{
	"version": "https://jsonfeed.org/version/1.1",
	"title": "SOC 2 news from Infosec Standards",
	"description": "News about SOC 2, including major updates to our page on it.",
	"home_page_url": "https://infosecstandards.org/standards/soc-2",
	"feed_url": "https://infosecstandards.org/standards/soc-2/feed.json",
	"authors": [
		{
			"name": "Infosec Standards",
			"url": "https://infosecstandards.org"
		}
	],
	"language": "en-US",
	"items": [
		{
			"id": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"url": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"title": "Standard pages now say who decides your obligation, and what to ask them",
			"summary": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"content_text": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"date_published": "2026-09-03T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/risk-assessment-tool",
			"url": "https://infosecstandards.org/news/risk-assessment-tool",
			"title": "Infosec Standards now has a free, browser-only risk assessment tool",
			"summary": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"content_text": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"date_published": "2026-09-02T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/soc-2-2022-points-of-focus",
			"url": "https://infosecstandards.org/news/soc-2-2022-points-of-focus",
			"title": "SOC 2 Trust Services Criteria points of focus revised in 2022",
			"summary": "In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.",
			"content_text": "In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.",
			"date_published": "2022-10-01T00:00:00.000Z",
			"tags": [
				"version-updates"
			]
		}
	]
}
