SOC 2 Trust Services Criteria

SOC 2 Availability Criterion

Availability covers system availability, processing capacity, and disaster recovery. It matters most for SaaS companies that promise uptime SLAs to customers.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILSOC 2 Availability EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Common control areas

System monitoring

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Capacity planning

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Backup and recovery procedures

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Disaster recovery plan

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Environmental protection

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Recovery time objectives

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Redundancy and failover

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Evidence to keep

  • Control owner and review cadence
  • Policy or procedure approved by management
  • System export, ticket, report, or log sample
  • Exception record and remediation evidence

Availability policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Back to all SOC 2 criteria, or open the SOC 2 template pack.