
The SOC 2 Trust Services Criteria are the five categories that define what a SOC 2 audit actually measures. If you are preparing for SOC 2, you need to know which criteria apply to your organisation before your audit begins.
The American Institute of Certified Public Accountants (AICPA) publishes the Trust Services Criteria. Security is mandatory for every SOC 2 report. Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on the services you provide.
This guide explains each of the five criteria in plain English, what auditors look for, and how to decide which optional criteria your organisation needs.
The SOC 2 Trust Services Criteria form the framework auditors use to evaluate your organisation's controls. Each criterion covers a distinct area of risk related to how you manage customer data and system operations.
Your auditor tests your controls against the criteria you select for your audit scope. The scope you choose affects both the cost and duration of your SOC 2 engagement.
Security is the only mandatory Trust Services Criterion. It is known as the Common Criteria because every SOC 2 report must include it, regardless of scope.
Security evaluates whether your organisation protects systems and data against unauthorised access, both physical and logical. Auditors assess a wide range of controls under this criterion.
The Security criterion is aligned with the COSO Internal Control framework. It also overlaps significantly with ISO 27001 Annex A controls, which helps organisations pursuing both standards.
Availability covers whether your systems are accessible and operational as agreed in your service level commitments. This criterion matters most to organisations providing infrastructure, SaaS, or uptime-dependent services.
Include Availability if your customers rely on continuous access to your platform, or if uptime is written into your service level agreements.
Processing Integrity evaluates whether your system processes data completely, accurately, on time, and only as authorised. It focuses on the reliability of your data processing functions, not just security.
Processing Integrity applies most directly to organisations handling financial transactions, e-commerce orders, or data transformation pipelines.
Confidentiality assesses how your organisation protects information designated as confidential under agreements with customers or partners. This differs from Security, which covers broader system protection.
Include Confidentiality if you handle trade secrets, proprietary business information, or client data covered by non-disclosure agreements.
Privacy evaluates how your organisation collects, uses, retains, discloses, and disposes of personal information. It is assessed against your own published privacy notice and the AICPA Privacy Management Framework.
For UK and EU organisations, the Privacy criterion complements existing GDPR compliance work. Many controls required for GDPR can be reused as evidence for this criterion.
Security applies to every SOC 2 audit. Beyond that, your scope should reflect what your customers actually care about and what your service commitments promise.
Adding unnecessary criteria increases audit cost and duration without adding customer value. Most SaaS companies start with Security and Availability, then expand scope as customer requirements grow.
The Trust Services Criteria should not be assessed in isolation. Security controls overlap with ISO 27001. Privacy controls overlap with GDPR. Treating SOC 2 as part of an integrated GRC programme reduces duplicate work.
The GRC Index assessment evaluates your organisation against SOC 2 Trust Services Criteria as part of the Information Security and Data Security domains. This gives you a single benchmark score across all your compliance obligations, not five separate checklists.
Unsure which Trust Services Criteria apply to your organisation?
The GRC Index assessment is free, independent, and benchmarked against AICPA Trust Services Criteria.
You receive a GRC Score, a public profile in the Index, and a prioritised improvement plan.
Start your assessment at grci.net | It takes under 20 minutes to complete.
The SOC 2 Trust Services Criteria are five categories defined by the AICPA: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Every SOC 2 audit must include Security. The other four are selected based on the services your organisation provides.
Security is the only mandatory criterion. It is known as the Common Criteria and covers access controls, monitoring, and incident response. Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on your services.
Select criteria based on what your customers care about and what your service commitments state. If uptime matters to customers, include Availability. If you process financial transactions, include Processing Integrity. If you handle proprietary or personal data, include Confidentiality or Privacy.
Security covers protecting systems generally from unauthorised access. Confidentiality specifically covers information designated as confidential, such as trade secrets or client data under a non-disclosure agreement. Security is mandatory; Confidentiality is optional.
Yes. The SOC 2 Security criterion overlaps significantly with ISO 27001 Annex A controls covering access management, risk management, and incident response. Organisations pursuing both standards can often reuse policies and evidence across audits.
© 2025 GRC Index. All rights reserved.