For organizations pursuing SOC 2 compliance, one of the most important concepts to understand is the Trust Services Criteria (TSC).
The Trust Services Criteria form the foundation of every SOC 2 audit and help organizations demonstrate that they have effective controls in place to protect customer data and maintain secure operations.
Whether you’re a SaaS startup, cloud service provider, FinTech company, or managed service provider, understanding these criteria is essential for achieving and maintaining SOC 2 compliance.
In this guide, we’ll cover:
- What the Trust Services Criteria are
- Why they matter in SOC 2 compliance
- The five Trust Services Criteria explained
- Examples of controls under each category
- Which criteria your business should include
- Common mistakes organizations make
What Are the Trust Services Criteria (TSC)?
The Trust Services Criteria are a set of control objectives developed by the American Institute of Certified Public Accountants (AICPA).
They are used by auditors to evaluate whether an organization has implemented appropriate controls to protect systems and customer information.
The five Trust Services Criteria are:
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
Among these, Security is mandatory for every SOC 2 audit.
The remaining four criteria are optional and selected based on business requirements and customer expectations.
Why Are the Trust Services Criteria Important?
The Trust Services Criteria help organizations demonstrate that they can:
- Protect sensitive information
- Manage cybersecurity risks
- Maintain reliable services
- Handle confidential data properly
- Respect customer privacy
These criteria provide a structured framework for evaluating security and operational effectiveness.
Enterprise customers frequently review SOC 2 reports to verify that vendors meet these standards.
Overview of the 5 Trust Services Criteria
| Criteria | Purpose |
|---|---|
| Security | Protect systems against unauthorized access |
| Availability | Ensure systems remain operational and accessible |
| Processing Integrity | Ensure data processing is accurate and complete |
| Confidentiality | Protect sensitive business information |
| Privacy | Manage personal information appropriately |
Let’s examine each criterion in detail.
1. Security (Common Criteria)
Security is the foundation of SOC 2 compliance and is included in every SOC 2 audit.
The primary objective is to protect systems and data from unauthorized access, misuse, and cyber threats.
Security controls typically focus on:
- Access management
- Authentication
- Network security
- Monitoring
- Incident response
- Risk management
Examples of Security Controls
Organizations commonly implement:
- Multi-factor authentication (MFA)
- Role-based access controls
- Endpoint protection
- Security monitoring
- Vulnerability management
- Incident response procedures
Why Security Is Mandatory
Without strong security controls, organizations cannot effectively support the other Trust Services Criteria.
This is why every SOC 2 report includes Security as the baseline requirement.
2. Availability
Availability evaluates whether systems remain accessible and operational as committed to customers.
This criterion focuses on ensuring that services are available when users need them.
Availability does not mean zero downtime.
Instead, it assesses whether organizations have implemented appropriate measures to maintain service reliability.
Examples of Availability Controls
Common controls include:
- Infrastructure monitoring
- Disaster recovery planning
- Business continuity procedures
- Backup management
- Capacity planning
- Redundancy measures
Who Should Include Availability?
Availability is often important for:
- SaaS companies
- Cloud platforms
- Managed service providers
- Critical business applications
Customers relying on continuous service access frequently request this criterion.
3. Processing Integrity
Processing Integrity evaluates whether systems process information accurately, completely, and in a timely manner.
The focus is on ensuring that data processing functions correctly.
This criterion helps demonstrate that systems produce reliable outputs.
Examples of Processing Integrity Controls
Organizations may implement:
- Data validation checks
- Error detection mechanisms
- Change management processes
- Transaction monitoring
- Quality assurance procedures
Who Should Include Processing Integrity?
Processing Integrity is especially relevant for:
- Financial platforms
- Payment processors
- Healthcare systems
- ERP applications
- Data processing services
Organizations handling critical transactions often include this criterion.
4. Confidentiality
Confidentiality focuses on protecting sensitive information from unauthorized disclosure.
This includes information that is not intended for public access.
