SOC 2 Trust Services Criteria: What You Need to Know

Security questionnaires are likely piling up in your inbox. Vendor due diligence is becoming more intense, and your customers are demanding clear proof that you are handling their data securely.
This is where SOC 2 comes in. It is a market-driven assurance framework, not a government regulation, designed to help service organizations demonstrate their control environment. However, organizations cannot rely on assertions alone. They are expected to support their claims with documented controls and audit evidence.
The framework used to evaluate those controls is the SOC 2 Trust Services Criteria.
In this article, I will explain the criteria, how auditors evaluate them, and how to apply them to your specific systems.
What Are SOC 2 Trust Services Criteria?
The SOC 2 Trust Services Criteria (TSC) are a set of criteria established by the AICPA for evaluating the design and operating effectiveness of controls at a service organization.
The criteria apply to assess control design for a Type I report as well as the operational effectiveness of such controls for a Type II report. The current framework is based on the 2017 Trust Services Criteria, which remain widely used today.
You also need to see these points as something other than a checklist. The criteria are principles-based rather than prescriptive. They define objectives organizations must meet, allowing flexibility in how controls are implemented. The organization is then able to implement the controls that are most effective for them.
The 5 SOC 2 Trust Services Criteria Explained

The framework has five different points. It is not a requirement to include all five in the audit. However, security is mandatory, while the other criteria are included based on scope.
Security (Mandatory)
The SOC 2 Security category is a requirement for all SOC 2 services. The Security category evaluates whether systems and information are protected against unauthorized access, use, or disclosure that could compromise the system or the data.
Core areas: This security category includes access controls, risk assessments, and system monitoring and oversight. All SOC 2 audits must include this area of security criteria.
Availability
Availability criteria assess whether systems are operational and accessible as defined by service commitments.
Core areas: Include system performance, network reliability, and disaster recovery or business continuity (DR/BCP). Whatever you promise or agree to with clients regarding a certain percentage of uptime, auditors evaluate system availability against defined service commitments.
Processing Integrity
Processing Integrity evaluates whether your system performs its intended functions without errors, delays, or accidental data manipulation.
Core areas: This category focuses on the accuracy, completeness, and timeliness of data processing. It is highly relevant for platforms that run financial calculations or aggregate critical data.
Confidentiality
Confidentiality criteria assess how you protect sensitive information that is restricted to specific individuals or organizations.
Core areas: This covers the protection of sensitive, non-personal data. Examples include intellectual property, business plans, or trade secrets. Controls typically involve encryption, access restrictions, and strict data disposal procedures.
Privacy
Privacy criteria address how your organization collects, uses, retains, and disposes of personal information.
Core areas: This focuses specifically on the handling of personally identifiable information (PII) throughout its lifecycle. It evaluates your adherence to your own privacy notices and generally accepted privacy principles.
Criteria | Focus | Example Controls |
Security | Protection against unauthorized access | Firewalls, MFA, access logging |
Availability | System uptime and resilience | Disaster recovery plans, backups |
Processing Integrity | Accurate and timely data delivery | Error monitoring, quality assurance |
Confidentiality | Protection of sensitive business data | Encryption, data classification |
Privacy | Secure handling of personal data (PII) | Consent mechanisms, data deletion |
Understanding Common Criteria (CC1–CC9)
When examining the Security category, it aligns with the main control areas that form the basis of a SOC 2 audit. These are the Common Criteria.
Common Criteria (CC): The Common Criteria are a set of nine criteria that form the foundation of the Security category within the Trust Services Criteria.
Since Criteria Security is compulsory, all SOC 2 audits incorporate these nine categories.
Governance (CC1): The control environment, including your organizational structure and code of conduct.
Communication (CC2): The internal and external distribution and allocation of security and protection.
Risk (CC3): How you identify, evaluate, and mitigate potential threats.
Monitoring (CC4): The assessment of the ongoing effectiveness of your controls.
Control Activities (CC5): The organizational risk mitigation policies and procedures.
Logical and Physical Access (CC6): The controls that restrict access to systems, data, and physical environments to authorized users.
System Operations (CC7): How you manage incident response and recovery.
