{
  "node_id": "soc-for-cybersecurity",
  "title": "AICPA SOC for Cybersecurity - Cybersecurity Risk Management Reporting Framework",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "SOC for Cybersecurity is an AICPA reporting framework for an examination of an entity-wide cybersecurity risk management program. Unlike SOC 2, which covers a defined system at a service organization, SOC for Cybersecurity reports on the entity as a whole and is intended for general use by boards, investors, and other stakeholders. It uses description criteria for the cybersecurity risk management program together with the control (trust services) criteria.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 5
}