
SOC 2 is one of the most respected compliance standards today. It provides a framework for implementing data security best practices and offers a verified method for evaluating and certifying your security infrastructure. The security policies and practices for SOC 2 are organized around five categories known as the Trust Services Criteria (TSC) — previously called the Trust Service Principles (TCPs) prior to 2018. During your SOC 2 audit, your auditor will assess your security infrastructure against these five criteria.
If you’re preparing to get your SOC 2, it’s important to know how each of the Trust Services Criteria applies to your business and what controls are needed in each. This article will explain each of the TSC areas and how they might apply to your SOC 2.
What are the 5 Trust Services Criteria?
The Trust Services Criteria are five categories the American Institute of Certified Public Accountants publishes for evaluating a service organization's controls. The AICPA's Assurance Services Executive Committee, known as ASEC, sets and maintains them. The current version is the 2017 Trust Services Criteria with revised points of focus issued in 2022, published under TSP Section 100.
Together, the five categories contain 61 individual criteria. Thirty-three of those sit under Security. The remaining 28 are distributed across the other four.
One naming point trips people up regularly. Before the 2017 revision, these categories were called the Trust Services Principles. You'll still see that term in vendor questionnaires and older audit reports. It refers to the same five categories.
The criteria describe outcomes, not controls. The AICPA doesn't tell you to rotate access keys every 90 days or to run quarterly access reviews. It states the outcome your controls need to achieve, and you design the controls that get you there. That's why two companies with the same SOC 2 scope can have entirely different control sets and both pass.
Why Security is the only required category
Security is required because its criteria are the shared foundation the other four categories build on. That's also why it's called the common criteria. Those 33 criteria are common to all five categories, so Availability, Confidentiality, Processing Integrity, and Privacy each layer additional criteria on top of Security rather than standing alone. You can't scope Availability without Security. The reverse works fine.
This matters for a reason that has nothing to do with audit mechanics. Teams preparing for their first SOC 2 audit often assume a Security-only report looks thin to buyers, so they scope in extra categories defensively. It's the most common scoping mistake, and it's expensive.
A Security-only SOC 2 is a complete, legitimate report, and it satisfies the large majority of enterprise procurement requests on its own. Buyers rarely ask for categories you haven't committed to contractually, and a well-run security review process handles the occasional question faster than an unnecessary audit category ever will.
There's a second reason to resist over-scoping. Every criterion you add is one you have to keep passing, year after year. An elective category that seemed harmless during audit prep becomes a permanent evidence obligation, and a qualified opinion on a category you never needed to report on does more damage in a deal review than never having reported on it.
The 33 common criteria behind the Security category
The Security category breaks into nine groups. Each group contains individually testable criteria, numbered as CC1.1, CC1.2, and so on through CC9.2.
Two patterns are worth noticing here.
CC1 through CC5 reads like governance rather than security, and there's a reason. They derive from the COSO internal control framework, which the AICPA adopted as the structural backbone of the common criteria. If your first draft of a SOC 2 control set is all encryption and access reviews with nothing about board oversight or fraud risk, you've built for CC6 and skipped a third of the requirements.
CC6 is the largest group at eight criteria, and it carries the heaviest evidence load in the whole common criteria set. Provisioning, deprovisioning, authentication, network segmentation, physical access, and data disposal each need their own evidence trail across the full observation period. If you're budgeting preparation time by group, budget most of it here.
That evidence load is the part teams underestimate. Each of the 61 criteria needs its own trail across the full observation period, and the mapping between a control, the evidence it produces, and the criteria it satisfies is rarely one to one. SOC 2 compliance software can handle this by tying evidence directly to individual criteria codes and testing continuously, which is how teams manage a multi-category scope without maintaining a spreadsheet of it. Vanta's SOC 2 framework maps automated tests to each criterion so gaps surface before an auditor finds them.
Which organizational systems do the Trust Services Criteria apply to?
Because SOC 2 is designed for data security, many people assume it only applies to your digital infrastructure and systems, but SOC 2 encompasses much more. It includes controls that protect your data from various risks across your entire organization, such as employee negligence or malice, gaps in physical security, and risks from third-parties.
