GetSOC2

SOC 2 Trust Services Criteria explained

Security is mandatory and the other four categories are optional. Which optional ones you include is the single scoping decision that moves your audit fee most, and it should be made by reading your customer's contract, not by guessing.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

The Trust Services Criteria are the AICPA's five categories a SOC 2 examination can cover: Security, Availability, Confidentiality, Processing Integrity and Privacy. Security is included in every report and is called the common criteria. The other four are added only when something specific makes them relevant. Each one adds controls, evidence, fieldwork hours and fee.

Each criterion has its own page with the controls and evidence an auditor asks for: security, which every report includes, then availability, confidentiality and processing integrity, which you add only when a customer contract or a regulator requires them.

Most Canadian first reports are Security only. Security plus Availability is the second most common shape. If nobody has named a category in writing, the right number of optional categories to include is zero, and every category you add shows up in the fee.

Category
One of the five Trust Services Criteria groupings. Security is in every report; the other four are optional.
Common criteria
The Security category, so called because its criteria are common to every SOC 2 report regardless of what else is included.
Criterion
A numbered requirement inside a category, for example CC6.1. It states an outcome, not a control.
Point of focus
An AICPA example of what meeting a criterion might look like. Illustrative, and not a checklist you have to complete.
Control
The thing you actually do, written by you, that meets a criterion in the way your system works.

The five categories at a glance

Trust Services Criteria categories and what triggers each one
CategoryThe question it answersInclude it whenEffect on fee
SecurityIs the system protected against unauthorized access, use or modificationAlwaysThe baseline
AvailabilityIs the system available for operation and use as committedYou sell an uptime commitment or an SLA with credits attachedAdd roughly 10 to 20 percent
ConfidentialityIs information designated as confidential protected as committedCustomers send you their own commercially sensitive material, not just personal dataAdd roughly 10 to 20 percent
Processing integrityIs processing complete, valid, accurate, timely and authorizedYou compute something on a customer's behalf: payments, payroll, billing, clinical or financial calculationsAdd roughly 20 to 35 percent
PrivacyIs personal information collected, used, retained and disposed of as committedA buyer asked for it in writing. Rarely otherwiseAdd roughly 20 to 30 percent

Inside Security: the nine common criteria series

Why board oversight is in a security standard

Security is not one criterion. It is nine numbered series, CC1 through CC9, and the first five map onto the COSO internal control framework. That mapping is why SOC 2 asks about board oversight and hiring practices, which surprises engineering teams expecting a technical standard.

The common criteria series and what an auditor tests in each
SeriesSubjectWhat the evidence usually looks like
CC1Control environmentOrg chart, background checks, code of conduct, board or advisor oversight, annual security training records
CC2Communication and informationPublished security commitments, internal policy distribution, a channel for reporting concerns
CC3Risk assessmentA dated risk register, treatment decisions, and evidence somebody revisited it
CC4Monitoring activitiesInternal control reviews, vulnerability scan output, remediation tracked to closure
CC5Control activitiesHow policies turn into configured controls in your actual systems
CC6Logical and physical accessThe heaviest series. Access provisioning and removal tickets, quarterly access reviews, multi-factor authentication, encryption in transit and at rest, key management
CC7System operationsMonitoring and alerting, vulnerability management, the incident response plan and evidence it was exercised
CC8Change managementPull request approvals, deployment records, separation between the person who wrote a change and the person who released it
CC9Risk mitigationVendor risk management, subservice organisation reviews, business continuity

Where the evidence actually piles up

CC6 and CC7 produce more evidence requests than the rest combined. If you are deciding where to spend readiness effort, access reviews, offboarding and vulnerability remediation are where audits get held up. The requirements page goes through the request list item by item, and section 4 of the report is where each of those tests and its result eventually appears in front of a buyer.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Points of focus are not a checklist

Under each criterion the AICPA publishes points of focus: examples of what meeting the criterion might look like. They are illustrative. You do not have to implement every point of focus, and an auditor who treats them as a required control list is applying the framework more strictly than it is written.

