PocketCPA

What is tested on the ISC CPA Exam?

The AICPA blueprint splits ISC into 3 content areas: Information Systems and Data Management at 35 to 45% of the section, Security, Confidentiality and Privacy at 35 to 45% of the section, Considerations for System and Organization Controls (SOC) Engagements at 15 to 25% of the section. Below them sit 8 groups.

AreaContentScore weight
ISC.IInformation Systems and Data Management35 to 45%
ISC.IISecurity, Confidentiality and Privacy35 to 45%
ISC.IIIConsiderations for System and Organization Controls (SOC) Engagements15 to 25%

Which area of ISC carries the most weight?

Information Systems and Data Management and Security, Confidentiality and Privacy are jointly the heaviest areas of ISC, each at 35 to 45% of the section.

How many topics are in the ISC blueprint?

The ISC blueprint lists 3 areas and 8 groups, without naming individual topics. Each area carries a published score weight range rather than a fixed percentage, so the exact mix varies between sittings.

What skill levels does the CPA Exam test?

The AICPA tests CPA Exam content at 3 skill levels: Remembering, Application, Analysis. The level assigned to a given ISC topic is published in the AICPA blueprint document itself.

Which accounting standards does the ISC CPA Exam test?

ISC is tested against 33 pieces of authoritative literature, among them AICPA Trust Services Criteria, AT-C 320, AU-C 402, COBIT, COSO, GAO Green Book, NIST SP 800-34, NIST SP 800-53, NIST SP 800-145, Sarbanes-Oxley Act. The remaining 23 are on the CPA Exam standards page, each listed against the blueprint groups that test it. The AICPA blueprint names the topics but not the standards behind them outside FAR, so this mapping is built from PocketCPA's own lesson citations and item sources rather than published by the AICPA.

What is tested in ISC Area I, Information Systems and Data Management?

ISC Area I, Information Systems and Data Management, is 35 to 45% of the section and covers 2 groups: Information systems, Data management.

GroupContentAuthoritative literature
ISC.I.AInformation systemsAICPA Trust Services Criteria, AT-C 320, AU-C 402, COBIT, COSO, GAO Green Book, NIST SP 800-34, NIST SP 800-53, NIST SP 800-145, Sarbanes-Oxley Act, SSAE 18
ISC.I.BData managementNIST SP 800-34

What is tested in ISC Area II, Security, Confidentiality and Privacy?

ISC Area II, Security, Confidentiality and Privacy, is 35 to 45% of the section and covers 4 groups: Regulations, standards and frameworks, Security, Confidentiality and privacy, Incident response.

GroupContentAuthoritative literature
ISC.II.ARegulations, standards and frameworksAICPA Trust Services Criteria, AT-C 205, AT-C 320, CCPA, COBIT, COSO, GAO Green Book, GDPR, Gramm-Leach-Bliley Act, HIPAA, ISO/IEC 27001, ISO/IEC 27002, ITIL, NIST Cybersecurity Framework, NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, PCI DSS, Sarbanes-Oxley Act, SSAE 18
ISC.II.BSecurityCOSO, NIST SP 800-53, NIST SP 800-63B, NIST SP 800-207, NIST SP 800-63-4
ISC.II.CConfidentiality and privacyAICPA Trust Services Criteria, CCPA, GDPR, Gramm-Leach-Bliley Act, HIPAA, NIST SP 800-53, NIST SP 800-88
ISC.II.DIncident responseNIST Cybersecurity Framework, NIST SP 800-34, NIST SP 800-53, NIST SP 800-61, NIST SP 800-61r

What is tested in ISC Area III, Considerations for System and Organization Controls (SOC) Engagements?

ISC Area III, Considerations for System and Organization Controls (SOC) Engagements, is 15 to 25% of the section and covers 2 groups: Considerations specific to planning and performing a SOC engagement, Considerations specific to reporting on a SOC engagement.

GroupContentAuthoritative literature
ISC.III.AConsiderations specific to planning and performing a SOC engagementAICPA Trust Services Criteria, AT-C 105, AT-C 205, AT-C 206, AT-C 320, AU-C 320, COSO, SSAE 18, SSAE 21
ISC.III.BConsiderations specific to reporting on a SOC engagementAICPA Trust Services Criteria, AT-C 105, AT-C 205, AT-C 320, AU-C 402, COSO, SSAE 18, SSAE 21

Areas, weights, groups and topics are the AICPA published blueprint. Pass rates are the AICPA published candidate pass rates for 2026 through Q2, read from AICPA & CIMA on 2026-08-17. The AICPA publishes them quarterly.

ISC pass rate, format and score weighting

See also