Get Demo
↑

The 5 SOC 2 Trust Services Criteria Explained

Security, Availability, Processing Integrity, Confidentiality, and Privacy — what each TSC covers and why Security is required on every SOC 2 exam.

Published: September 2026 Compliance · SOC 2 8–12 min read

Every SOC 2 examination is scoped against the AICPA Trust Services Criteria (TSC). There are five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is required on every engagement; the other four are optional and included based on your system description, trust commitments, and what customers ask for.

Related: Common Criteria CC1–CC9 · Type I vs Type II · CSA for SOC 2.

Five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is required for every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on the system description, trust commitments, and customer needs.

How TSC Scoping Works

Your CPA firm examines controls relevant to the criteria you include. The system description (management’s description of the service) and written trust commitments drive which optional criteria belong in scope. Buyers often ask for Security plus Availability and Confidentiality for SaaS; Privacy is common when personal data handling is central to the service.

The Five Criteria

Criterion
Required?
What it addresses
Security
Yes — always
Protection against unauthorized access, use, or modification; expressed through Common Criteria CC1–CC9
Availability
Optional
System available for operation and use as committed (capacity, continuity, recovery)
Processing Integrity
Optional
System processing is complete, valid, accurate, timely, and authorized
Confidentiality
Optional
Information designated as confidential is protected as committed
Privacy
Optional
Personal information is collected, used, retained, disclosed, and disposed of in line with commitments and criteria

Security and the Common Criteria

Security is implemented through the Common Criteria (CC1–CC9) in the 2017 Trust Services Criteria. Those categories cover control environment, communication, risk assessment, monitoring, control activities, logical/physical access, system operations, change management, and risk mitigation. See also CC7 monitoring and SIEM evidence.

Choosing Optional Criteria

More criteria means more points of focus and evidence. Scope to what you commit to customers — not every optional category by default.

How CyberSilo Helps

Compliance Standards Automation maps your stack to TSC points of focus and keeps evidence ready for Type I or Type II fieldwork. Pair with ThreatHawk when CC7 monitoring proof must be operational.

Scope TSC With Evidence You Can Defend

See how CSA organises Security (CC1–CC9) and optional criteria against your system description.

Frequently Asked Questions

Is Security required on every SOC 2?

Yes. Security is required for every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional.

Can we do Privacy without Security?

No. Security is always in scope. Privacy can be added alongside Security when personal-information commitments warrant it.

Who decides which criteria are in scope?

Management defines the system description and trust commitments; customers and contracts often drive optional criteria. The CPA firm examines against that scope.

SOC 2 hub · CC1–CC9 · Controls list · Attestation vs certification · CSA SOC 2

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!