SOC 2 · Trust Services Criteria

SOC 2 Trust Services Criteria: Which of the 5 Do You Actually Need?

The right criteria scope means a tighter audit, faster readiness, and a report that actually answers what your customers are asking. CISOGenie customers get there in 4–5 weeks, with ~70% less manual effort.

SOC 2 Trust Services Criteria Scoping illustration

Summarize and analyze this content with:

ChatGPT logoPerplexity logoGemini logoClaude logo

Executive Summary

The SOC 2 Trust Services Criteria (TSC) are the five categories against which an independent auditor evaluates a service organization's controls: Security, Availability, Processing Integrity, Confidentiality, and Privacy, as defined by the AICPA in TSP Section 100. Security is the only mandatory criterion. The other four are optional, and should be selected based on what your product actually does and what your customers actually ask for. Choosing the wrong scope is one of the most common causes of audit inefficiency and wasted evidence-collection effort. CISOGenie's Risk-Led Security Management Platform maps your product commitments to the right Trust Services Criteria and delivers audit-ready reporting in 4–5 weeks.

Framework Overview

Understanding the SOC 2 Trust Services Criteria

The Trust Services Criteria are the framework against which a SOC 2 audit is conducted. Developed by the AICPA, they organize a service organization's controls into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Security, also called the Common Criteria, is mandatory for every SOC 2 report. It covers the foundational controls that protect systems against unauthorized access: logical access, encryption, change management, risk assessment, incident response, and operational oversight. The common criteria series runs CC1 through CC9, structured around the COSO Internal Control framework.

The other four are optional, and that's a design decision, not an invitation to add all of them. Each one should go in only when it reflects a commitment your organization actually makes to customers, or when buyers are explicitly asking for it. Get this wrong and it gets expensive fast: scope too broadly and you're spending evidence-collection effort on criteria no customer will ever look at; scope too narrowly and the report doesn't satisfy what an enterprise buyer actually needs from you.

The Five Trust Services Criteria — What Each Covers

The Five Trust Services Criteria at a Glance

Quick reference of mandatory vs. optional scope requirements.

CriterionWhat it coversAdd it when…
SecurityMandatory
Logical access, encryption, change management, incident response — CC1–CC9Always — every SOC 2 report includes it
AvailabilityOptional
Uptime, monitoring, disaster recovery, capacity planningYour product is infrastructure-critical or your SLA includes uptime commitments
Processing IntegrityOptional
Complete, valid, accurate, timely, authorized processingPayment processors, lending platforms, or any system where a processing error directly harms a customer
ConfidentialityOptional
Protection of trade secrets, financial data, IPContracts or NDAs include specific confidentiality obligations beyond general security
PrivacyOptional
Collection, use, retention, and disposal of personal information (GAPP)You've made specific commitments to individuals — common in B2C or healthcare

Detailed Scope & Solution Mapping

Explore each criterion in depth and see how CISOGenie automates control evidence collection.

Mandatory Common Criteria

Security (Common Criteria) — Mandatory for Every SOC 2 Report

Security covers the controls that protect your systems and data against unauthorized access, disclosure, and damage, organized into nine common criteria series (CC1–CC9). Every SOC 2 report includes it, and the other four criteria sit on top of it. For most organizations pursuing their first SOC 2, Security-only is the right place to start. It's the most commonly requested scope by enterprise buyers and the cleanest path to an initial report.

CISOGenie Platform Coverage
Gap Assessment maps your current controls against all nine common criteria series. Risk Management provides the risk register that underpins the CC3 and CC9 risk assessment evidence your auditor will expect.
Optional Criterion

Availability — Is Your Uptime a Customer Commitment?

Availability requires documented monitoring, incident response, disaster recovery, and capacity planning. What it's really asking for is evidence that you can detect and recover from outages, not just a policy that says you can. Add it if your product is infrastructure-critical, or your SLA includes uptime commitments customers would actually seek remedies for.

CISOGenie Platform Coverage
The Continuous Monitoring Agent tracks uptime-related controls in real time. The Incident Register documents detection, response, and recovery.
Optional Criterion

Processing Integrity — Does Your System Process Data Correctly?

Processing Integrity applies when customers depend on your system to process their data correctly, not just store or transmit it securely. It's one of the more rigorous criteria to evidence, since auditors want to see how processing errors are detected, logged, and corrected.

