SOC 2 Trust Services Criteria: A Practical View for Security Teams

SOC 2 Trust Services Criteria: A Practical View for Security Teams

Updated:

May 8, 2026

SOC 2 audits are structured around the Trust Services Criteria, a framework developed by the AICPA. These criteria outline expectations for managing data securely and responsibly.

The core criteria, established in 2017, remain unchanged. However, in 2022, the AICPA issued revised points of focus to address evolving technologies, threats, and regulatory requirements.

The Trust Services Criteria guide service organizations in shaping their cybersecurity programs. They serve as reference points during audits, with organizations responsible for designing their own SOC 2 controls.

Security is mandatory in every SOC 2 audit, while the inclusion of Availability, Processing Integrity, Confidentiality, and Privacy depends on the services provided and the nature of the data handled.

Organizations often start with criteria already addressed in their operations and may incorporate additional criteria over time as risks and customer needs evolve.

Key Takeaways

What Are the Five AICPA Trust Services Criteria for SOC 2?

The AICPA Trust Services Criteria (TSC) form the foundation of SOC 2 audits. These criteria define the areas organizations must address to demonstrate sound practices in data security, system reliability, and privacy. Each criterion outlines specific control objectives and can be selected based on the services a company provides.

5 AICPA Trust Services Criteria for SOC 2

1. Security

The Security Trust Services Criterion focuses on protecting systems and data from unauthorized access, disclosure, or modification.

Also referred to as the Common Criteria, this area confirms that a service organization has safeguards in place to prevent intrusion, misuse, and operational disruption. Controls under this criterion typically include access management, firewalls, encryption, and intrusion detection.

Security is mandatory in every SOC 2 audit. The remaining four criteria are optional and can be included depending on your organization’s services and risk profile.

Common Criteria (CC1–CC9):

Legal Considerations:

Compliance with regulations such as the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) is essential, as they mandate stringent security measures to protect personal and sensitive data.

2. Availability

Availability evaluates whether systems remain accessible and operational when needed, both for internal users and external customers.

This includes mechanisms like data replication, disaster recovery solutions, failover strategies, and uptime monitoring. If a natural disaster impacts a facility, resilient design—such as backup power systems and redundant infrastructure—should keep services online.

Consider including Availability in your SOC 2 scope if:

Additional Criteria (A-series):

Legal Considerations:

Regulations like the Sarbanes-Oxley Act (SOX) require organizations to have controls ensuring system availability to maintain accurate financial reporting.

3. Processing Integrity

Processing Integrity reviews whether systems deliver accurate and timely processing of data, without unintended delays, errors, or manipulation.

It focuses on whether a system operates correctly rather than whether the data input is accurate. For example, if an online order system lets a customer complete a purchase and sends the item to the address provided—even if that address was typed incorrectly—the system still meets the Processing Integrity requirement.

Consider including this criterion if:

Additional Criteria (PI-series):

Legal Considerations:

Compliance with financial regulations, such as those enforced by the Securities and Exchange Commission (SEC), necessitates accurate and authorized data processing to ensure reliable financial statements.

4. Confidentiality

Confidentiality addresses how sensitive information is stored, accessed, and shared within the organization.

This includes implementing policies for data classification, restricting access to authorized personnel, and encrypting confidential records. Examples of protected information include contracts, financial statements, business strategies, and proprietary designs.

Consider including Confidentiality if:

Additional Criteria (C-series):

Legal Considerations:

Laws like the Trade Secrets Act and contractual obligations require organizations to implement measures safeguarding confidential information.

5. Privacy

The Privacy criterion assesses how personal data is collected, stored, used, and shared in line with the AICPA’s Generally Accepted Privacy Principles (GAPP).

It focuses specifically on personally identifiable information (PII) such as names, email addresses, home addresses, and Social Security numbers. For some sectors, this also extends to data about health, biometric identifiers, or demographic attributes.

Consider including Privacy if:

Additional Criteria (P-series):

Legal Considerations:

Regulations such as GDPR and the California Consumer Privacy Act (CCPA) impose strict requirements on how personal information is handled, granting individuals rights over their data and mandating organizations to implement robust privacy controls.

What Are SOC 2 Compliance Requirements?

SOC 2 requirements are risk based and depend on the Trust Services Criteria included in scope, with Security always required. You meet SOC 2 expectations when management defines the system boundary, selects applicable criteria, designs and implements controls that address those criteria, documents policies and evidence, and completes an independent CPA examination.

  1. Define scope: system description, boundaries, services, locations, and third party dependencies.
  2. Choose criteria: Security is required; add other criteria only if relevant to customer commitments and how your service works.
  3. Implement controls: policies, technical safeguards, operational procedures, and governance that address the selected criteria.
  4. Collect evidence: tickets, logs, access reviews, training records, incident records, vendor reviews, change records, and other artifacts that prove controls operate as described.
  5. Complete the audit:
    1. Type 1: evaluates design of controls at a point in time.
    2. Type 2: evaluates operating effectiveness of controls over a defined period.

Which Criteria are Applicable to SOC 2 Engagements?