Below are the systems and departments that SOC 2 impacts:
- Physical infrastructure: Where your data is stored (server room, data center) and security practices to control access to these spaces (employee badges, user authentication).
- Digital infrastructure: How your network is configured to segregate data that limits internal and external access.
- Third-party vendors: How you close security gaps and prevent risks from third-party tools and applications.
- Internal operations: Which procedures and practices your staff and contractors follow.
- People: What hiring practices you have in place (background checks) as well as how you onboard and offboard employee’s access to systems.
- Leadership: How your leaders communicate and prioritize security across the organization.
Because SOC 2 touches so many teams and functions, it requires collaboration across multiple departments throughout your organization.
{{cta_withimage1="/cta-blocks"}}
When to include each Trust Service Criteria in your SOC 2
The security criteria are mandatory for anyone receiving a SOC 2, but the other four categories — availability, processing integrity, confidentiality, and privacy — only need to be included if they’re applicable to your business. It’s important to know which ones apply to your organization so you can properly prepare your infrastructure for audit.
In this section, we’ll break down each TSC category to help you assess which ones apply to you.
Security (common criteria)
Security, or the common criteria, is the cornerstone of SOC 2. The controls for this section must be included for all completed SOC 2 reports. This category outlines controls that are about securing data against unauthorized access and breaches.
Here’s what's included in the security criteria:
- Control environment: Establish an environment that values integrity and security.
- Communication and information: Document policies and communicate data handling expectations to internal and external stakeholders.
- Risk assessment: Monitor and assess potential risks.
- Monitoring controls: Ensure security controls are effective.
- Control activities: Reduce risk by implementing the right controls, processes, and technologies.
- Logical and physical access controls: Block unauthorized access and activities to sensitive data, devices, and locations.
- System operations: Set up system monitoring capabilities and establish a recovery plan.
- Change management: Test and approve system changes before deploying them.
- Risk mitigation: Monitor risk from third-parties with vendor risk management.
When to include security in your SOC 2:
Security is a mandatory element of every SOC 2 report. Organizations that don’t have all the controls listed under the security criteria will not receive a SOC 2.
Availability
The availability category is an additional criteria of SOC 2 that ensures data is available when needed for its intended use. This requires that your systems be reliable enough that employees and customers have continued access to the data and functionalities they need. It also requires that you have a recovery plan in case an incident occurs that results in a loss of data.
Here is a summary of the controls needed for the availability criteria:
- Manage, forecast, and adjust capacity demands.
- Establish environmental protections, backup processes, and recovery infrastructure.
- Test recovery plan procedures.
When to include availability in your SOC 2:
Availability is applicable to organizations that offer data-centered services. It’s especially important if employees or customers need your data to do their jobs or use your products. Some examples could be businesses that provide cloud storage solutions or CRM software.
Confidentiality
Each of the Trust Services Criteria help keep your clients’ data secure, but the confidentiality category is used when those protections need to be enhanced even further. The confidentiality criteria are relevant if your business handles certain datasets that must be kept confidential and requires only authorized users have access to it.
Here is a summary of the controls for the confidentiality criteria:
- Identify and maintain the confidentiality of information used for designated purposes.
- Dispose of confidential information properly.
When to include confidentiality in your SOC 2:
The confidentiality criteria apply to your organization if you handle confidential or potentially sensitive data. Some examples include your customer’s intellectual property, trade secrets, or private financial reports.
Processing integrity
The processing integrity category is an additional criteria that ensures your systems are all working properly without producing any errors or incorrectly manipulating the data. The processing integrity category includes criteria around the reliability of your systems to accurately process data and prevent your customers or employees from receiving inaccurate results.
Here are the controls for the processing integrity criteria:
- Maintain and use quality information for data processing.
- Implement policies and procedures around system inputs.
- Implement policies and procedures around system processing.
- Implement policies and procedures to ensure data outputs are accurate and made available in a timely fashion.
- Implement policies and procedures to store inputs, items in processing, and outputs.