What you do have to do is meet the criterion with controls that suit your system, and be able to explain why those controls meet it. Two companies can satisfy CC6.1 in different ways and both be right. This is also why there is no downloadable list of SOC 2 controls that is correct for everyone.

The Privacy category, and why Canadian companies usually skip it

A professional framework, not a statute

The Privacy criteria are built on the AICPA and CPA Canada Generally Accepted Privacy Principles. They are a professional framework, not law. Including them in your report says an auditor tested whether you handle personal information the way you told people you would. It says nothing about whether you comply with PIPEDA, Quebec's Law 25, or Ontario's PHIPA, and passing does not defend you if a Privacy Commissioner comes asking.

What to do instead

Those statutory duties apply whether or not any customer asks for a report. Take Security only in the report and handle privacy obligations as separate work, unless a customer wrote Privacy into a contract. The SOC 2 and PIPEDA page sets out what each one does and does not cover, and a readiness consultant will only scope the statutory half if you ask for it in writing.

A useful test before adding a category

Ask whoever requested the report to point at the sentence in their security schedule that names the category. If they cannot, the category came from a template and dropping it costs you nothing. If they can, you have a requirement rather than an assumption.

Availability, in practice

Availability is the most commonly added category and the least painful. The evidence is mostly things you already have: monitoring, alerting, capacity planning, backup configuration, restore tests, and a business continuity plan. The one item that catches teams out is the restore test. Auditors want evidence that a backup was restored during the period, not that backups ran. Doing one restore per quarter and screenshotting it is cheaper than explaining why you did not.

Availability is also the criterion that decides how a report reads to a regulated financial buyer, since resilience is a large part of what they are required to assess. See OSFI B-13 and SOC 2.

Processing integrity, and why it costs more

Processing integrity is about whether your system produces correct output. It is relevant to payments platforms, payroll, billing engines, clinical calculations and anything a customer relies on for a number. It costs more because the auditor has to understand your processing logic well enough to design tests around input validation, error handling, reconciliation and output completeness.

If you are a general-purpose SaaS storing and displaying customer data, you almost certainly do not need it, and adding it because it sounds thorough is an expensive mistake.

Adding a category later

Between periods, which is the cheap way

You can add a category in a later period, and that is normally the cheaper path. The report you issue names the categories covered, so a Security-only report followed a year later by a Security and Availability report is a normal progression and buyers read it as one.

Mid-period, which is not

Adding a category in the middle of a period is the expensive version. The observation window for the new category starts when its controls started operating, not when the rest of the report started. That leaves you with two dates in one report and a reviewer asking why. The deadline back-calculator shows what the second window does to your report date before you agree to it.

Get the scope priced before you commit to it

Tell us which categories your buyer named and we will put the scope in front of Canadian audit firms.

Get matched

Common questions

What are the five SOC 2 Trust Services Criteria?

Security, Availability, Confidentiality, Processing Integrity and Privacy. Security is mandatory in every SOC 2 report and is known as the common criteria. The other four are optional categories included only when a customer commitment or the nature of your service makes them relevant.

Which criteria should we include in our first report?

Security only, unless a customer has named another category in writing. Security plus Availability is the sensible second shape if you sell an uptime SLA. Each added category increases evidence volume and audit fee, and categories can be added in a later reporting period without penalty.

Is the Privacy criteria the same as PIPEDA compliance?

No. The Privacy category tests whether you handle personal information the way your own notices and commitments say you do. PIPEDA is federal Canadian law with its own requirements and its own regulator. A clean SOC 2 report covering Privacy is evidence of good practice, not a compliance finding under Canadian privacy law.

How many controls does SOC 2 require?

None specifically. SOC 2 sets criteria and you choose controls that meet them, which is why control counts differ so much between companies. A small SaaS company typically ends up with 60 to 120 controls mapped across the nine common criteria series, and the number itself means nothing to an auditor.

What is the difference between CC series and the optional categories?

The CC series, CC1 through CC9, are the nine groupings inside the Security category and appear in every report. The optional categories sit alongside them with their own criteria, numbered A for availability, C for confidentiality, PI for processing integrity and P for privacy.