# AICPA: 2017 Trust Services Criteria with revised points of focus

> Official source for the criteria used in SOC 2 examinations. Referenced for the existence and location of the criteria, not as an assurance opinion. Checked September 12, 2026.

Canonical page: https://datacenterlabeling.com/references/s53

Original source: [AICPA: 2017 Trust Services Criteria with revised points of focus](https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022)

## Scope of this source

Official source for the criteria used in SOC 2 examinations. Referenced for the existence and location of the criteria, not as an assurance opinion. Checked September 12, 2026.

Identifies where the criteria are published. Whether identification evidence is relevant to a given engagement is a matter for the practitioner and the control owner.

Rackstamp provides editorial field guidance. IDs, cases, and worksheet entries are fictional examples unless identified otherwise. Distinguish local conventions from adopted standards. Source notes describe the evidence scope; a linked overview is not the full standard or a project approval.

## Related guidance

- [Prepare labeling evidence for an audit or assessment](https://datacenterlabeling.com/guides/labeling-evidence-for-audits)
