In the AICPA Trust Services Criteria for SOC 2, what are the five categories, and which criteria apply to every examination?
answer
- security plus four optional
- common criteria, CC series
- COSO's seventeen principles underneath
- category-specific A, C, PI, P
- points of focus are not a checklist
basics
~20 sThe categories are security, availability, processing integrity, confidentiality and privacy. The common criteria (CC1 to CC9) apply in every SOC 2 examination; each other category chosen adds its own criteria: A, PI, C or P series.
solid answer
~50 sThe 2017 **Trust Services Criteria** define five categories: **security**, **availability**, **processing integrity**, **confidentiality** and **privacy**. The **common criteria** (CC1 to CC9, 33 criteria) apply to every category. CC1 to CC5 follow COSO's 17 internal-control principles (control environment, information and communication, risk assessment, monitoring, control activities), and CC6 to CC9 add supplemental criteria: logical and physical access, system operations, change management, risk mitigation. Security needs nothing beyond the common criteria; each other category adds its own series — availability A1, processing integrity PI1, confidentiality C1, privacy P1 to P8. Security is in almost every SOC 2, though the TSC call leaving it out uncommon rather than forbidden. A B2B SaaS vendor usually picks security plus availability and confidentiality, based on customer commitments. **Points of focus** guide how a criterion is met; they are not each required.
go deeper
Recall the five categories and that the common criteria, CC1 to CC9, apply to every SOC 2.
Explain how CC1 to CC5 derive from COSO and CC6 to CC9 add technology criteria, and how a vendor chooses categories from its commitments.
Show how you would scope categories for a vendor, defend a criterion marked not applicable, and use points of focus without turning them into a checklist.
Discuss when adding availability, processing integrity or privacy is worth the added audit cost relative to what customers actually rely on.
## The five categories The AICPA's **2017 Trust Services Criteria** (TSP section 100, with revised points of focus in 2022) are the criteria a SOC 2 examination evaluates controls against. They are grouped into five **Trust Services Categories**: | Category | TSC definition, in short | Extra criteria | |---|---|---| | **Security** | Information and systems are protected against unauthorized access, disclosure and damage | None beyond the common criteria | | **Availability** | Information and systems are available for operation and use to meet objectives | A1.1–A1.3 | | **Processing integrity** | Processing is complete, valid, accurate, timely and authorized | PI1.1–PI1.5 | | **Confidentiality** | Information designated confidential is protected | C1.1–C1.2 | | **Privacy** | Personal information is collected, used, retained, disclosed and disposed of to meet objectives | P1–P8 series | The TSC distinguish confidentiality from privacy: privacy applies only to personal information, while confidentiality covers any information designated confidential, such as trade secrets. ## The common criteria Every SOC 2 examination uses the **common criteria**, because controls such as logical access affect every category. There are 33 of them across nine series: - **CC1** Control environment (COSO principles 1–5). - **CC2** Information and communication. - **CC3** Risk assessment. - **CC4** Monitoring activities. - **CC5** Control activities. - **CC6** Logical and physical access controls. - **CC7** System operations. - **CC8** Change management. - **CC9** Risk mitigation, including vendors and business partners. CC1 to CC5 are aligned to the 17 principles of the COSO internal control framework (2013). CC6 to CC9 are **supplemental criteria** the AICPA added under COSO principle 12 for technology controls. For security, the TSC say the common criteria are sufficient and "no additional control activity criteria are needed". For any other category, the complete set is the common criteria plus that category's specific criteria. ## Is security mandatory? In practice nearly every SOC 2 includes security, and customers expect it. The TSC text itself is more careful: it describes an examination without the security category as "uncommon", and says that even then the common criteria are applied as they affect the chosen category. What is never optional is the **common criteria**. ## Choosing categories for a B2B SaaS vendor Categories should follow the vendor's **service commitments** to customers: 1. **Security** — always, as the base customers expect. 2. **Availability** — if contracts promise uptime or recovery targets. 3. **Confidentiality** — if the vendor holds customer data marked confidential under contract. 4. **Processing integrity** — if customers rely on the accuracy and completeness of processing, such as billing or payments. 5. **Privacy** — if the vendor itself collects personal information from data subjects; many vendors processing on a customer's behalf rely on confidentiality instead. Adding a category means every criterion in it must be addressed; a criterion can be marked not applicable only when it is genuinely irrelevant to the service, as the TSC illustrate with P3.1 for a vendor that does not collect personal information directly. ## Points of focus Each criterion comes with **points of focus**: characteristics that help design and evaluate controls. The TSC state that use of the criteria "does not require an assessment of whether each point of focus is addressed". They are guidance for judgement, not a checklist; the criterion is what the opinion addresses.
- Why do the common criteria apply even when a report covers only availability?Because controls like logical access, change management and system operations affect availability as much as security. The TSC say that when security is not addressed, the complete set is the common criteria plus the availability criteria, with the common criteria evaluated for their effect on availability objectives.
- Should a SaaS vendor that processes customer personal data include the privacy category?Not automatically. The privacy criteria address notice, choice and consent, collection, use and retention, access, disclosure, quality and monitoring from the perspective of the entity dealing with data subjects. A vendor processing on a customer's behalf often includes confidentiality instead, and includes privacy only if it makes privacy commitments that the criteria would test.
saying these in an interview costs you the question
- A SOC 2 report must include all five categories.
- A report covering only availability does not use the common criteria.
- Every point of focus must be met for the criterion to be met.
- Confidentiality and privacy are two names for the same category.
- The common criteria are a separate sixth category.