The SOC 2 Trust Services Criteria, Explained

Compliance / SOC 2 / Trust Services Criteria
Compliance & Audit Readiness

The SOC 2 Trust Services Criteria, Explained

Every SOC 2 report is built on the AICPA’s five Trust Services Criteria. Only one is mandatory. Here’s what each one actually covers, and how the other four get selected.

Schedule a Consultation →

Definition

The Trust Services Criteria are the control categories the AICPA defined for SOC 2 (and SOC 3) engagements. A SOC 2 report is always scoped against Security, and against however many of the remaining four criteria — Availability, Confidentiality, Processing Integrity, and Privacy — actually apply to the service being examined. Scope is a business decision, not a checkbox exercise: adding a criterion that doesn’t reflect what your service does just adds audit cost without adding buyer confidence.

Mandatory

Security: The Common Criteria

Security — formally the Common Criteria, CC1 through CC9 — is the only criterion required in every SOC 2 engagement, regardless of what the service does. It covers the control environment (CC1), communication and information (CC2), risk assessment (CC3), monitoring activities (CC4), control activities (CC5), logical and physical access controls (CC6), system operations (CC7), change management (CC8), and risk mitigation (CC9). This is the backbone every other criterion builds on: access control, MFA enforcement, vulnerability management, incident response, and change-management gates all live here.

Selected by Scope

The Four Optional Criteria

Each of these is added only when it reflects a real commitment your organization has made to customers.

Availability

Systems are available for operation and use as committed or agreed. Typically selected by SaaS platforms with published uptime SLAs, where a customer’s ability to reach the service is itself a contractual commitment.

Confidentiality

Information designated as confidential is protected as committed or agreed. Common for B2B platforms and fintechs handling client business data, source code, or other information under an NDA.

Processing Integrity

System processing is complete, valid, accurate, timely, and authorized. Relevant to payment processors, billing platforms, and any system where a processing error has direct financial consequences.

Privacy

Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments in the entity’s privacy notice. Selected when consumer PII, not just business data, is directly in scope.

Choosing Scope

How Armorstack Helps You Pick the Right Criteria

The wrong scope decision cuts both ways. Under-scoping produces a report buyers reject because it doesn’t cover a commitment they care about — a common failure when a SaaS vendor skips Availability despite selling on an uptime SLA. Over-scoping adds audit cost and remediation burden for criteria nobody asked about. VERITY’s readiness assessment maps your actual customer commitments — contracts, marketing claims, DPAs — against the five criteria before recommending scope, so the report you pay for is the report your buyers actually need.

Once scope is set, see how the readiness assessment identifies control gaps against it, and how those decisions flow into realistic timeline and cost planning.

Not Sure Which Criteria Apply to You?

Armorstack maps your actual customer commitments against the Trust Services Criteria and tells you exactly what belongs in scope.