CPA ISC Exam Topics
The 2026 ISC blueprint has three Areas: Information Systems and Data Management at 35 to 45 percent, Security, Confidentiality and Privacy at 35 to 45 percent, and Considerations for SOC Engagements at 15 to 25 percent.
- It covers system risks, data, safeguards, incident response and SOC reporting.
On this page11 sections
- ISC blueprint at a glance
- Area I: Information Systems and Data Management
- Area II: Security, Confidentiality and Privacy
- Area III: Considerations for SOC Engagements
- Skills tested across the blueprint
- Use weights to allocate study time
- How to read representative tasks
- Examples of applying the blueprint
- Study scope and weight without overfitting
- Use a topic map to find gaps
- Translate topics into study tasks
ISC blueprint at a glance
| Area | Weight | Representative scope |
|---|---|---|
| Information Systems and Data Management | 35-45% | IT architecture, business processes, data lifecycle, processing integrity, system availability and change management |
| Security, Confidentiality and Privacy | 35-45% | Frameworks, threats, safeguards, privacy, confidentiality and incident response |
| Considerations for SOC Engagements | 15-25% | SOC report purpose and content, criteria, planning, procedures and reporting |
The allocation ranges show the approximate share of the section devoted to each Area. They are not exact counts of questions, and the low or high end need not occur in every form. The blueprint also identifies representative tasks, skill levels and reference literature. Its tasks guide preparation but are not an exhaustive list of every possible item.
Area I: Information Systems and Data Management
Area I covers modern IT systems and data management. Candidates should understand cloud infrastructure, platform and software services; enterprise and accounting information systems; business processes; system availability; and IT change management. The blueprint connects those systems to processing integrity and the risks that controls are meant to address.
Data topics follow information through its lifecycle. The work can include extracting data, storing and using it, querying structured data with SQL, and integrating information from different sources. Candidates need to consider completeness and accuracy before relying on analytics. A technically correct analysis built on incomplete source data may still produce an unreliable conclusion.
Business process models help explain how transactions and information move through an organization. Study the relationship among process steps, systems, data and controls. When a scenario describes a change to an application or a cloud service, identify the affected process and the potential impact on availability, integrity or access.
Area II: Security, Confidentiality and Privacy
Area II covers selected portions of regulations, standards and frameworks used in designing and evaluating security, confidentiality and privacy controls. It includes threats and attacks, including cyber threats; controls to prevent, detect or respond; protection of confidential information; privacy handling; control testing; and incident response.
Separate the objective from the mechanism. A firewall, access review or encryption process is a control or tool; the objective concerns the risk it addresses. A good answer evaluates whether a described control is appropriate to the risk, how it operates and what evidence could support a conclusion. Distinguish a design deficiency from a deviation in operation when facts support that distinction.
Privacy and confidentiality overlap with security but are not interchangeable. Security concerns protection against unauthorized access or disruption. Confidentiality is about limiting access to designated information. Privacy addresses appropriate collection, use, retention and disclosure of personal information. A question may combine them, so identify the particular obligation described.
Area III: Considerations for SOC Engagements
Area III focuses on matters specific to System and Organization Controls engagements. Topics include report form and content, management assertions, intended users and purposes of SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports. Candidates should understand planning, procedures and reporting considerations.
The Area also includes system description criteria, trust services criteria for SOC 2, and complementary user-entity and subservice-organization controls. A report may rely on controls performed by the customer or another service provider. Understand how those complementary controls affect what the report covers and what the user may need to do.
Do not treat a SOC report as a blanket assurance that a service organization is risk-free. Interpret it in light of its type, criteria, period, scope, intended users and findings. A SOC 1 engagement concerns controls relevant to user entities’ internal control over financial reporting; SOC 2 is organized around trust services criteria for relevant service commitments and system requirements.
Skills tested across the blueprint
The ISC section assesses remembering and understanding across all Areas, application across all Areas, and analysis in Areas I and II. Candidates must do more than recite terminology. They may apply a concept to a business process, evaluate evidence or detect a control weakness.
Practise by explaining a chain: system or data, risk, control objective, control activity and evidence. For SOC cases, add report type, criteria, intended user and period. This structure helps you avoid memorizing isolated definitions without understanding how the pieces work together.
Use weights to allocate study time
The two largest Areas each carry 35 to 45 percent. Give both substantial attention, then reserve time for SOC topics even though their range is 15 to 25 percent. Do not treat the smaller Area as optional. A candidate unfamiliar with SOC report distinctions may need more time there than the range alone would suggest.
