home / frameworks / soc-2 / trust-services-criteria

// SOC 2 hub

SOC 2 Trust Services Criteria explained

How the 2017 Trust Services Criteria are built, what the 9 common criteria cover, and how to choose the optional categories.

What the criteria are

The Trust Services Criteria are the benchmark a CPA uses in a SOC 2 examination. They're set by the AICPA's Assurance Services Executive Committee and cover 5 categories, which are security, availability, processing integrity, confidentiality, and privacy. The version in use is the 2017 Trust Services Criteria with revised points of focus from 2022. The criteria themselves didn't change then.

The criteria are outcome based. They say what a control system must achieve, not which tool or setting to use. A small SaaS company and a large data centre operator can both meet CC6.1, for example, with very different controls. That flexibility is why 2 SOC 2 reports can look quite different even when both opinions are clean.

The common criteria for security

Security is mandatory in every report. It is covered by 33 common criteria, so called because they also apply to the other categories. The first 5 groups follow the structure of the COSO 2013 internal control framework, and the last 4 add technology and risk topics that COSO treats only broadly.

  • CC1 Control environment: governance, ethics, structure, competence, and accountability
  • CC2 Communication and information: quality information and internal and external communication
  • CC3 Risk assessment: objectives, risk identification, fraud risk, and change
  • CC4 Monitoring activities: evaluating controls and fixing deficiencies
  • CC5 Control activities: choosing controls, technology controls, and policies
  • CC6 Logical and physical access: user access, least privilege, encryption in transit, malware, disposal
  • CC7 System operations: vulnerability detection, monitoring, incident response, and recovery
  • CC8 Change management: authorizing, testing, and approving changes
  • CC9 Risk mitigation: business disruption planning and vendor risk

The 4 optional categories

Availability (A1) adds 3 criteria on capacity, backups, recovery infrastructure, and recovery testing. It suits services with uptime commitments. Confidentiality (C1) adds 2 criteria on identifying, protecting, and disposing of confidential information such as customer business data, source code, or pricing.

Processing integrity (PI1) adds 5 criteria on whether inputs, processing, and outputs are complete, accurate, timely, and authorized. It fits payroll, billing, claims, and transaction processors. Privacy (P1 to P8) adds 18 criteria on notice, consent, collection, use, retention, access, disclosure, data quality, and complaints, which makes it the largest category by far. Many Canadian vendors pick confidentiality over privacy. The privacy criteria assume the vendor makes commitments directly to individuals, which isn't true for many business-to-business services.

Points of focus

Each criterion comes with points of focus, which describe characteristics a control system often has when it meets that criterion. They are not requirements. An organization doesn't have to address every one of them, and the 2022 revision updated the points of focus and added implementation guidance while leaving the criteria unchanged.

Auditors use points of focus to judge whether the controls a company picked are enough to meet a criterion. Readiness work goes faster if each control is mapped to the criterion it supports and the points of focus it covers.

Choosing categories for your report

Start from what customers ask for and what your contracts promise. If a master services agreement includes an uptime commitment, availability is a natural addition. If customers send detailed questionnaires about how their business data is stored, shared, and deleted, confidentiality usually comes next in line. Each category adds cost. It increases the number of controls tested, the evidence needed, and the fee.

The categories chosen are listed in the auditor's opinion, so readers can see exactly what was covered. A report can add categories later. Most organizations start with security alone and expand once the first Type 2 cycle runs smoothly and the team has time for more controls.

Resources

All SOC 2 resources

References

  1. 2017 Trust Services Criteria (With Revised Points of Focus - 2022), AICPA and CIMA
  2. SOC 2: SOC for Service Organizations: Trust Services Criteria, AICPA and CIMA
  3. Mapping: 2017 Trust Services Criteria to ISO 27001, AICPA and CIMA