CISOGenie Platform Coverage
Audit Management organizes processing control evidence by control and period. The OSCAL Policy Agent keeps processing-related policies current and aligned to what your auditor will test.
Optional Criterion

Confidentiality — Have You Made Confidentiality Commitments?

Add Confidentiality when contracts or service agreements include specific confidentiality obligations around customer data beyond general security. This comes up a lot for multi-tenant SaaS and professional services firms handling client materials.

CISOGenie Platform Coverage
Policy Management maintains data classification and confidentiality handling policies. Privacy Management covers the related but distinct obligation set when personal data is also in scope.
Optional Criterion

Privacy — Are You Processing Personal Data Under Defined Commitments?

Privacy covers how personal information is collected, used, retained, and disposed of, evaluated against the AICPA's Generally Accepted Privacy Principles. It's the most evidence-intensive optional criterion, and honestly the one most often added when it isn't needed. Many B2B SaaS companies handle their GDPR or CCPA obligations separately, and what their enterprise customers are actually asking for is Confidentiality, not Privacy.

CISOGenie Platform Coverage
Privacy Management handles data subject requests, consent records, and privacy policy documentation.

How to Decide Which Criteria You Actually Need

Three practical questions to define an audit scope that answers customer needs without wasting resources.

01

What commitments have you made to customers?

Review service agreements, SLAs, and contracts for uptime, confidentiality, or privacy obligations.

02

What are your customers asking for?

If enterprise prospects are explicitly requesting Availability or Confidentiality coverage, that's a commercial signal.

03

What does your product actually do?

Match the criteria to the product reality, not to what sounds credible.

What to avoid

Adding criteria because a template suggested it, or because a competitor happened to include them. An over-scoped SOC 2 isn't more trustworthy. It's just harder to evidence. See how CISOGenie maps criteria to your product commitments →

Continuous Scoping Loop

Why CISOGenie — From Criteria Scoping to Audit-Ready Evidence

CISOGenie connects criteria scoping, gap assessment, policy, risk, and evidence collection in a single continuous loop. You scope the criteria that match your commitments, Gap Assessment shows where controls stand against each one, and the Evidence Collection Agent gathers proof automatically throughout the audit period.

That's "Map Once, Comply Everywhere" in practice: controls mapped for SOC 2 cross-map automatically to ISO 27001, GDPR, DPDPA, and 35+ other frameworks.

How It Works

1
Discover
2
Configure
3
Implement
4
Monitor
5
Audit & Report
6
Maintain
Step 1

Discover

Gap Assessment maps your current controls against the Trust Services Criteria relevant to your product. Gaps are visible within days, prioritized by risk and criterion.

Impact Metrics

0–5 Wks

Rapid Audit Readiness

4–5 weeks to initial SOC 2 audit readiness with scoped criteria.

~0%

Less Manual Effort

Reduction in manual effort on gap assessment and evidence collection.

24/7

Continuous Evidence

Automated evidence gathered across all selected criteria, every day.

0+

Multi-Framework Overlap

One program for SOC 2, ISO 27001, GDPR, DPDPA, and 30+ frameworks.

Perfect For

First-Time SOC 2 SaaS
Audit Renewal Teams
CISOs Launching Products
Founders Facing RFPs

Key Risks You Can't Ignore

Over-scoping wastes evidence effort and budget

Every criterion added adds controls, tests, and time.

Under-scoping loses deals

A Security-only report handed to a buyer expecting Confidentiality or Availability evidence signals a mismatch.

Scope drift between audits

New processing workflows or data types can mean year-one scope is no longer accurate for year two.

Evidence gaps within selected criteria

A criterion in scope without an evidence programme behind it produces the worst outcome — a finding that controls couldn't be evidenced.

What Makes CISOGenie Different

Built by CISOs

Scoping guidance reflects operational experience, not a generic checklist.

Fast go-live

Customers are in production within 4–5 weeks.

Automation-first

Evidence collection, gap tracking, and policy management run automatically across all selected criteria.

Full data sovereignty

Your compliance data never leaves your perimeter.

OSCAL-powered, multi-framework

Controls mapped to SOC 2 contribute automatically to ISO 27001, GDPR, DPDPA, and 30+ other frameworks.

Platform plus expertise

GRC professionals support criteria scoping and audit preparation.

Get Your SOC 2 Criteria Scope Right
— From Day One

Whether you're choosing criteria for the first time or reassessing scope ahead of a renewal, CISOGenie can show you a faster path to audit readiness.

Frequently Asked Questions