How to read aa GRC Score
Governance

SOC 2 Trust Services Criteria Explained

August 13, 2026

The SOC 2 Trust Services Criteria are the five categories that define what a SOC 2 audit actually measures. If you are preparing for SOC 2, you need to know which criteria apply to your organisation before your audit begins.

The American Institute of Certified Public Accountants (AICPA) publishes the Trust Services Criteria. Security is mandatory for every SOC 2 report. Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on the services you provide.

This guide explains each of the five criteria in plain English, what auditors look for, and how to decide which optional criteria your organisation needs.

What Are the SOC 2 Trust Services Criteria?

The SOC 2 Trust Services Criteria form the framework auditors use to evaluate your organisation's controls. Each criterion covers a distinct area of risk related to how you manage customer data and system operations.

Your auditor tests your controls against the criteria you select for your audit scope. The scope you choose affects both the cost and duration of your SOC 2 engagement.

The Five Trust Services Criteria at a Glance

  1. Security (Required):  Protection against unauthorised access to systems and data.
  2. Availability:  Systems are accessible and operational as agreed with customers.
  3. Processing Integrity:  Data processing is complete, accurate, and authorised.
  4. Confidentiality:  Confidential information is protected from unauthorised disclosure.
  5. Privacy:  Personal information is collected, used, and disposed of appropriately.

1. Security: The Common Criteria

Security is the only mandatory Trust Services Criterion. It is known as the Common Criteria because every SOC 2 report must include it, regardless of scope.

Security evaluates whether your organisation protects systems and data against unauthorised access, both physical and logical. Auditors assess a wide range of controls under this criterion.

What Auditors Test Under Security

  • Access controls: user provisioning, deprovisioning, and role-based permissions
  • Network security: firewalls, intrusion detection, and network segmentation
  • Change management: how software and infrastructure changes are approved and tracked
  • Incident response: how security incidents are detected, escalated, and resolved
  • Risk assessment: how your organisation identifies and manages security risks

The Security criterion is aligned with the COSO Internal Control framework. It also overlaps significantly with ISO 27001 Annex A controls, which helps organisations pursuing both standards.

2. Availability

Availability covers whether your systems are accessible and operational as agreed in your service level commitments. This criterion matters most to organisations providing infrastructure, SaaS, or uptime-dependent services.

What Auditors Test Under Availability

  • Performance monitoring: systems and alerting for capacity and uptime
  • Disaster recovery: backup procedures and recovery time objectives
  • Business continuity planning: documented plans for service disruption scenarios
  • Environmental controls: physical safeguards for data centres and server rooms

Include Availability if your customers rely on continuous access to your platform, or if uptime is written into your service level agreements.

3. Processing Integrity

Processing Integrity evaluates whether your system processes data completely, accurately, on time, and only as authorised. It focuses on the reliability of your data processing functions, not just security.

What Auditors Test Under Processing Integrity

  • Data input validation: checks that prevent incorrect or incomplete data entry
  • Processing accuracy: controls that confirm transactions are processed correctly
  • Output completeness: confirmation that all expected outputs are delivered on time
  • Quality assurance: testing procedures before processing changes go live

Processing Integrity applies most directly to organisations handling financial transactions, e-commerce orders, or data transformation pipelines.

4. Confidentiality

Confidentiality assesses how your organisation protects information designated as confidential under agreements with customers or partners. This differs from Security, which covers broader system protection.

What Auditors Test Under Confidentiality

  • Data classification: policies that identify and label confidential information
  • Encryption: protection of confidential data at rest and in transit
  • Access restriction: limiting confidential data access to authorised personnel only
  • Secure disposal: procedures for destroying confidential data when no longer needed

Include Confidentiality if you handle trade secrets, proprietary business information, or client data covered by non-disclosure agreements.

5. Privacy

Privacy evaluates how your organisation collects, uses, retains, discloses, and disposes of personal information. It is assessed against your own published privacy notice and the AICPA Privacy Management Framework.

What Auditors Test Under Privacy

  • Notice and consent: how you inform individuals about data collection
  • Collection limitation: whether you collect only the data you need
  • Retention and disposal: how long personal data is kept and how it is deleted
  • Third-party disclosure: controls over sharing personal data with vendors or partners

For UK and EU organisations, the Privacy criterion complements existing GDPR compliance work. Many controls required for GDPR can be reused as evidence for this criterion.

How to Choose Which Criteria Apply to You

Security applies to every SOC 2 audit. Beyond that, your scope should reflect what your customers actually care about and what your service commitments promise.

  • Ask what your sales team hears: if prospects ask about uptime, include Availability
  • Review your contracts: if SLAs mention data accuracy, include Processing Integrity
  • Check your data types: if you hold proprietary client data, include Confidentiality
  • Consider your data subjects: if you process personal data at scale, include Privacy

Adding unnecessary criteria increases audit cost and duration without adding customer value. Most SaaS companies start with Security and Availability, then expand scope as customer requirements grow.

Trust Services Criteria and Your Wider GRC Programme

The Trust Services Criteria should not be assessed in isolation. Security controls overlap with ISO 27001. Privacy controls overlap with GDPR. Treating SOC 2 as part of an integrated GRC programme reduces duplicate work.

The GRC Index assessment evaluates your organisation against SOC 2 Trust Services Criteria as part of the Information Security and Data Security domains. This gives you a single benchmark score across all your compliance obligations, not five separate checklists.

Benchmark Your SOC 2 Readiness Today

Unsure which Trust Services Criteria apply to your organisation?

The GRC Index assessment is free, independent, and benchmarked against AICPA Trust Services Criteria.

You receive a GRC Score, a public profile in the Index, and a prioritised improvement plan.

Start your assessment at grci.net |  It takes under 20 minutes to complete.

Frequently Asked Questions About SOC 2 Trust Services Criteria

What are the SOC 2 Trust Services Criteria?

The SOC 2 Trust Services Criteria are five categories defined by the AICPA: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Every SOC 2 audit must include Security. The other four are selected based on the services your organisation provides.

Which Trust Services Criteria are mandatory for SOC 2?

Security is the only mandatory criterion. It is known as the Common Criteria and covers access controls, monitoring, and incident response. Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on your services.

How do I know which optional criteria to include in my SOC 2 audit?

Select criteria based on what your customers care about and what your service commitments state. If uptime matters to customers, include Availability. If you process financial transactions, include Processing Integrity. If you handle proprietary or personal data, include Confidentiality or Privacy.

What is the difference between SOC 2 Security and Confidentiality criteria?

Security covers protecting systems generally from unauthorised access. Confidentiality specifically covers information designated as confidential, such as trade secrets or client data under a non-disclosure agreement. Security is mandatory; Confidentiality is optional.

Do the SOC 2 Trust Services Criteria align with ISO 27001?

Yes. The SOC 2 Security criterion overlaps significantly with ISO 27001 Annex A controls covering access management, risk management, and incident response. Organisations pursuing both standards can often reuse policies and evidence across audits.

GRC Assessment & Benchmarking

Evaluate your governance, risk, and compliance performance. Receive your GRC Score. Join organisations & professionals building verifiable, standards-based trust.