The AICPA published criteria. You wrote the controls.
The common read: The AICPA publishes the list of SOC 2 controls, so the percentage on my readiness meter is my distance from a requirement somebody outside my company set.
The vendor's library. The AICPA publishes criteria, attaches no controls to them, and the denominator on that meter was written by a product team who have never seen your infrastructure. A criterion states what has to be achieved. It does not name the approver, the queue the request sits in, or the number of business days.
The sentences that do name them are controls, and they are yours: management prepares the description of the system, states the controls in it, and asserts that those controls achieve the service commitments and system requirements management itself set. The firm then opines on whether the controls STATED IN THE DESCRIPTION were suitably designed and whether they operated. Read that clause the way an auditor reads it. The subject of the opinion is your sentence, and the criteria are the benchmark it is measured against.
The other thing stuck teams wait for does not exist either. Points of focus look like a checklist under each criterion, and the trust services criteria say that use of the criteria does not require an assessment of whether each point of focus is addressed. There is no list and no mandatory sub-list. What you have is a sentence and the record it emits: a quarterly access review is not a control until it names the completion record in your identity provider and its reviewed-on date field.
It arrives as "the auditor changed the requirements on us" in week three of fieldwork, filed against the audit firm, and the requirement was a sentence your platform imported from a template that nobody who runs the system had ever read. The cheapest hour of the whole engagement is the one where the people who operate each system read their own control statements out loud and say which artifact, which emitter and which date field answers each one.
