Blog

SOC 2 trust services criteria explained, and which to choose

Every SOC 2 report is measured against the AICPA's trust services criteria. Here is how they are organized, what each series means in plain English, and how to decide which optional categories to include.

What the trust services criteria are

The trust services criteria are the yardstick a SOC 2 audit measures you against. They are published by the AICPA, and the current set is the 2017 Trust Services Criteria, with revised points of focus issued in 2022. The 2022 update refreshed the guidance that sits under each criterion. The criteria themselves, and their numbering, stayed the same.

When a CPA firm examines your company for a SOC 2 report, it gives an opinion on whether your controls meet the criteria that are in scope. So before you write a single policy, it helps to know how the criteria are organized, which ones every report includes, and which ones you choose.

Note: the descriptions below are short paraphrases, not the AICPA's wording. Use the criterion IDs to look up the official text, and treat your auditor's reading as the one that counts.

The five SOC 2 categories

The trust services criteria are grouped into five categories (older material calls them "principles"). Security is the only one every SOC 2 report must include. The other four are optional, and you add them when they match what you promise your customers.

CategoryThe question it answersCriteriaIn scope
SecurityIs the system protected against unauthorized access, use and change?The Common Criteria, CC1 to CC9Always
AvailabilityIs the system available for operation and use as committed?A1Optional
Processing IntegrityIs processing complete, valid, accurate, timely and authorized?PI1Optional
ConfidentialityIs information designated as confidential protected as committed?C1Optional
PrivacyIs personal information collected, used, kept, disclosed and disposed of as committed?P1 to P8Optional

The Common Criteria get their name because they are shared. When you add Availability, for example, the Common Criteria also apply to your availability objectives, and the A1 series adds a few criteria specific to availability on top. That is why every SOC 2 report, whatever its scope, starts from the same CC1 to CC9 base.

The Common Criteria, CC1 to CC9, explained

The Common Criteria are split into nine series. Each series holds a handful of numbered criteria (CC6.1, CC6.2 and so on), 33 in total.

SeriesNameIn plain English
CC1Control environmentLeadership sets the tone: a commitment to integrity, oversight of security, clear structure and reporting lines, competent people, and accountability for doing their part.
CC2Communication and informationThe right information reaches the right people, inside the company and outside it, so they can carry out their control responsibilities.
CC3Risk assessmentYou set clear objectives, identify and analyze the risks to them (including fraud), and reassess when something significant changes.
CC4Monitoring activitiesYou check that your controls actually work, through ongoing or separate evaluations, and report the problems you find to the people who can fix them.
CC5Control activitiesYou choose and put in place controls that reduce your risks, including general controls over technology, and you deploy them through policies and procedures.
CC6Logical and physical access controlsOnly the right people and systems get access: user registration and removal, least privilege, physical access, disposal of assets, protection at the system boundary and in transit, and defense against malicious software.
CC7System operationsYou detect vulnerabilities and unexpected changes, monitor for security events, evaluate them, respond to incidents and recover from them.
CC8Change managementChanges to infrastructure, software and data are authorized, designed, tested, approved and documented before they reach production.
CC9Risk mitigationYou plan for business disruption, and you assess and manage the risk that comes from vendors and business partners.

How CC1 to CC5 relate to COSO

The first five series follow the 2013 COSO internal control framework, which many finance and audit teams already know. COSO has five components (control environment, risk assessment, control activities, information and communication, and monitoring activities) and 17 principles. CC1 to CC5 map to those 17 principles, one criterion each. CC6 to CC9 are the criteria the AICPA added for the risks specific to running technology systems.

In practice this means CC1 to CC5 are about how the company is governed and managed, and they are often evidenced with documents, meetings and reviews. CC6 to CC9 are where most of the technical controls live: access, monitoring, incident response, change control and vendors.

The additional criteria for each optional category

Each optional category adds its own short series. The Common Criteria still apply, so these criteria cover only what is specific to the category.

Availability (A1)

Three criteria, A1.1 to A1.3. They cover managing capacity so you can meet demand, protecting the environment and maintaining backups and recovery infrastructure, and testing your recovery plans.

Processing Integrity (PI1)

Five criteria, PI1.1 to PI1.5. They cover defining what your processing is supposed to do, and then making sure inputs, processing and outputs are complete and accurate, and that inputs, items in process and outputs are stored properly. This category is about whether your system does its job correctly, not about data security in general.

Confidentiality (C1)

Two criteria, C1.1 and C1.2. They cover identifying and protecting information that is designated as confidential, and disposing of it when it should no longer be kept. Classification, handling rules, retention schedules and secure disposal are the usual building blocks.

