SOC 2 / criteria map

SOC 2 Trust Services Criteria

SOC 2 reports are scoped against the Trust Services Criteria. Security is always included. Availability, Processing Integrity, Confidentiality, and Privacy are added when your customer commitments and data flows make them relevant.

SOC 2 Trust Services Criteria map showing security, availability, processing integrity, confidentiality and privacy.
SOC 2 criteria map / 13 KB WebP
Common

Security

The security criterion is mandatory for every SOC 2 report. It covers protection against unauthorised access (both logical and physical). Every organisation that does SOC 2 includes this one.

12 common control areas ->

TSC

Availability

Availability covers system availability, processing capacity, and disaster recovery. It matters most for SaaS companies that promise uptime SLAs to customers.

7 common control areas ->

TSC

Processing Integrity

Processing integrity means system processing is complete, accurate, timely, and authorised. It is most relevant for organisations that process data on behalf of others (payment processors, data processors).

5 common control areas ->

TSC

Confidentiality

Confidentiality covers the protection of designated confidential information. It matters when you handle client data, trade secrets, or any information marked as confidential.

6 common control areas ->

TSC

Privacy

Privacy covers the collection, use, retention, disclosure, and disposal of personal information in line with the organisation's privacy notice and applicable laws (GDPR, CCPA, Australian Privacy Principles).

8 common control areas ->

How to choose criteria

Always include Security

The common criteria are mandatory and form the baseline for access, monitoring, change, vendor, and risk controls.

Add criteria from commitments

Availability, confidentiality, processing integrity, and privacy should match what you promise customers and what your system actually does.

Keep evidence practical

Each selected criterion needs policy, owner, control operation, sample evidence, review cadence, and auditor-ready exports.

SOC 2 policy templates for Trust Services Criteria

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Audit-ready next steps

SOC 2 documents, evidence, and software path

Access, supplier, change, incident, backup, encryption, secure development, monitoring, and review records.