When to include processing integrity in your SOC 2:
If your business or product processes data (such as running calculations or analysis) on your customers’ behalf, this will be something you may consider adding to your SOC 2. Adding this to your SOC 2 attests to your customers that they can trust the accuracy of the analysis and results you generate for them.
Privacy
The privacy category protects the rights of consumers and their data. These criteria ensure businesses follow the proper protocols to collect consumer data, protect it from unauthorized access or misuse, and dispose of it properly when it’s no longer needed or at the consumer's request.
Here are the controls for the privacy criteria:
- Notice and communication: Provide notice to data subjects about privacy practices.
- Choice and consent: Give consumers options about how they want their data to be handled.
- Collection: Collect only the necessary pieces of information to complete the intended business objective and get consent from the consumer prior to collecting it.
- Use, retention, and disposal: Maintain privacy during the collection, storage, and disposal of consumer data.
- Access: Give consumers access to their information and the ability to edit it.
- Disclosure and notification: Disclose what information is collected, and in the case of a breach or loss of data, notify affected parties.
- Quality: Maintain accurate, up-to-date, complete, and relevant information.
- Monitoring and enforcement: Implement processes for receiving and processing privacy complaints or inquiries.
When to include privacy in your SOC 2:
You should consider adding the privacy category to your SOC 2 if you deal with customer data and want to assure customers you’ve created processes with privacy in mind. If you collect any type of consumer data, including data from users on your app, cookies on your website, and personal or contact information consider adding this to your report.
What changing your TSC scope does to your next report
Adding a category isn't a switch you flip before an audit. New criteria need their own observation period before a Type 2 report can cover them, so a category you add in March won't appear in a Type 2 covering January through June with any meaningful test coverage.
The usual bridge is a Type 1 report on the expanded scope while the observation window accrues, then a Type 2 covering the full set in the following cycle. Plan for two reporting periods, not one.
Scope changes also break comparability. Enterprise buyers who track your reports year over year will notice when the categories move, and a bridge letter doesn't explain a scope change. Adding categories reads as maturity. Removing one you previously reported on invites questions you'll answer in every renewal conversation for the next year, which is the strongest practical argument for scoping conservatively at the start and expanding deliberately.
Expanding deliberately means knowing what a category costs before you commit to it. Because the criteria cross-map, a good share of any elective category is usually already covered by controls you built for Security, so the real question is the size of the remaining gap. In Vanta, the SOC 2 control set is an editable field on the framework, and switching it shows your current categories next to the ones you're moving to so you can review the difference before you confirm.
Simplify your SOC 2 audit
The average SOC 2 process takes roughly a year from the moment you start preparing the controls to when you have a completed SOC 2 report in hand. What takes the most time is preparing your infrastructure and getting all the controls that apply to your organization in place.
However, you can cut this time in half with compliance automation. With Vanta’s compliance automation capabilities, you can assess your risk holistically, identify areas of non-compliance, and get a checklist of actions to help you make the needed changes. From there, Vanta will help you automate the evidence collection process and centralize all your documents to prepare you for audit. We can even help you find an auditor.
The bigger gain shows up after the audit ends. Continuous testing catches a failing control the week it breaks rather than the month before your next report, and the evidence trail for all 61 criteria builds itself while your team does its regular work. When a buyer or a new contract pushes you to scope in Availability or Privacy, you'll already know which controls carry over and which ones you still have to build. That's often the difference between one reporting cycle and two. See how Vanta automates SOC 2 and book a demo to find out where your controls stand today before an auditor does it for you.
{{cta_simple1="/cta-blocks"}}
Introduction to SOC 2
The guide to SOC 2 Trust Services Criteria

Introduction to SOC 2
The guide to SOC 2 Trust Services Criteria

Download the checklist
Looking to automate SOC 2 audit prep?
SOC 2 is one of the most respected compliance standards today. It provides a framework for implementing data security best practices and offers a verified method for evaluating and certifying your security infrastructure. The security policies and practices for SOC 2 are organized around five categories known as the Trust Services Criteria (TSC) — previously called the Trust Service Principles (TCPs) prior to 2018. During your SOC 2 audit, your auditor will assess your security infrastructure against these five criteria.