Privacy (P1 to P8)

Eighteen criteria across eight series, making it the largest optional category. The series are:

  • P1 Notice: telling people about your privacy practices.
  • P2 Choice and consent.
  • P3 Collection: collecting only what your objectives need.
  • P4 Use, retention and disposal.
  • P5 Access: letting people see and correct their information.
  • P6 Disclosure and notification, including to third parties and after breaches.
  • P7 Quality: keeping personal information accurate and complete.
  • P8 Monitoring and enforcement, including handling inquiries and complaints.

Confidentiality and Privacy are easy to mix up. Confidentiality is about information you have agreed to keep confidential, whatever it is. Privacy is about personal information and the commitments you make to the people it describes.

Points of focus are guidance, not a checklist

Under each criterion the AICPA lists points of focus: characteristics that are often relevant when you design and evaluate controls for that criterion. The 2022 revision updated these, without changing the criteria they sit under.

They are not a list of requirements. You don't need a control for every point of focus, and some won't apply to your business at all. What matters is that your controls, taken together, meet the criterion. Points of focus are useful as a prompt when you design a control, and as a way to spot something you have missed. Whether a gap matters is your auditor's judgment.

Which SOC 2 categories to choose

Security is decided for you. For the other four, three questions do most of the work.

  1. What are customers asking for? Read the security questionnaires, RFPs and contract redlines you already have. If prospects ask about a category by name, that is a strong signal.
  2. What do you already promise? A SOC 2 report describes the commitments you make to customers. If your contracts include an uptime SLA, confidentiality terms or privacy commitments to individuals, a matching category lets the report speak to them.
  3. What will the extra scope cost? Every category adds criteria, controls to run and evidence to collect, and more for the auditor to test, which usually shows up in the fee. Ask auditors to quote the options side by side.
CategoryConsider it whenOften fine to leave out when
AvailabilityYou commit to uptime or recovery targets, or customers run critical operations on your serviceYou make no availability commitments and customers don't ask about them
ConfidentialityYou store customer business data under confidentiality terms, such as documents, source code or financial recordsYou hold little customer data beyond what the Security criteria already cover
Processing IntegrityCustomers rely on your calculations or transactions being correct, such as billing, payroll or paymentsYour product stores or moves data without transforming it in ways customers rely on
PrivacyYou collect personal information directly from individuals and make privacy commitments to themYou mainly process personal data on your customers' behalf, and customers haven't asked for it

Many first reports cover Security alone, or Security plus one or two categories that customers keep asking about. That is a common choice, not a rule. You can add categories in a later report, and any added controls then need to operate through that report's period. The SOC 2 Type 1 vs Type 2 article explains how scope and report type fit together, and the SOC 2 readiness checklist puts the scope decision first for good reason.

Important: agree the categories with your auditor before the period starts. Adding a category halfway through a Type 2 period can leave you without evidence for the months before it was added.

Mapping the trust services criteria in Confluence

Once you have chosen your categories, you need policies and recurring controls that cover each criterion, and a way to see which criteria are still uncovered. If your team already works in Confluence, Compliance in a Box builds that structure in one Confluence space. Its SOC 2 content is based on the 2017 Trust Services Criteria with the 2022 revised points of focus.

  • Choose categories at setup. In Settings, under Frameworks & pages, each Trust Services Category is a checkbox. Security is always included. You tick the others you want and select Generate pages. See Getting started.
  • Pages per category. Security brings 20 policies and 13 recurring activities. Availability adds 2 policies (Backup, and Capacity & Performance Management) and 2 activities (a Business Continuity / DR Test and a quarterly Backup Restore Test). Processing Integrity and Privacy add one policy each. Confidentiality adds no extra pages, because its two policies (Data Classification & Handling, and Data Retention & Disposal) are already part of Security. With all five categories you get 24 policies and 15 recurring activities.
  • A controls matrix by criterion. The app generates a controls matrix page that lists every criterion in your selected categories, with the policies and activities mapped to it, each with a link and its current status. Each criterion rolls up to Covered, Attention or Gap, and the top of the page totals them. The app refreshes it daily from its records. See Evidence, reports and audits.
  • Add categories later. If a customer starts asking for Availability next year, you tick it and select Generate again. The app creates only the missing pages and leaves everything your team has edited as it is. Categories can't be removed once added.

The full criterion by criterion mapping is in the SOC 2 content reference, and the SOC 2 policies list explains what each policy is for. The mappings are a starting point, not audit advice: have your auditor review them.

FAQ

Is Security the same as the Common Criteria?

Yes, in effect. The Security category is made up of the Common Criteria, CC1 to CC9. They are called common because they also apply to any optional category you add.

Did the 2022 revision change the criteria?

No. The 2022 revision updated the points of focus, the supporting guidance under each criterion. The 2017 criteria and their numbering stayed the same.

Do we need all five categories for a SOC 2 report?

No. Only Security is required. Add the others when customers ask for them or when they match commitments you make in your contracts.

Can we change categories between reports?

Yes. Scope is set for each report, so you can add a category in your next audit. Talk to your auditor early, because the new controls need to operate through the new period.

← All articles