SOC 2 Availability criteria explained
Availability is three criteria about capacity, recovery and testing. Add it when you sell an uptime commitment, and not because it sounds thorough.
The Availability category adds three criteria, A1.1 to A1.3, on top of the 33 common criteria. They ask whether you manage capacity, whether you have recovery and backup arrangements, and whether you test those arrangements. Availability adds 10 to 20 percent to a Canadian audit fee. Include it when you have signed an uptime commitment with money attached.
- A1.1
- You maintain, monitor and evaluate capacity so that demand can be met and additional capacity can be added before it is needed.
- A1.2
- You authorize, design, develop, implement, operate, approve, maintain and monitor environmental protections, software, data backup processes and recovery infrastructure.
- A1.3
- You test the recovery plan procedures that support system recovery.
When to include Availability
| Your situation | Include it |
|---|---|
| Your contracts contain an uptime percentage with service credits | Yes. The buyer is buying availability, so the report should cover it |
| Enterprise customers run your product in an operational workflow they cannot pause | Usually yes |
| You publish a status page and an SLA target but commit to nothing contractually | Optional. Ask the customer |
| Your buyer named Availability in a contract schedule or a questionnaire | Yes |
| Nobody has asked and you have no SLA | No. Add it later if it comes up |
Availability is the cheapest optional category to add and the easiest to satisfy for a company already running on a hyperscaler, which makes it tempting to include for appearance. That commits you to capacity monitoring evidence and a tested recovery every year, permanently, for a category no customer asked for. Categories are easy to add at the next audit and awkward to drop: a buyer who saw it last year asks why it disappeared.
What the auditor asks for
| Criterion | Evidence that satisfies it | Common gap |
|---|---|---|
| A1.1 capacity | Monitoring dashboards with thresholds, autoscaling configuration, capacity review notes, alert history | Autoscaling exists, nobody reviews utilisation trends or records having done so |
| A1.2 backup and recovery | Backup configuration and schedules, retention settings, replication across zones or regions, documented recovery objectives | Recovery time and recovery point objectives were never written down, so there is nothing to test against |
| A1.3 testing | A dated restore test with the result, or a documented failover exercise with participants and outcome | Backups have never been restored. This is the single most common Availability exception |
Restore one database, once, and write it down
The cheapest exception to avoid on this whole page. Restore a production backup into a scratch environment, verify the data, note who did it, on what date, how long it took, and whether it met your recovery time objective. Half a day of work, once a year, removes the finding that Availability reports most often carry.
Your SLA and your report have to agree
A reviewer with the Availability section open will compare your stated commitments with your evidence. If your contract promises 99.9 percent and your report describes no capacity monitoring and an untested recovery plan, the report has undermined the contract. Decide the number you can meet before either document says it. Incidents that breached the SLA during the period do not have to be hidden. An incident record with a post-incident review reads better than a suspiciously empty one.
What it adds in Canada
| Company size | Security only | With Availability |
|---|---|---|
| Under 25 staff | $20,000 to $35,000 | $23,000 to $40,000 |
| 25 to 100 staff | $30,000 to $60,000 | $34,000 to $70,000 |
| Over 100 staff | $45,000 to $100,000 | $50,000 to $118,000 |
| Typical uplift for adding the category | 10 to 20 percent of the audit fee | |
The full four-line budget is on the cost page, and what drives a quote covers the other scoping decisions that move the number.
Price it both ways
Ask firms to quote Security only and Security plus Availability against the same system. The difference is the decision.
Get matchedWhere to go from here
- SOC 2 Trust Services Criteria explained. How availability sits beside the other four criteria.
- The SOC 2 common criteria, CC1 to CC9. Security is the only mandatory category, and it carries the most evidence.
- SOC 2 requirements. What the whole report asks of you before you add optional criteria.
- What drives a SOC 2 quote. Each criterion you add changes the quote. This is by how much.
Common questions
How many Availability criteria are there?
Three, numbered A1.1 through A1.3, covering capacity management, backup and recovery infrastructure, and testing of recovery procedures. They sit on top of the 33 common criteria, which are in every report.
Does Availability mean we have to guarantee uptime?
No. The criteria do not set a target. They ask whether you meet the commitments you yourself made, and whether the arrangements behind those commitments are managed and tested. A company committing to 99.5 percent and meeting it is in a better position than one committing to 99.99 percent and missing it.
Can we add Availability to next year's report?
Yes, and that is usually the right sequence. Do Security only for the first report, then add categories as customers name them. Adding a category means new controls that have to operate for the whole of the next observation window, so decide before that window starts rather than during it.
Does our cloud provider's availability count as ours?
Only partly. Their infrastructure resilience is carved out of your report as a subservice organization matter. How you use it, whether you run across availability zones, how you back up and whether you have ever restored, is yours. Reviewers ask about exactly that boundary.