SOC 2 Trust Services Criteria: Which of the 5 Do You Actually Need?
The right criteria scope means a tighter audit, faster readiness, and a report that actually answers what your customers are asking. CISOGenie customers get there in 4–5 weeks, with ~70% less manual effort.

Summarize and analyze this content with:
Executive Summary
The SOC 2 Trust Services Criteria (TSC) are the five categories against which an independent auditor evaluates a service organization's controls: Security, Availability, Processing Integrity, Confidentiality, and Privacy, as defined by the AICPA in TSP Section 100. Security is the only mandatory criterion. The other four are optional, and should be selected based on what your product actually does and what your customers actually ask for. Choosing the wrong scope is one of the most common causes of audit inefficiency and wasted evidence-collection effort. CISOGenie's Risk-Led Security Management Platform maps your product commitments to the right Trust Services Criteria and delivers audit-ready reporting in 4–5 weeks.
Understanding the SOC 2 Trust Services Criteria
The Trust Services Criteria are the framework against which a SOC 2 audit is conducted. Developed by the AICPA, they organize a service organization's controls into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Security, also called the Common Criteria, is mandatory for every SOC 2 report. It covers the foundational controls that protect systems against unauthorized access: logical access, encryption, change management, risk assessment, incident response, and operational oversight. The common criteria series runs CC1 through CC9, structured around the COSO Internal Control framework.
The other four are optional, and that's a design decision, not an invitation to add all of them. Each one should go in only when it reflects a commitment your organization actually makes to customers, or when buyers are explicitly asking for it. Get this wrong and it gets expensive fast: scope too broadly and you're spending evidence-collection effort on criteria no customer will ever look at; scope too narrowly and the report doesn't satisfy what an enterprise buyer actually needs from you.
The Five Trust Services Criteria — What Each Covers
The Five Trust Services Criteria at a Glance
Quick reference of mandatory vs. optional scope requirements.
| Criterion | What it covers | Add it when… |
|---|---|---|
SecurityMandatory | Logical access, encryption, change management, incident response — CC1–CC9 | Always — every SOC 2 report includes it |
AvailabilityOptional | Uptime, monitoring, disaster recovery, capacity planning | Your product is infrastructure-critical or your SLA includes uptime commitments |
Processing IntegrityOptional | Complete, valid, accurate, timely, authorized processing | Payment processors, lending platforms, or any system where a processing error directly harms a customer |
ConfidentialityOptional | Protection of trade secrets, financial data, IP | Contracts or NDAs include specific confidentiality obligations beyond general security |
PrivacyOptional | Collection, use, retention, and disposal of personal information (GAPP) | You've made specific commitments to individuals — common in B2C or healthcare |
Detailed Scope & Solution Mapping
Explore each criterion in depth and see how CISOGenie automates control evidence collection.
Security (Common Criteria) — Mandatory for Every SOC 2 Report
Security covers the controls that protect your systems and data against unauthorized access, disclosure, and damage, organized into nine common criteria series (CC1–CC9). Every SOC 2 report includes it, and the other four criteria sit on top of it. For most organizations pursuing their first SOC 2, Security-only is the right place to start. It's the most commonly requested scope by enterprise buyers and the cleanest path to an initial report.
Availability — Is Your Uptime a Customer Commitment?
Availability requires documented monitoring, incident response, disaster recovery, and capacity planning. What it's really asking for is evidence that you can detect and recover from outages, not just a policy that says you can. Add it if your product is infrastructure-critical, or your SLA includes uptime commitments customers would actually seek remedies for.
Processing Integrity — Does Your System Process Data Correctly?
Processing Integrity applies when customers depend on your system to process their data correctly, not just store or transmit it securely. It's one of the more rigorous criteria to evidence, since auditors want to see how processing errors are detected, logged, and corrected.
Confidentiality — Have You Made Confidentiality Commitments?
Add Confidentiality when contracts or service agreements include specific confidentiality obligations around customer data beyond general security. This comes up a lot for multi-tenant SaaS and professional services firms handling client materials.
Privacy — Are You Processing Personal Data Under Defined Commitments?
Privacy covers how personal information is collected, used, retained, and disposed of, evaluated against the AICPA's Generally Accepted Privacy Principles. It's the most evidence-intensive optional criterion, and honestly the one most often added when it isn't needed. Many B2B SaaS companies handle their GDPR or CCPA obligations separately, and what their enterprise customers are actually asking for is Confidentiality, not Privacy.
How to Decide Which Criteria You Actually Need
Three practical questions to define an audit scope that answers customer needs without wasting resources.
What commitments have you made to customers?
Review service agreements, SLAs, and contracts for uptime, confidentiality, or privacy obligations.
What are your customers asking for?
If enterprise prospects are explicitly requesting Availability or Confidentiality coverage, that's a commercial signal.
What does your product actually do?
Match the criteria to the product reality, not to what sounds credible.
What to avoid
Adding criteria because a template suggested it, or because a competitor happened to include them. An over-scoped SOC 2 isn't more trustworthy. It's just harder to evidence. See how CISOGenie maps criteria to your product commitments →
Why CISOGenie — From Criteria Scoping to Audit-Ready Evidence
CISOGenie connects criteria scoping, gap assessment, policy, risk, and evidence collection in a single continuous loop. You scope the criteria that match your commitments, Gap Assessment shows where controls stand against each one, and the Evidence Collection Agent gathers proof automatically throughout the audit period.
That's "Map Once, Comply Everywhere" in practice: controls mapped for SOC 2 cross-map automatically to ISO 27001, GDPR, DPDPA, and 35+ other frameworks.
How It Works
Discover
Gap Assessment maps your current controls against the Trust Services Criteria relevant to your product. Gaps are visible within days, prioritized by risk and criterion.
Impact Metrics
Rapid Audit Readiness
4–5 weeks to initial SOC 2 audit readiness with scoped criteria.
Less Manual Effort
Reduction in manual effort on gap assessment and evidence collection.
Continuous Evidence
Automated evidence gathered across all selected criteria, every day.
Multi-Framework Overlap
One program for SOC 2, ISO 27001, GDPR, DPDPA, and 30+ frameworks.
Perfect For
Key Risks You Can't Ignore
Over-scoping wastes evidence effort and budget
Every criterion added adds controls, tests, and time.
Under-scoping loses deals
A Security-only report handed to a buyer expecting Confidentiality or Availability evidence signals a mismatch.
Scope drift between audits
New processing workflows or data types can mean year-one scope is no longer accurate for year two.
Evidence gaps within selected criteria
A criterion in scope without an evidence programme behind it produces the worst outcome — a finding that controls couldn't be evidenced.
What Makes CISOGenie Different
Built by CISOs
Scoping guidance reflects operational experience, not a generic checklist.
Fast go-live
Customers are in production within 4–5 weeks.
Automation-first
Evidence collection, gap tracking, and policy management run automatically across all selected criteria.
Full data sovereignty
Your compliance data never leaves your perimeter.
OSCAL-powered, multi-framework
Controls mapped to SOC 2 contribute automatically to ISO 27001, GDPR, DPDPA, and 30+ other frameworks.
Platform plus expertise
GRC professionals support criteria scoping and audit preparation.