The Five SOC 2 Trust Services Criteria, Explained
Every SOC 2 report is scoped against the Trust Services Criteria, or TSC. Understanding them tells you exactly what your audit will and will not cover.
There are five criteria. Security (the Common Criteria) is mandatory in every SOC 2; the other four are optional and chosen based on what you promise customers.
Security (the Common Criteria)
Security is the only mandatory criterion and underpins all the others. It covers protection of systems and data against unauthorised access, covering access controls, change management, risk management, and monitoring.
If a SOC 2 report mentions only one criterion, it is almost always Security.
Availability
Availability addresses whether systems are available for operation and use as committed, think uptime commitments, monitoring, incident response, and disaster recovery.
Include it if customers depend on your uptime or you make availability commitments in contracts or SLAs.
Processing Integrity
Processing Integrity covers whether system processing is complete, valid, accurate, timely, and authorised. It matters most for systems that process transactions or critical data on a customer’s behalf.
Confidentiality and Privacy
Confidentiality covers protection of information designated as confidential (for example, customer business data under NDA).
Privacy covers how you collect, use, retain, disclose, and dispose of personal information in line with your privacy notice. Add these when your product handles confidential or personal data accordingly.
SOC 2 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate SOC 2 with Drata
Drata maps the controls, collects evidence automatically, and keeps you audit-ready. Automated, continuous compliance with deep integrations.
FAQ
- Which Trust Services Criteria are required?
- Only Security (the Common Criteria) is mandatory. The other four are optional and selected based on your commitments.
- Should I include all five?
- Not necessarily. More criteria mean more controls and cost. Include only those relevant to what you promise customers.
- What is the difference between Confidentiality and Privacy?
- Confidentiality protects information designated confidential; Privacy specifically governs personal information handling.