Which trust services criteria belong in your SOC 2
Security is in every SOC 2. The other four categories are a choice, and each one you add is real evidence work for the life of the report. Seven questions decide which of them you actually need.
A SOC 2 report covers one to five trust services categories. Security, the common criteria, is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are elective, and the decision is yours rather than your auditor's. Companies routinely elect categories nobody asked for, then carry the evidence burden for every year the report is renewed.
This asks what your product does, what you promise customers in a contract, and what your buyers named in writing. It returns the categories to include, the reason for each, and how much additional criteria work each one adds. The answer renders on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
The model this uses
Each elective category is scored on three things: whether your business creates the obligation the category tests, whether a buyer has asked for it in writing, and whether the category is one that buyers in your market treat as standard. A category that scores on the first two is included. A category that scores only on the third is offered as a decision rather than a recommendation.
The evidence weight beside each category is the count of additional criteria in the 2017 trust services criteria, the ones that sit on top of the thirty three common criteria that make up Security.
| Category | Criteria | What it tests |
|---|---|---|
| Security | 33 | The common criteria. Mandatory in every report |
| Availability | 3 | Capacity planning, recovery, and testing the recovery |
| Confidentiality | 2 | Identifying confidential information and disposing of it |
| Processing Integrity | 5 | Inputs, processing and outputs being complete and accurate |
| Privacy | 18 | Notice, choice, collection, retention, access, disclosure and quality |
Adding a category later
Categories are not a one-way door. A second year report can add Availability or Confidentiality without repeating the first year, because the common criteria work carries over and only the additional criteria are new. What you cannot do is add a category part way through an observation window and have the report cover it from the start of that window. The controls have to have been operating for the whole period, which is why the decision belongs before the window opens rather than after a customer complains.
Removing a category is harder, because a customer who has read last year's report will notice. Electing Privacy in year one and dropping it in year two reads as a failure whether or not it was one. That asymmetry is the reason to be conservative here.
Common questions
Does adding a category cost more?
Yes, on both lines. The audit fee rises because there are more criteria to test, and the readiness work rises because there are more controls to build and more evidence to keep. Availability and Confidentiality are modest additions. Privacy is not, and it is the one that most often doubles a readiness timeline. The cost calculator prices the difference in Canadian dollars.
Our customer said "SOC 2" and nothing else. What do we elect?
Ask them. It is a one line email and it is the cheapest question on the project. When there is genuinely nobody to ask, Security alone is a complete and respectable report, and Security with Availability is what most software buyers expect to see. Electing four categories to look thorough buys you evidence work rather than deals.
Is Privacy the same as being compliant with PIPEDA or Law 25?
No. The Privacy category tests whether you do what your own privacy notice says you do, and whether the supporting controls operate. Canadian privacy law imposes obligations that exist whether or not you hold a SOC 2. The two overlap in evidence and not in scope. See SOC 2 and PIPEDA and SOC 2 and Quebec Law 25.
Can we elect Confidentiality without Availability?
Yes. The categories are independent and any combination that includes Security is a valid report. The common pairing of Security and Availability is a market convention rather than a rule, and if your buyers care about data handling more than uptime, say so in the report and elect accordingly.
Who decides, us or the auditor?
You do. Management selects the categories and writes the system description; the audit firm reports on what management asserted. A firm that tells you which categories you must elect before understanding your business is answering a question that was yours to answer. The questions to ask an auditor cover how to test that in a first call.
Price the scope you just defined
Take the category list to Canadian audit firms so every quote you get back covers the same report.
Get matched