If you’re preparing to get your SOC 2, it’s important to know how each of the Trust Services Criteria applies to your business and what controls are needed in each. This article will explain each of the TSC areas and how they might apply to your SOC 2.
What are the 5 Trust Services Criteria?
The Trust Services Criteria are five categories the American Institute of Certified Public Accountants publishes for evaluating a service organization's controls. The AICPA's Assurance Services Executive Committee, known as ASEC, sets and maintains them. The current version is the 2017 Trust Services Criteria with revised points of focus issued in 2022, published under TSP Section 100.
Together, the five categories contain 61 individual criteria. Thirty-three of those sit under Security. The remaining 28 are distributed across the other four.
One naming point trips people up regularly. Before the 2017 revision, these categories were called the Trust Services Principles. You'll still see that term in vendor questionnaires and older audit reports. It refers to the same five categories.
The criteria describe outcomes, not controls. The AICPA doesn't tell you to rotate access keys every 90 days or to run quarterly access reviews. It states the outcome your controls need to achieve, and you design the controls that get you there. That's why two companies with the same SOC 2 scope can have entirely different control sets and both pass.
Why Security is the only required category
Security is required because its criteria are the shared foundation the other four categories build on. That's also why it's called the common criteria. Those 33 criteria are common to all five categories, so Availability, Confidentiality, Processing Integrity, and Privacy each layer additional criteria on top of Security rather than standing alone. You can't scope Availability without Security. The reverse works fine.
This matters for a reason that has nothing to do with audit mechanics. Teams preparing for their first SOC 2 audit often assume a Security-only report looks thin to buyers, so they scope in extra categories defensively. It's the most common scoping mistake, and it's expensive.
A Security-only SOC 2 is a complete, legitimate report, and it satisfies the large majority of enterprise procurement requests on its own. Buyers rarely ask for categories you haven't committed to contractually, and a well-run security review process handles the occasional question faster than an unnecessary audit category ever will.
There's a second reason to resist over-scoping. Every criterion you add is one you have to keep passing, year after year. An elective category that seemed harmless during audit prep becomes a permanent evidence obligation, and a qualified opinion on a category you never needed to report on does more damage in a deal review than never having reported on it.
The 33 common criteria behind the Security category
The Security category breaks into nine groups. Each group contains individually testable criteria, numbered as CC1.1, CC1.2, and so on through CC9.2.
Two patterns are worth noticing here.
CC1 through CC5 reads like governance rather than security, and there's a reason. They derive from the COSO internal control framework, which the AICPA adopted as the structural backbone of the common criteria. If your first draft of a SOC 2 control set is all encryption and access reviews with nothing about board oversight or fraud risk, you've built for CC6 and skipped a third of the requirements.
CC6 is the largest group at eight criteria, and it carries the heaviest evidence load in the whole common criteria set. Provisioning, deprovisioning, authentication, network segmentation, physical access, and data disposal each need their own evidence trail across the full observation period. If you're budgeting preparation time by group, budget most of it here.
That evidence load is the part teams underestimate. Each of the 61 criteria needs its own trail across the full observation period, and the mapping between a control, the evidence it produces, and the criteria it satisfies is rarely one to one. SOC 2 compliance software can handle this by tying evidence directly to individual criteria codes and testing continuously, which is how teams manage a multi-category scope without maintaining a spreadsheet of it. Vanta's SOC 2 framework maps automated tests to each criterion so gaps surface before an auditor finds them.
Which organizational systems do the Trust Services Criteria apply to?
Because SOC 2 is designed for data security, many people assume it only applies to your digital infrastructure and systems, but SOC 2 encompasses much more. It includes controls that protect your data from various risks across your entire organization, such as employee negligence or malice, gaps in physical security, and risks from third-parties.
Below are the systems and departments that SOC 2 impacts:
- Physical infrastructure: Where your data is stored (server room, data center) and security practices to control access to these spaces (employee badges, user authentication).
