SOC 2 Trust Services Criteria
SOC 2 reports are scoped against the Trust Services Criteria. Security is always included. Availability, Processing Integrity, Confidentiality, and Privacy are added when your customer commitments and data flows make them relevant.

Security
The security criterion is mandatory for every SOC 2 report. It covers protection against unauthorised access (both logical and physical). Every organisation that does SOC 2 includes this one.
12 common control areas ->
TSCAvailability
Availability covers system availability, processing capacity, and disaster recovery. It matters most for SaaS companies that promise uptime SLAs to customers.
7 common control areas ->
TSCProcessing Integrity
Processing integrity means system processing is complete, accurate, timely, and authorised. It is most relevant for organisations that process data on behalf of others (payment processors, data processors).
5 common control areas ->
TSCConfidentiality
Confidentiality covers the protection of designated confidential information. It matters when you handle client data, trade secrets, or any information marked as confidential.
6 common control areas ->
TSCPrivacy
Privacy covers the collection, use, retention, disclosure, and disposal of personal information in line with the organisation's privacy notice and applicable laws (GDPR, CCPA, Australian Privacy Principles).
8 common control areas ->
How to choose criteria
Always include Security
The common criteria are mandatory and form the baseline for access, monitoring, change, vendor, and risk controls.
Add criteria from commitments
Availability, confidentiality, processing integrity, and privacy should match what you promise customers and what your system actually does.
Keep evidence practical
Each selected criterion needs policy, owner, control operation, sample evidence, review cadence, and auditor-ready exports.
SOC 2 policy templates for Trust Services Criteria
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
SOC 2 documents, evidence, and software path
Access, supplier, change, incident, backup, encryption, secure development, monitoring, and review records.