Use a diagnostic to refine the allocation. Complete mixed questions and identify whether errors arise from terminology, system reasoning, evidence evaluation or report interpretation. Prioritize recurring gaps while maintaining cumulative review in the other Areas. The blueprint weight is a guide to exam coverage, not a personal study-hours formula.
How to read representative tasks
Each task in the detailed blueprint describes work a newly licensed CPA may be expected to perform. Read the verb carefully: identify, explain, evaluate, determine or recommend can call for different depth. A task that asks you to assess suitability requires applying facts to a criterion, not merely naming a framework.
The official blueprint is the source for eligible content, task descriptions and weight ranges. Use it with the exam format guide and a practice plan. A commercial course outline can help organize study but should not replace the official content map.
Examples of applying the blueprint
Consider a payroll process that sends employee changes from a human-resources system to a payroll application. A useful analysis identifies the source of the change, who can approve it, how it is transferred, what validates the data and how exceptions are resolved. This touches process understanding, data integrity and access controls. A question may focus on one part, so read the requirement carefully before broadening the analysis.
For a security case, distinguish the threat from the control. A phishing attempt is a threat; multifactor authentication or user training may be control responses. The task may ask whether the response is suitable, whether the evidence shows it operated or what additional evidence is needed. Naming a safeguard without considering the risk and evidence is incomplete reasoning.
For a SOC case, identify the service commitment and criteria before interpreting a finding. If an exception concerns a control that the customer must perform, determine whether it is a complementary user-entity control and whether the described customer evidence exists. The provider report alone may not answer a question about the customer’s own controls.
These scenarios illustrate a method, not an exhaustive exam topic list. The official blueprint defines the detailed groups and representative tasks. Use it to check coverage and use practice material to learn how the concepts appear in different fact patterns.
Study scope and weight without overfitting
Weight ranges are useful for broad allocation, but they do not guarantee that every individual form contains topics in exact proportions. The detailed blueprint describes representative tasks, not a list to memorize as a script. Candidates should learn the underlying concepts and be ready to apply them when a scenario combines areas.
Information Systems and Data Management and Security, Confidentiality and Privacy each represent 35 to 45 percent. One practical implication is to maintain two substantial strands of study. Do not finish one Area completely and leave the other for later if doing so creates a long gap in retrieval. Alternate coverage once you understand the foundational terms.
SOC Engagements carry 15 to 25 percent, but the subject has specialized vocabulary that can require focused work. Create a concise comparison of report purpose, intended users, system description, criteria, period and complementary controls. Then practise interpreting what a report does and does not support. Avoid memorizing a label without applying it to the facts.
The blueprint’s skill allocation also affects preparation. Remembering terms is necessary but not sufficient. Application and analysis require evaluating a control in context, understanding how information moves and assessing whether evidence is persuasive. Use question explanations to identify the mental operation required, not only the topic name.
Use a topic map to find gaps
A topic map can turn the detailed blueprint into a practical study checklist. Under systems, list architecture, business process, data lifecycle, availability and change management. Under security and privacy, list threats, controls, frameworks and incident response. Under SOC, list report purposes, criteria, intended users and complementary controls. Mark each item only after you can explain or apply it, not after watching a lesson.
When a task verb asks you to evaluate, state the criterion and compare the facts to it. When it asks you to identify, determine which fact distinguishes the likely issue from alternatives. When it asks you to recommend, connect the action to the risk. This reading discipline helps translate blueprint tasks into answer behavior.
Keep notes concise. A small chart that contrasts report types or control objectives is more useful for retrieval than pages of copied definitions. Add an example and a common confusion to each entry. Then close the notes and reconstruct the comparison from memory.
Translate topics into study tasks
For system architecture, sketch where infrastructure, platforms, applications and data sit, then note which party is responsible for each relevant control. For a data lifecycle topic, trace source, extraction, transformation, storage and use. These diagrams can reveal gaps that a glossary alone does not show.
For security and privacy topics, organize notes around objectives and risks rather than a long list of tools. A control matters because of what it prevents or detects. Practise explaining the evidence that would demonstrate design and the evidence that would demonstrate operation.
For SOC, compare report purpose, intended audience, criteria, covered period and complementary controls. Then apply the comparison to a short scenario. This is more durable than memorizing report names without knowing the limits of each report.
Common questions
What are the three ISC blueprint areas?
Information Systems and Data Management; Security, Confidentiality and Privacy; and Considerations for SOC Engagements.
Which ISC areas have the greatest weight?
Information Systems and Data Management and Security, Confidentiality and Privacy are each weighted 35 to 45 percent.
Does the blueprint list every possible question?
No. It provides representative tasks and eligible content, not an exhaustive list of exam items.