Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOC 2 Trust Services Criteria explained - security, availability, processing integrity, confidentiality and privacy

SOC 2 Trust Services Criteria Explained

The SOC 2 Trust Services Criteria are the foundation of every SOC 2 report. They define what an auditor evaluates and which aspects of your service you are making commitments about. Understanding them is essential to scoping your SOC 2 correctly. This guide explains all five criteria and how to choose the right ones.

SOC 2 Trust Services Criteria explained - security, availability, processing integrity, confidentiality and privacy

For the wider context, see our complete SOC 2 guide.

What are the SOC 2 Trust Services Criteria?

Developed by the AICPA, the Trust Services Criteria are the set of principles a SOC 2 examination measures your controls against. There are five, and you select which apply to your report based on your service and the promises you make to customers. Only one — Security — is mandatory; the rest are optional but often expected depending on what you do.

1. Security (the common criteria)

Security is the baseline that every SOC 2 report includes. It covers protection of systems and data against unauthorised access, both physical and logical — access controls, network security, monitoring, and incident response. Because it is always in scope, it is often called the “common criteria,” and it forms the core of your control set.

2. Availability

The availability criterion addresses whether your systems are available for operation and use as committed or agreed. It is relevant if you make uptime or service-level commitments, and it covers areas like performance monitoring, disaster recovery, and business continuity. SaaS platforms with SLAs commonly include it.

3. Processing integrity

Processing integrity concerns whether system processing is complete, valid, accurate, timely, and authorised. It matters most where your service processes transactions or data on customers’ behalf — for example payments, analytics, or data transformation — and customers rely on the correctness of the output.

4. Confidentiality

The confidentiality criterion covers information that is designated as confidential and must be protected accordingly, such as business plans, intellectual property, or contracts. It is distinct from privacy: confidentiality is about protecting sensitive business information, not necessarily personal data.

5. Privacy

The privacy criterion addresses how you collect, use, retain, disclose, and dispose of personal information in line with your privacy notice and the AICPA’s privacy criteria. It is relevant where your service handles individuals’ personal data and you want to demonstrate responsible privacy practices alongside security.

How to choose your criteria

Start with Security, then add the criteria that reflect the commitments you actually make to customers. Including a criterion means your auditor will test controls for it, so choose deliberately: adding availability, processing integrity, confidentiality, or privacy strengthens your report where it is relevant, but each expands your control and evidence burden. Scoping accurately is one of the most important early SOC 2 decisions.

Map controls to every criterion.

Our SOC 2 Toolkit maps policies and controls to all five Trust Services Criteria, so you can scope your report and prepare evidence with confidence — in Word and Excel.

Explore the SOC 2 Toolkit →

Frequently asked questions

What are the five SOC 2 Trust Services Criteria?

Security, availability, processing integrity, confidentiality, and privacy. Security is always included; the others are selected based on your service and commitments.

Which Trust Services Criteria are mandatory?

Only Security (the common criteria) is mandatory in every SOC 2 report. The other four are optional but often expected depending on what you do.

What is the difference between confidentiality and privacy in SOC 2?

Confidentiality protects sensitive business information designated as confidential; privacy specifically governs how you handle individuals’ personal information.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.