Examples include:
- Intellectual property
- Proprietary business data
- Customer contracts
- Financial information
- Trade secrets
Examples of Confidentiality Controls
Common controls include:
- Data encryption
- Access restrictions
- Secure file sharing
- Data classification policies
- Confidentiality agreements
Who Should Include Confidentiality?
Confidentiality is commonly selected by:
- SaaS providers
- Legal technology firms
- Financial services organizations
- Consulting companies
- Research organizations
Any business handling sensitive non-public information should consider this criterion.
5. Privacy
Privacy focuses on how organizations collect, use, store, share, and dispose of personal information.
This criterion evaluates whether personal data is managed according to privacy commitments and applicable regulations.
Privacy requirements often overlap with data protection laws.
Examples of Privacy Controls
Organizations may implement:
- Consent management processes
- Privacy notices
- Data retention policies
- Data subject request procedures
- Personal data protection controls
Who Should Include Privacy?
Privacy is particularly important for:
- SaaS companies
- eCommerce businesses
- Healthcare platforms
- HR software providers
- Consumer-facing applications
Businesses handling large volumes of personal information often include Privacy in their SOC 2 scope.
How the Trust Services Criteria Work Together
The five criteria are interconnected.
For example:
- Security supports Confidentiality.
- Confidentiality supports Privacy.
- Availability supports service reliability.
- Processing Integrity ensures trustworthy outcomes.
Together, they create a comprehensive framework for evaluating organizational controls.
Which Trust Services Criteria Should Your Business Choose?
Not every organization needs all five criteria.
The right selection depends on:
- Industry requirements
- Customer expectations
- Regulatory obligations
- Business model
- Data sensitivity
Most Common SOC 2 Scope
Many organizations begin with:
- Security
or
- Security + Availability
These are often sufficient for early-stage SaaS companies.
Expanded Enterprise Scope
Larger organizations frequently include:
- Security
- Availability
- Confidentiality
or
- Security
- Availability
- Confidentiality
- Privacy
This broader scope provides stronger assurance to enterprise customers.
Common Mistakes When Selecting Trust Services Criteria
Choosing All Five Without Business Need
Including unnecessary criteria increases audit complexity and cost.
Ignoring Customer Requirements
Enterprise clients often specify which criteria they expect vendors to cover.
Overlooking Privacy Obligations
Organizations handling personal information may underestimate privacy expectations.
Failing to Define Scope Properly
Poorly scoped audits often result in higher implementation effort and longer timelines.
How Trust Services Criteria Affect SOC 2 Costs
Each additional criterion increases:
- Documentation requirements
- Control implementation
- Evidence collection
- Audit testing
- Compliance management effort
Organizations should select criteria strategically rather than automatically choosing all five.
Benefits of Implementing the Trust Services Criteria
When properly implemented, the Trust Services Criteria help organizations:
- Strengthen cybersecurity
- Improve customer trust
- Reduce operational risks
- Support enterprise sales
- Enhance compliance maturity
- Improve governance practices
Many businesses find that the operational improvements extend well beyond audit requirements.
Final Thoughts
The five Trust Services Criteria are the core of every SOC 2 audit.
They provide a structured framework for evaluating how organizations protect systems, manage data, and deliver reliable services.
To recap:
Security
Protects systems and data from unauthorized access.
Availability
Ensures services remain accessible and reliable.
Processing Integrity
Ensures data processing is accurate and complete.
Confidentiality
Protects sensitive business information.
Privacy
Protects personal information and supports responsible data handling.
For most organizations, Security is the starting point. Additional criteria should be selected based on customer expectations, business needs, and compliance objectives.
A well-planned SOC 2 program aligned with the appropriate Trust Services Criteria can help organizations strengthen security, build trust, and accelerate growth in competitive markets.
Need Help with SOC 2 Compliance?
Whether you’re preparing for a SOC 2 Type I or Type II audit, selecting the right Trust Services Criteria is critical to audit success.
A structured readiness assessment can help you:
- Define the right audit scope
- Identify control gaps
- Reduce compliance costs
- Improve audit readiness
- Accelerate enterprise sales opportunities
The right compliance strategy ensures your SOC 2 program delivers both security value and business growth.




