The applicable criteria in a SOC 2 engagement are the Trust Services Criteria categories that management selects for the report, with Security always included. Availability, Processing Integrity, Confidentiality, and Privacy are included only when they match what the service promises customers and what data the service handles.

What if a Client Is Asking for All Criteria to Be Included?

Some clients or prospects request that all five criteria be included in a SOC 2 report—even when not all of them apply. This usually stems from a lack of clarity on what each criterion represents. Rather than defaulting to a full-scope audit, it’s best to have a direct conversation with the client.

Service providers often find that bringing the auditor into the conversation helps resolve confusion. This discussion helps explain each criterion’s intent and allows both parties to agree on a relevant and efficient scope for the audit.

Can Testing Occur in a SOC 2 Outside of the SOC 2 Criteria?

Yes, SOC 2 audits allow flexibility through a structure known as SOC 2+. This format permits organizations to map their controls against other frameworks, certifications, or regulatory standards.

Common examples include:

SOC 2+ helps organizations meet multiple assurance requirements within a single examination. This is especially useful for service providers who need to demonstrate compliance across several regulatory domains without running redundant audits.

Points of Focus in a SOC 2

The concept of “points of focus” became part of SOC 2 reporting with the release of the 2017 Trust Services Criteria. While new to SOC 2 at the time, points of focus had already been part of the COSO internal control framework. Each Trust Services Criterion includes an associated set of points of focus. These are not mandatory requirements but serve as guidance that helps shape the design, implementation, and ongoing operation of the controls tied to each criterion.

The 2017 Trust Services Criteria include over 200 points of focus just under the Security (or Common Criteria) category. When expanded to cover all five criteria—Security, Availability, Processing Integrity, Confidentiality, and Privacy—the list grows to 61 criteria with nearly 300 points of focus in total.

These numbers can seem overwhelming, but they largely reflect best practices that SOC 2 auditors already expect. The 2017 update simply documented them more explicitly. According to AICPA guidance (TSP 100.07), a service organization is not required to meet every point of focus. Instead, they serve as examples or suggestions of how organizations might meet the criteria.

Frequently Asked Questions

What are the SOC 2 Trust Services Criteria

The Trust Services Criteria are AICPA control criteria used in SOC 2 engagements to evaluate and report on controls over the security and related attributes of the systems that deliver a service.

Which Trust Services Criteria are required vs optional

Security is the baseline for every SOC 2 report, and the other categories are added when they match the service commitments and customer expectations for availability, processing integrity, confidentiality, or privacy.

What “common criteria” means in day-to-day security work

Common criteria are the security foundation that applies across SOC 2, and many guides describe them as CC1 to CC9, which security teams typically translate into governance and oversight, risk assessment, access control, change management, system operations, monitoring, incident response, and vendor management evidence.

How to pick the right extra categories for your scope

Availability fits when you make uptime or resilience commitments, confidentiality fits when you commit to restricting access to sensitive data, privacy fits when you handle personal information under stated privacy commitments, and processing integrity fits when you commit to complete, valid, accurate, and timely processing for defined transactions.

What auditors usually want to see as evidence for TSC

Auditors typically look for documented policies and procedures plus proof the controls ran as described, such as access reviews, MFA and privileged access settings, change tickets and approvals, vulnerability handling records, incident response records, monitoring alerts, and a clear list of complementary user entity controls that customers must operate.

My sales team says a customer needs SOC 2 soon. What is the fastest practical path

A SOC 2 Type I report can be the fastest first milestone when timing is tight because it covers control design at a point in time, while Type II needs a measurement period to show controls operated over time.

I am a security lead. What should I do in the first week to avoid audit rework

Start with a system scope statement, a data flow map for in-scope data, an inventory of in-scope apps and vendors, and an evidence plan that assigns an owner and a source system for each control so evidence collection does not turn into a late scramble.

I received a SOC 2 report from a vendor. What should I check first in real life

Check the report period, the system and services in scope, the Trust Services Criteria included, the auditor’s opinion, and any listed complementary user entity controls, because those details tell you what was actually reviewed and what you still must operate on your side.

What are the 5 trust principles of SOC 2?

The five SOC 2 Trust Services Criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy.

What is SOC 2 Type 2 compliance checklist?

A practical SOC 2 Type 2 checklist covers the steps below

– Pick Type 2 and set the testing period;

– Define the system scope and boundaries;

– Choose the Trust Services Criteria needed (Security is always included);

– Document controls and the system description used in the report package;

– Run the controls for the full period and collect evidence as you go;

– Do a readiness or SOC 2 gap assessment, then fix gaps before audit testing starts;

– Engage an independent CPA firm to perform the examination and issue the report;

What does the security criterion in SOC2 focus on?

The SOC 2 Security criterion focuses on protecting the system against unauthorized access and security events, and it is typically evaluated through Common Criteria themes such as governance and oversight (CC1), communication (CC2), risk assessment (CC3), monitoring (CC4), control activities (CC5), logical and physical access controls (CC6), system operations (CC7), change management (CC8), and risk mitigation (CC9).