- Digital infrastructure: How your network is configured to segregate data that limits internal and external access.
- Third-party vendors: How you close security gaps and prevent risks from third-party tools and applications.
- Internal operations: Which procedures and practices your staff and contractors follow.
- People: What hiring practices you have in place (background checks) as well as how you onboard and offboard employee’s access to systems.
- Leadership: How your leaders communicate and prioritize security across the organization.
Because SOC 2 touches so many teams and functions, it requires collaboration across multiple departments throughout your organization.
{{cta_withimage1="/cta-blocks"}}
When to include each Trust Service Criteria in your SOC 2
The security criteria are mandatory for anyone receiving a SOC 2, but the other four categories — availability, processing integrity, confidentiality, and privacy — only need to be included if they’re applicable to your business. It’s important to know which ones apply to your organization so you can properly prepare your infrastructure for audit.
In this section, we’ll break down each TSC category to help you assess which ones apply to you.
Security (common criteria)
Security, or the common criteria, is the cornerstone of SOC 2. The controls for this section must be included for all completed SOC 2 reports. This category outlines controls that are about securing data against unauthorized access and breaches.
Here’s what's included in the security criteria:
- Control environment: Establish an environment that values integrity and security.
- Communication and information: Document policies and communicate data handling expectations to internal and external stakeholders.
- Risk assessment: Monitor and assess potential risks.
- Monitoring controls: Ensure security controls are effective.
- Control activities: Reduce risk by implementing the right controls, processes, and technologies.
- Logical and physical access controls: Block unauthorized access and activities to sensitive data, devices, and locations.
- System operations: Set up system monitoring capabilities and establish a recovery plan.
- Change management: Test and approve system changes before deploying them.
- Risk mitigation: Monitor risk from third-parties with vendor risk management.
When to include security in your SOC 2:
Security is a mandatory element of every SOC 2 report. Organizations that don’t have all the controls listed under the security criteria will not receive a SOC 2.
Availability
The availability category is an additional criteria of SOC 2 that ensures data is available when needed for its intended use. This requires that your systems be reliable enough that employees and customers have continued access to the data and functionalities they need. It also requires that you have a recovery plan in case an incident occurs that results in a loss of data.
Here is a summary of the controls needed for the availability criteria:
- Manage, forecast, and adjust capacity demands.
- Establish environmental protections, backup processes, and recovery infrastructure.
- Test recovery plan procedures.
When to include availability in your SOC 2:
Availability is applicable to organizations that offer data-centered services. It’s especially important if employees or customers need your data to do their jobs or use your products. Some examples could be businesses that provide cloud storage solutions or CRM software.
Confidentiality
Each of the Trust Services Criteria help keep your clients’ data secure, but the confidentiality category is used when those protections need to be enhanced even further. The confidentiality criteria are relevant if your business handles certain datasets that must be kept confidential and requires only authorized users have access to it.
Here is a summary of the controls for the confidentiality criteria:
- Identify and maintain the confidentiality of information used for designated purposes.
- Dispose of confidential information properly.
When to include confidentiality in your SOC 2:
The confidentiality criteria apply to your organization if you handle confidential or potentially sensitive data. Some examples include your customer’s intellectual property, trade secrets, or private financial reports.
Processing integrity
The processing integrity category is an additional criteria that ensures your systems are all working properly without producing any errors or incorrectly manipulating the data. The processing integrity category includes criteria around the reliability of your systems to accurately process data and prevent your customers or employees from receiving inaccurate results.
Here are the controls for the processing integrity criteria:
- Maintain and use quality information for data processing.
- Implement policies and procedures around system inputs.
- Implement policies and procedures around system processing.
- Implement policies and procedures to ensure data outputs are accurate and made available in a timely fashion.
- Implement policies and procedures to store inputs, items in processing, and outputs.
When to include processing integrity in your SOC 2:
If your business or product processes data (such as running calculations or analysis) on your customers’ behalf, this will be something you may consider adding to your SOC 2. Adding this to your SOC 2 attests to your customers that they can trust the accuracy of the analysis and results you generate for them.
