SOC 2 · 6 min read · Updated 2026-06-29

The Five SOC 2 Trust Services Criteria, Explained

Every SOC 2 report is scoped against the Trust Services Criteria, or TSC. Understanding them tells you exactly what your audit will and will not cover.

There are five criteria. Security (the Common Criteria) is mandatory in every SOC 2; the other four are optional and chosen based on what you promise customers.

Security (the Common Criteria)

Security is the only mandatory criterion and underpins all the others. It covers protection of systems and data against unauthorised access, covering access controls, change management, risk management, and monitoring.

If a SOC 2 report mentions only one criterion, it is almost always Security.

Availability

Availability addresses whether systems are available for operation and use as committed, think uptime commitments, monitoring, incident response, and disaster recovery.

Include it if customers depend on your uptime or you make availability commitments in contracts or SLAs.

Processing Integrity

Processing Integrity covers whether system processing is complete, valid, accurate, timely, and authorised. It matters most for systems that process transactions or critical data on a customer’s behalf.

Confidentiality and Privacy

Confidentiality covers protection of information designated as confidential (for example, customer business data under NDA).

Privacy covers how you collect, use, retain, disclose, and dispose of personal information in line with your privacy notice. Add these when your product handles confidential or personal data accordingly.

SOC 2 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Automate SOC 2 with Drata

Drata maps the controls, collects evidence automatically, and keeps you audit-ready. Automated, continuous compliance with deep integrations.

FAQ

Which Trust Services Criteria are required?
Only Security (the Common Criteria) is mandatory. The other four are optional and selected based on your commitments.
Should I include all five?
Not necessarily. More criteria mean more controls and cost. Include only those relevant to what you promise customers.
What is the difference between Confidentiality and Privacy?
Confidentiality protects information designated confidential; Privacy specifically governs personal information handling.