Trust Service Criteria
Trust Service Criteria (TSC) are the five categories used in SOC 2 audits: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Trust Service Criteria are the framework used in SOC 2 attestations, developed by AICPA.
The five criteria: 1. Security (Common Criteria): Protection against unauthorized access. Required for all SOC 2 reports. 2. Availability: System is available as committed. Addresses uptime, DR, BC. 3. Processing Integrity: Processing is complete, valid, accurate, timely. 4. Confidentiality: Confidential information is protected. 5. Privacy: Personal information is handled appropriately.
Organizations choose criteria based on services and customer requirements. Security is always required; others are optional.
Why It Matters
Choosing the right Trust Service Criteria determines the scope and value of your SOC 2 report. Including only Security is the minimum, but most enterprise customers expect Availability and Confidentiality as well. Understanding each criterion helps organizations focus their compliance efforts on what matters most to their customers while avoiding unnecessary scope expansion that increases audit costs.
Key Points
Applicable Compliance Frameworks
Related Terms
SOC 2 is an auditing framework developed by AICPA that evaluates how service organizations manage customer data based on five Trust Service Criteria.
Controls testing is the process of evaluating whether security and compliance controls are properly designed and operating effectively to achieve their intended objectives.
Frequently Asked Questions
Which Trust Service Criteria should I include?
Security is required. Most SaaS companies add Availability. Add others based on data types and customer requirements.
What are Points of Focus?
Supplementary considerations within each criteria that help organizations understand how to meet requirements. They're guidance, not mandatory.
Related Services & Resources
Vanta Implementation
Expert Vanta deployment with 80+ integrations configured in 4-6 weeks
Learn moreDrata Implementation
Full Drata setup with automated evidence collection and control mapping
Learn moreISO 27001 Certification
International standard for information security management
Learn moreHIPAA Compliance
Healthcare data protection requirements for PHI security
Learn moreSOC 2 Complete Guide
Everything you need to know about achieving SOC 2 compliance
Learn moreHIPAA Checklist
Comprehensive checklist for HIPAA compliance requirements
Learn moreNeed Help with Trust Service Criteria?
Our experts can help you understand and implement the right controls for your organization.