Privacy
The privacy category protects the rights of consumers and their data. These criteria ensure businesses follow the proper protocols to collect consumer data, protect it from unauthorized access or misuse, and dispose of it properly when it’s no longer needed or at the consumer's request.
Here are the controls for the privacy criteria:
- Notice and communication: Provide notice to data subjects about privacy practices.
- Choice and consent: Give consumers options about how they want their data to be handled.
- Collection: Collect only the necessary pieces of information to complete the intended business objective and get consent from the consumer prior to collecting it.
- Use, retention, and disposal: Maintain privacy during the collection, storage, and disposal of consumer data.
- Access: Give consumers access to their information and the ability to edit it.
- Disclosure and notification: Disclose what information is collected, and in the case of a breach or loss of data, notify affected parties.
- Quality: Maintain accurate, up-to-date, complete, and relevant information.
- Monitoring and enforcement: Implement processes for receiving and processing privacy complaints or inquiries.
When to include privacy in your SOC 2:
You should consider adding the privacy category to your SOC 2 if you deal with customer data and want to assure customers you’ve created processes with privacy in mind. If you collect any type of consumer data, including data from users on your app, cookies on your website, and personal or contact information consider adding this to your report.
What changing your TSC scope does to your next report
Adding a category isn't a switch you flip before an audit. New criteria need their own observation period before a Type 2 report can cover them, so a category you add in March won't appear in a Type 2 covering January through June with any meaningful test coverage.
The usual bridge is a Type 1 report on the expanded scope while the observation window accrues, then a Type 2 covering the full set in the following cycle. Plan for two reporting periods, not one.
Scope changes also break comparability. Enterprise buyers who track your reports year over year will notice when the categories move, and a bridge letter doesn't explain a scope change. Adding categories reads as maturity. Removing one you previously reported on invites questions you'll answer in every renewal conversation for the next year, which is the strongest practical argument for scoping conservatively at the start and expanding deliberately.
Expanding deliberately means knowing what a category costs before you commit to it. Because the criteria cross-map, a good share of any elective category is usually already covered by controls you built for Security, so the real question is the size of the remaining gap. In Vanta, the SOC 2 control set is an editable field on the framework, and switching it shows your current categories next to the ones you're moving to so you can review the difference before you confirm.
Simplify your SOC 2 audit
The average SOC 2 process takes roughly a year from the moment you start preparing the controls to when you have a completed SOC 2 report in hand. What takes the most time is preparing your infrastructure and getting all the controls that apply to your organization in place.
However, you can cut this time in half with compliance automation. With Vanta’s compliance automation capabilities, you can assess your risk holistically, identify areas of non-compliance, and get a checklist of actions to help you make the needed changes. From there, Vanta will help you automate the evidence collection process and centralize all your documents to prepare you for audit. We can even help you find an auditor.
The bigger gain shows up after the audit ends. Continuous testing catches a failing control the week it breaks rather than the month before your next report, and the evidence trail for all 61 criteria builds itself while your team does its regular work. When a buyer or a new contract pushes you to scope in Availability or Privacy, you'll already know which controls carry over and which ones you still have to build. That's often the difference between one reporting cycle and two. See how Vanta automates SOC 2 and book a demo to find out where your controls stand today before an auditor does it for you.
{{cta_simple1="/cta-blocks"}}


Explore more SOC 2 articles
Introduction to SOC 2
Preparing for a SOC 2 audit
SOC 2 reporting and documentation
Streamlining SOC 2 compliance
SOC differences and similarities
Additional SOC 2 resources
Get started with SOC 2
Start your SOC 2 journey with these related resources.

The SOC 2 Compliance Checklist
Speed up SOC 2 audit prep with automation. This checklist shows how to simplify compliance, reduce audit friction, and unlock enterprise deals.

Vanta in Action: Compliance Automation
Demonstrating security compliance with a framework like SOC 2, ISO 27001, HIPAA, etc. is not only essential for scaling your business and raising capital, it also builds an important foundation of trust.