The American Institute of CPAs (AICPA) updated the Trust Services Criteria in 2022, introducing changes to the language and structure that govern SOC 2 audits. For SaaS organizations operating under existing SOC 2 reports, or preparing for initial certification, this update requires reassessment of control design, evidence gathering, and the way leadership describes its security posture to customers, investors, and auditors.

The problem for executives is not the criteria themselves—it is that responsibility for interpreting the changes, redesigning controls, and ensuring ongoing compliance often falls into a gap between IT operations, external auditors, and the executive team. Without clear ownership at the leadership level, organizations risk treating SOC 2 as a project rather than a continuous governance obligation.

What the 2022 Trust Services Criteria Update Changed

The 2022 update refined the language of the Trust Services Criteria to align more closely with evolving risk management practices and to reduce ambiguity in how controls are described and evaluated. While the five Trust Services Categories—Security, Availability, Processing Integrity, Confidentiality, and Privacy—remained unchanged, the criteria within those categories were revised to clarify expectations and address emerging security concerns.

The update introduced more explicit language around risk assessment, control monitoring, and the integration of security into the broader enterprise risk management function. Criteria that previously used general terms were rewritten to specify the activities, documentation, and decision-making processes that constitute adequate control. This means that controls designed under the prior criteria may no longer meet the standard without modification.

Importantly, the update also placed greater emphasis on the governance and oversight responsibilities of senior management and the board. The revised criteria make it clearer that compliance is not solely a technical function—it requires executive involvement in defining risk appetite, approving control frameworks, and ensuring that security outcomes align with business objectives.

Why This Matters to SaaS Leadership

SOC 2 reports are foundational to customer trust, sales cycles, and contract negotiations in SaaS. Customers, particularly those in regulated industries or those subject to vendor risk management requirements, rely on SOC 2 as evidence that a provider maintains appropriate controls. A report issued under outdated criteria, or one that fails to reflect the 2022 language, may not satisfy customer due diligence requirements.

The business consequence of non-alignment is delay. Sales cycles extend. Security questionnaires require additional explanation. Procurement teams escalate concerns to their own compliance functions. In competitive bids, a current, clearly documented SOC 2 report becomes a differentiator.

From a governance perspective, the updated criteria also clarify where accountability sits. Boards and executive teams are expected to demonstrate active oversight of the control environment, not merely delegate compliance to IT or engage an auditor on an annual basis. This shift mirrors the approach taken in frameworks such as the [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework), which emphasizes governance as a core function of effective risk management.

What Leadership Must Reassess

Organizations operating under SOC 2 should review three areas in light of the 2022 criteria: control descriptions, evidence of governance, and the way risk decisions are documented and approved.

Control Descriptions

The updated criteria use more precise language to describe what constitutes a control. If your current SOC 2 report includes control descriptions written before 2022, they may not align with the new terminology. This is not a matter of rewriting for style—it is a question of whether the control as described meets the revised standard. Auditors will evaluate controls against the 2022 criteria, and gaps will need to be addressed before the next report period.

Evidence of Governance

The 2022 update places greater weight on documented evidence of executive and board oversight. This includes records of risk discussions, approval of control changes, and review of security incidents or exceptions. Many organizations do not have a consistent process for creating this evidence, particularly if security is managed primarily by IT without formal reporting to the executive team. The absence of this documentation can result in qualifications or findings in the SOC 2 report.

Risk Decision Documentation

The revised criteria expect that risk decisions—such as accepting a residual risk, deferring a control, or prioritizing remediation—are documented with rationale and approved at an appropriate level. In practice, many organizations make these decisions informally, often in response to operational constraints or budget limitations. Under the 2022 criteria, informal decisions do not satisfy the governance expectations. Leadership must establish a process for risk acceptance that includes documentation, approval, and periodic review.

Who Owns SOC 2 Compliance and What Adequate Ownership Looks Like

Accountability for SOC 2 compliance cannot sit solely with the auditor, IT, or a compliance coordinator. The updated criteria make it explicit that senior management and the board are responsible for the oversight of the control environment. This means that someone at the executive level must be accountable for ensuring that controls are designed, implemented, monitored, and reported in accordance with the criteria.

Adequate ownership includes the following elements:

  • A named executive responsible for the SOC 2 program, with direct reporting to the CEO or board.
  • A documented governance structure that defines how control changes are proposed, reviewed, and approved.
  • A process for escalating security incidents, exceptions, or control failures to the executive team and board.
  • Regular reporting to the board on the status of controls, audit findings, and remediation timelines.
  • Integration of SOC 2 requirements into the broader enterprise risk management function, not as a separate compliance exercise.

For many SaaS organizations, particularly those in growth stages or those without a full-time Chief Information Security Officer, this level of governance is difficult to establish internally. [Virtual CISO (vCISO) leadership](/vciso/) provides the executive ownership that closes this gap, offering strategy, governance, risk decisions, regulatory positioning, and reporting without the overhead of a full-time hire.

How This Relates to Regulatory and Framework Readiness

SOC 2 compliance does not exist in isolation. Organizations operating under multiple regulatory or framework requirements—such as HIPAA, GDPR, or the [NIST Privacy Framework](https://www.nist.gov/privacy-framework)—must coordinate their approach to avoid duplication, conflict, or gaps. The 2022 Trust Services Criteria align more closely with enterprise risk management principles, which makes integration with other frameworks more straightforward, but only if governance is structured to support it.

Regulatory and framework readiness means having the governance, processes, and evidence in place to demonstrate compliance across multiple obligations without treating each as a separate project. For SaaS leadership, this requires a unified view of risk, a single source of truth for control documentation, and executive oversight that spans all regulatory and contractual commitments.

The updated SOC 2 criteria, with their emphasis on governance and risk management, provide a foundation for this integrated approach—but only if leadership treats compliance as a continuous governance function rather than an annual audit event.

Practical Next Steps for Leadership

SaaS executives and compliance leaders should take the following steps to ensure alignment with the 2022 Trust Services Criteria and to establish adequate governance over the SOC 2 program:

  • Obtain the 2022 Trust Services Criteria document and compare it to your current SOC 2 report. Identify any areas where control descriptions or evidence do not align with the revised language.
  • Review the governance structure for SOC 2 compliance. Confirm that there is a named executive accountable for the program, with clear reporting lines to the board.
  • Assess whether risk decisions are documented and approved in a manner consistent with the updated criteria. If not, establish a process for risk acceptance, documentation, and periodic review.
  • Engage your auditor early to discuss the 2022 update and its implications for your next report period. Do not wait until the audit fieldwork begins to address gaps.
  • Integrate SOC 2 governance into the broader enterprise risk management function. Ensure that security, privacy, and compliance are coordinated, not managed as separate activities.
  • If your organization lacks the internal capacity for executive-level oversight of SOC 2, consider whether [virtual CISO leadership](/vciso/) can provide the governance, strategy, and reporting that the updated criteria require.

For organizations that recognize the need for executive-level accountability but are uncertain about the scope, sequence, or resourcing required, Heights Consulting Group offers a confidential consultation to assess governance gaps and recommend a practical path forward. This is offered once, at the point where the decision is under consideration, and is structured to provide clarity rather than a sales process.

The 2022 update to the Trust Services Criteria is not a minor revision. It changes what constitutes adequate control, how governance must be documented, and where accountability sits. For SaaS leadership, the question is whether the organization has the structure, processes, and executive ownership in place to meet the standard—or whether it is relying on informal practices that will not satisfy the updated criteria. The time to close that gap is before the next audit cycle, not during it.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness