SOC 2 · Trust Services Criteria
The AICPA Trust Services Criteria,
Explained
The AICPA’s control criteria for SOC 2 examinations, organised into five categories. Security — the common criteria, CC1–CC9 — is mandatory in every report; Availability, Processing Integrity, Confidentiality, and Privacy are scoped in based on what you commit to customers.
A precision worth keeping: the five names are categories, not criteria — the criteria are the requirements beneath them, and they are what your auditor actually evaluates.
Plain-English explainer · TSC 2017, 2022 points of focus · Last reviewed July 2026
The Trust Services Criteria (TSC) are the control criteria the AICPA defines for SOC 2 examinations — the fixed benchmark a CPA firm measures your controls against. The current version is TSC 2017, with points of focus revised in 2022, organised into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The names cause a persistent confusion: the five are categories, while the criteria are the individual requirements beneath them (CC6.1, A1.2, P3.1, and so on). Security is the only category included in every SOC 2 — its criteria are the common criteria, CC1–CC9 — and the other four are scoped to match your service commitments. The report names which categories were examined — the TSC selection determines what your auditor tests and what your customers can rely on.
The five categories
One mandatory, four optional
Each category is a set of criteria with its own series prefix: Security carries the common criteria (CC), and the optional categories add the A, PI, C, and P series on top of it.
Security
Criteria series: CC1–CC9
The common criteria — the only category included in every SOC 2. Protection of systems and data against unauthorised access, disclosure, and damage.
Read the Security criteriaAvailability
Criteria series: A1
For uptime commitments — capacity management, backup and recovery, and environmental protections. Common wherever customers rely on an SLA.
Read the Availability criteriaProcessing Integrity
Criteria series: PI1
For systems that must process data completely, accurately, and on time — inputs, processing, outputs, and the integrity of stored items.
Read the Processing Integrity criteriaConfidentiality
Criteria series: C1
For information designated confidential — identifying it, protecting it, and disposing of it when commitments end.
Read the Confidentiality criteriaPrivacy
Criteria series: P1–P8
For personal information — notice, choice and consent, collection, use, retention, disclosure, quality, and enforcement. The largest optional add-on.
Read the Privacy criteriaSecurity · CC1–CC9
The common criteria, series by series
Because Security appears in every SOC 2, its criteria are the “common criteria” — the 2017 TSC defines 33 of them, organised into nine series. CC1–CC5 align with COSO’s 17 internal-control principles — control environment, communication and information, risk assessment, monitoring activities, and control activities. CC6–CC9 are the supplemental, more technical series — access control, operations, change management, and risk mitigation.
| Series | Focus | What auditors look for |
|---|---|---|
| CC1Control environment | Integrity and ethics, leadership oversight, structure, competence, and accountability — the COSO control-environment principles. | Code of conduct, background screening, org chart and reporting lines, defined security roles and leadership oversight. |
| CC2Communication & information | Communicating security objectives, responsibilities, and commitments internally and externally. | Acknowledged policies, commitments communicated to customers, working channels for reporting incidents and concerns. |
| CC3Risk assessment | Identifying and analysing risks (including fraud risk) and assessing changes that could affect controls. | A documented risk assessment and risk register, fraud-risk consideration, re-assessment when the business or system changes. |
| CC4Monitoring activities | Ongoing and separate evaluations of whether controls are present and functioning, and communication of deficiencies. | Control monitoring, internal audits or readiness assessments, tracked remediation of identified deficiencies. |
| CC5Control activities | Selecting and deploying control activities through policies and procedures that address identified risks. | Controls demonstrably mapped to risks, documented procedures, general IT controls over the technology stack. |
| CC6Logical & physical access | Identity, authentication, authorisation, provisioning, physical access, and protection of data at rest and in transit. | MFA, least-privilege roles, timely offboarding, periodic access reviews, encryption, physical entry controls, secure media disposal. |
| CC7System operations | Detecting and responding to anomalies, vulnerabilities, and security events; recovering from incidents. | Vulnerability management, security monitoring and alerting, incident-response records and post-incident reviews, tested recovery. |
| CC8Change management | Authorising, designing, testing, approving, and deploying changes to infrastructure, data, and software. | Documented change workflow, peer review and pre-deployment approvals, segregation of duties, handling of emergency changes. |
| CC9Risk mitigation | Mitigating risks of business disruption and risks arising from vendors and business partners. | Vendor due diligence and risk assessments, review of vendors’ own SOC reports, contractual security commitments, disruption-mitigation activities. |
In practice, CC6 and CC7 generate the largest share of evidence requests. For how these criteria translate into a working control set, see our illustrative SOC 2 controls list.
The optional categories
A1, PI1, C1, and P1–P8
Each optional category layers its own criteria series onto the common criteria — none stands alone without Security — and each one you add expands the evidence your auditor tests.
Availability — the A1 series
Availability adds criteria on maintaining and monitoring capacity, backup and recovery provisions, and environmental protections for infrastructure. Choose it when customers rely on an uptime SLA — for most SaaS platforms it is the first optional add.
Processing Integrity — the PI1 series
Processing Integrity addresses whether the system processes data completely, accurately, on time, and only as authorised: its criteria cover inputs, processing, outputs, and the integrity of stored items. It fits payment processors, payroll engines, and billing systems — anywhere a customer relies on the correctness of a transaction.
Confidentiality — the C1 series
Confidentiality adds criteria on identifying information designated as confidential — customer business data, contracts, intellectual property — and on protecting and disposing of it in line with commitments. If your MSAs and NDAs promise confidential treatment of customer data, it is a natural, low-friction inclusion.
Privacy — the P1–P8 series
Privacy is the largest optional add, organised into eight series: notice (P1); choice and consent (P2); collection (P3); use, retention, and disposal (P4); access (P5); disclosure and notification (P6); quality (P7); and monitoring and enforcement (P8). Because it adds the most criteria and operational scope, many organisations defer Privacy in their first SOC 2 and add it once the privacy program matures.
The guidance layer
Points of focus — guidance, not a checklist
Beneath every criterion the AICPA publishes points of focus — short statements describing characteristics that matter to achieving the criterion. They were revised in 2022 to reflect current technology and practices, which is why the TSC is often cited as “TSC 2017 (with revised points of focus, 2022)”.
Their status matters: points of focus are not requirements to be individually satisfied. The auditor’s opinion is formed at the criterion level; points of focus inform that judgement but are not separately “passed” or “failed”, and an organisation need not address every one. Used well, they are a design aid for pressure-testing your controls before the auditor asks.
The key distinction
Criteria vs controls
The division of labour in a SOC 2 is precise. The AICPA defines the criteria — fixed, universal statements of what must be achieved. Your organisation designs the controls — the specific mechanisms that achieve them in your environment. The auditor maps your controls to the criteria and tests them — first whether each control is suitably designed, then (in a Type 2) whether it operated effectively over the review period.
This is why no two SOC 2 reports contain identical control lists: a small startup and a global data-centre operator answer the same criteria with very different controls. It is also why criteria matter when things go wrong — a control that fails testing becomes an exception against the criterion it supports, and enough of them can qualify the opinion (see SOC 2 opinions and exceptions). Our SOC 2 controls list shows a typical criteria-to-control mapping.
Scoping
How to choose your categories
The selection is driven by your principal service commitments — the promises you make in contracts, SLAs, and public documentation. The mapping is direct:
- You commit to an uptime SLA or sit in customers’ critical path → add Availability.
- You promise complete, accurate, timely transaction processing (payments, payroll, billing) → add Processing Integrity.
- Your contracts and NDAs designate customer data as confidential → add Confidentiality.
- You make commitments to individuals about their personal information → add Privacy.
Two practical rules follow. First, scope in only what you can evidence: an Availability category without tested recovery converts ambition into exceptions. Second, the selection is not forever — most organisations start with Security (often plus Availability) and add categories in later cycles. The Type 1 vs Type 2 decision is a separate axis — either report type can cover any category selection. To see how commitments translate into scope, our interactive SOC 2 simulator walks through exactly this logic.
This scoping conversation is where Tranquility Cybersecurity (TCSA) typically starts a SOC 2 engagement: we review your commitments, map them to categories and criteria, prepare the control set and evidence, and coordinate the examination through empanelled, independent licensed CPA firms who issue the report.
Common misconceptions
Four things the TSC is not
“The TSC are five criteria.”
The five names are categories. The criteria are the requirements beneath them — CC1.1, A1.2, P4.3, and so on — and they are what auditors evaluate.
“All five categories are required.”
Only Security is required. The other four are scoped in based on your service commitments — a Security-only report is a complete, valid SOC 2, and often exactly what buyers ask for.
“Points of focus are a checklist to satisfy.”
They are guidance illustrating how a criterion might be met. The auditor concludes on the criterion; you need not address every point of focus, and no opinion is issued on them individually.
“TSC 2022 replaced TSC 2017.”
The 2022 revision updated the points of focus — the guidance layer — to reflect current technology and risk. The criteria themselves remain the 2017 Trust Services Criteria, which is why reports still cite TSC 2017.
Trust Services Criteria — Common Questions
Categories, common criteria, points of focus, and how criteria relate to controls.
What are the Trust Services Criteria?
The Trust Services Criteria (TSC) are the control criteria the AICPA establishes for SOC 2 examinations — the benchmark a licensed CPA firm measures a service organisation’s controls against. The current version is TSC 2017, with points of focus revised in 2022, organised into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
What are the five Trust Services Categories, and which are mandatory?
Security (the common criteria, CC1–CC9), Availability, Processing Integrity, Confidentiality, and Privacy. Only Security is mandatory — it appears in every SOC 2 examination, which is why its criteria are called the common criteria. The other four are optional, scoped in based on the commitments you make to customers. A Security-only report is a complete, valid SOC 2, and you can add categories in a later examination as requirements evolve.
What are the Common Criteria (CC1–CC9)?
The common criteria are the criteria of the Security category, organised into nine series. CC1–CC5 align with COSO’s internal-control principles — control environment, communication and information, risk assessment, monitoring activities, and control activities. CC6–CC9 are the supplemental, more technical series: logical and physical access controls, system operations, change management, and risk mitigation.
What are points of focus in the TSC?
Points of focus are guidance published under each criterion — characteristics that illustrate how it might be met — revised in 2022 to reflect current technology and practices. They are not requirements to be individually satisfied: auditors use them to inform their evaluation of whether the criteria are met, but no opinion is issued on points of focus themselves.
How many Trust Services Criteria are there?
The 2017 TSC defines 33 common criteria across the nine CC series — those apply to every SOC 2. Each optional category adds its own series: Availability (A1), Processing Integrity (PI1), Confidentiality (C1), and Privacy (P1–P8, the largest set). The total in scope depends on which categories the organisation selects.
How do criteria differ from controls?
Criteria are the AICPA’s fixed requirements — what must be achieved. Controls are the specific mechanisms your organisation designs to achieve them — MFA, access reviews, change approvals. The AICPA does not prescribe controls: you design your own set, and the auditor maps each control to the criteria it supports and tests it (design in a Type 1; design and operating effectiveness in a Type 2).
Related reading: What is SOC 2?, the SOC 2 controls list, how to read a SOC 2 report, opinions & exceptions, Type 1 vs Type 2, and TCSA’s SOC 2 services. More terms in the compliance glossary.
Written By Expert Auditors
Get in touch
Book a free consultation or send us your requirements. We respond within 24 hours.
Quick Call
Pick a time slot
Send Requirements
Get a custom quote in 24 hours