Change Management (CC8): How you safely test and deploy updates to your systems.
Risk Mitigation (CC9): The efforts to identify, assess, and address risks to the achievement of your business goals.
These criteria support the evaluation of controls across selected Trust Services Categories. If you choose to include availability in scope, so too will the common criteria controls for determining risk and change management in the context of the availability of the system.
SOC 2 Type 1 vs Type 2: Where Criteria Fit
You will obtain both Type 1 and Type 2 SOC 2 reports. While both utilize the same Trust Services Criteria, Type 1 and Type 2 reports differ in terms of testing.
Type 1: Evaluates the design and implementation of controls at a specific point in time and answers the following questions: Are your security processes appropriately designed and in place by this date?
Type 2: Evaluates the operating effectiveness of controls over a defined period, ranging from 3 to 12 months, and answers the following questions: Did you actually adhere to your security processes consistently throughout the defined review period (3-12 months)?
Type 1 reports often kick off compliance programs, which later lead to the progression to a Type II report.
How Do You Choose the Right Trust Services Categories?
Not all Trust Services Criteria need to be met; the only mandatory category is security. Typically, companies add the other categories based on customer needs and the company's service offerings and type of data handled.
Shown below is how organizations usually determine the scope of their audits:
SaaS Platforms: Many organizations included in this category use the Availability Trust Services category, and most use Security, as they need to reassure customers that the service is stable and their data is kept secure.
Fintech Companies: Almost all of them must add the Processing Integrity Trust Services category because their core service is reliant on clients’ finances being complete, valid, and accurate.
Healthcare or HR Tech: All providers often include the Privacy category because they handle sensitive personal data.
Evaluate your contracts and service level agreements. If you are making legal commitments about data privacy, the privacy criteria may need to be included to back up those claims.
Common Challenges in Meeting SOC 2 Criteria
Going through an SOC 2 audit is a complicated and costly thing for many organizations. There are many operational challenges that most organizations find to be roadblocks for them.
Checklist mentality: Organizations often try to map generic controls without tailoring them to their specific system risks.
Lack of evidence: Having a written policy is not the end of the process, as auditors need to see that the policy has been enacted.
Over-scoping: Organizations may unnecessarily increase audit scope by including all five categories when only a subset is relevant.
Manual preparation: Tracking policies, procedures, and evidence across dozens of folders creates administrative chaos.
For CPA firms and advisory teams managing these engagements, manual documentation review can limit scalability. Roz is an AI-native engagement and audit-delivery platform that acts as an intelligent enterprise data room.
Firms can use Roz to set up a secure workspace for each client, uploading policies, evidence, and prior reports. The platform can then extract controls, support gap analysis against framework criteria, and generate AI-assisted draft workpapers with a complete audit trail. By structuring documentation and supporting first-pass analysis, Roz helps reduce manual drafting effort and enables teams to manage engagements more efficiently.
Conclusion
The SOC 2 Trust Services Criteria provide a commonly used framework for communicating your security posture to the market. Remember, this is an evaluation framework, not a rigid legal mandate.
You must define your scope carefully. Strong mapping and well-organized evidence are key to a successful examination. Organizations preparing for SOC 2 should evaluate which criteria directly align with their services and risk profile before beginning an audit.
Frequently Asked Questions (FAQs)
Are all 5 criteria required for SOC 2?
No. Security is the only mandatory category. You can choose to include any of the remaining four categories based on your business model and customer commitments.
How do criteria differ in Type 1 vs Type 2?
The criteria remain exactly the same. The difference is the testing period. A Type 1 report looks at control design at a single point in time, while a Type 2 report tests operating effectiveness over a period of time.
Which SOC 2 criteria should SaaS companies choose?
The starting criteria for most SaaS companies are security and availability, since the SaaS uptime is often a primary concern for cloud software customers.
Is SOC 2 mandatory?
No, SOC 2 is not required by any law or regulation. However, it is commonly requested by enterprise customers for doing business, given that most large customers will not sign a deal without getting a SOC 2 report.























































