auditable requirements, auditors apply professional judgment about which considerations are relevant to a given environment.
Information security and control owners
Those responsible for designing and operating controls across the Security category (required) and any additional categories in scope—Availability, Confidentiality, Privacy, or Processing Integrity—can use points of focus to understand the characteristics a control is expected to demonstrate.
Vendor risk and procurement reviewers
Parties who rely on a service organization's SOC 2 report as part of contractual assurance benefit from understanding that points of focus guide interpretation of the criteria rather than functioning as fixed, itemized obligations, which informs how they read the scope and coverage of a report.

Inside Points of Focus

Definition and role
Points of Focus are illustrative considerations that support the criteria within certain control frameworks, most prominently the AICPA's Trust Services Criteria used in SOC 2 examinations. They describe important characteristics that may help an organization understand and apply a criterion, but they are not themselves separate requirements that must each be met.
Relationship to criteria
Each Point of Focus is subordinate to a specific criterion. The criterion sets the objective to be achieved, while the associated Points of Focus break down aspects an organization might consider when designing and operating controls to meet that objective.
Non-mandatory nature
Points of Focus are intended to assist judgment rather than to serve as a checklist. An organization need not demonstrate that every Point of Focus is individually addressed, and management and the practitioner exercise judgment about their relevance to the particular entity and its controls.
Voluntary framework context
Points of Focus appear within voluntary, contract-driven attestation frameworks such as SOC 2 rather than within binding law. They do not carry legal force in themselves; their significance derives from the framework and the engagement in which they are used.
Application by management and practitioners
Management typically considers relevant Points of Focus when designing its control environment, and service auditors may consider them when evaluating whether controls are suitably designed and operating to meet the related criteria.

Common questions

Answers to the questions practitioners most commonly ask about Points of Focus.

Are Points of Focus mandatory requirements that must all be met to achieve a SOC 2 report?
No. Points of Focus are not mandatory checklist items. In the AICPA Trust Services Criteria framework, they are illustrative considerations that describe characteristics an organization might address when designing and evaluating controls relative to a criterion. Management and the service auditor are generally not required to satisfy, address, or document every Point of Focus individually. The criteria themselves are what must be met; Points of Focus support the exercise of judgment about how to meet them. Treating them as a rigid compliance checklist misreads their purpose.
Do Points of Focus carry legal force the way a regulation does?
No. Points of Focus originate from the AICPA's Trust Services Criteria, which underpin voluntary, attestation-based SOC 2 examinations performed under professional standards. They are not law and do not carry statutory or regulatory force in themselves. Their relevance is contractual and professional rather than legislative. An organization is typically subject to them only because it has chosen to undergo a SOC 2 examination or is contractually expected to. This differs fundamentally from binding regulations, which apply by operation of law regardless of election.
How should an organization use Points of Focus when designing its controls?
Points of Focus are generally used as a reference set of considerations to help management determine whether its controls are suitably designed to meet a given criterion. Organizations often review the Points of Focus associated with a criterion, assess which are relevant to their particular systems, size, and risk profile, and design or map controls accordingly. Because they are illustrative rather than prescriptive, some may not apply, and additional considerations beyond those listed may be needed. Application to specific circumstances requires professional judgment.
Does an auditor test each Point of Focus during a SOC 2 examination?
In most cases, no. A service auditor tests controls against the applicable Trust Services Criteria, not against each Point of Focus individually. Points of Focus may inform the auditor's understanding of what a well-designed control could address, but the opinion is expressed on whether controls were suitably designed and, in a Type 2 report, operating effectively to meet the criteria. Practice can vary between firms, so readers should confirm expectations with their service auditor.
Should organizations document how they addressed each Point of Focus?
Documentation practices vary and are a matter of judgment. Some organizations map their controls to relevant Points of Focus to demonstrate a structured rationale for how criteria are met, which can aid internal review and readiness assessments. Others document only at the criterion level. Because Points of Focus are not individually mandatory, exhaustive per-item documentation is generally not required, though a clear record of design rationale is often useful. Confirm expectations against current AICPA materials and with the service auditor.
What should an organization do when a Point of Focus does not apply to its environment?
When a Point of Focus is not relevant to an organization's systems, services, or risk profile, it generally need not be addressed, since these considerations are illustrative rather than universally applicable. The key question remains whether the associated criterion is met through suitably designed and, where applicable, operating controls. Organizations may find it helpful to note why a given consideration is not applicable to support internal consistency, but this is a matter of judgment rather than a defined requirement. Verify current guidance against the latest authoritative AICPA source.

Common misconceptions

Every Point of Focus is a mandatory requirement that must be satisfied to pass an examination.
Points of Focus are generally illustrative and support the criteria rather than functioning as discrete pass/fail requirements. In most cases they inform judgment about how a criterion might be met, and their relevance depends on the entity's circumstances. The criteria themselves, not the individual Points of Focus, are what controls are evaluated against.
Points of Focus are legal obligations similar to those imposed by regulations such as the GDPR or HIPAA.
Points of Focus sit within voluntary or contractual attestation frameworks and do not carry independent legal force. Any binding effect arises only from contractual commitments or from a framework being incorporated by agreement, and this differs fundamentally from statutory requirements.
Points of Focus are fixed and unchanging references.
The frameworks that contain Points of Focus are periodically revised, and the wording, grouping, and content of Points of Focus can change across versions. Readers should verify against the current authoritative version rather than assuming permanence.

Best practices

Treat Points of Focus as aids to interpreting and applying the related criteria, and document how the criterion itself is being met rather than mechanically checking off each Point of Focus.
Assess the relevance of each Point of Focus to your specific organization, system, and risk profile, and record the rationale where a Point of Focus is considered not applicable.
Confirm which version of the underlying framework applies to your engagement, since Points of Focus and their associated criteria are periodically updated.
Coordinate with the service auditor or assessor early to align on how Points of Focus will inform the evaluation of control design and operating effectiveness.
Keep the distinction clear between the mandatory criteria that must be met and the supporting Points of Focus that guide judgment, so that scoping and evidence collection are proportionate.
Consult the current official framework text and obtain professional judgment for your particular circumstances, as this definition is informational and not a substitute for engagement-specific advice.
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."