The Trust Services Criteria (TSC) are the AICPA criteria a CPA firm uses to evaluate controls in a SOC 2 examination. They are grouped into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
The current set is the 2017 Trust Services Criteria with revised points of focus (2022), published by the AICPA. The criteria describe what well-designed controls should achieve. They do not list the exact controls your company must run. Management designs the controls, and the auditor tests them against the criteria in scope.
In simple terms, the Trust Services Criteria answer:
- Which trust themes does this SOC 2 report cover?
- What should controls achieve for each of those themes?
- What benchmark will the auditor use to judge design and, for Type 2, operation?
This page is the short definition. For scoping advice, criterion-by-criterion examples, and help choosing optional categories, read SOC 2 Trust Services Criteria Explained. For the attestation itself, see What Is SOC 2?.
Why the Trust Services Criteria Matter
The criteria set the scope and the yardstick for a SOC 2 report.
They matter because:
- Report readers check which categories are in scope before they rely on the report.
- Auditors map every in-scope control back to one or more criteria.
- Adding a category adds criteria to address, controls to operate, and evidence to keep.
- Shared language helps engineering, security, and compliance agree on what "covered" means.
- Clear criteria mapping reduces surprise requests during fieldwork.
A sales claim such as "we are SOC 2 for everything" means little until you know which criteria the report actually covers. The system description names that scope.
The Five Categories at a Glance
| Category | What it addresses | Criteria series | When teams include it |
|---|---|---|---|
| Security | Protection against unauthorized access, disclosure, and damage | Common criteria CC1 to CC9 | Baseline for SOC 2 examinations |
| Availability | System availability for operation and use as committed or agreed | A1 | Uptime, recovery, or capacity commitments matter to customers |
| Processing Integrity | Complete, valid, accurate, timely, and authorized processing | PI1 | The service processes transactions or calculations customers depend on |
| Confidentiality | Protection of information designated as confidential | C1 | Contracts or customers require confidential data handling |
| Privacy | Collection, use, retention, disclosure, and disposal of personal information | P1 to P8 | The service handles personal information under privacy commitments |
Security is the baseline category, and its common criteria also apply when you add other categories. See What Is Availability? and What Is Confidentiality? for two of the optional categories in more depth.
Criteria vs Points of Focus vs Controls
These three terms get mixed up often. Keep them separate.
| Term | Who writes it | What it is | Common confusion |
|---|---|---|---|
| Criterion | AICPA | The benchmark a control set must meet, such as a CC6 logical access criterion | Treating a criterion as a ready-made control |
| Point of focus | AICPA | An illustrative characteristic that may help a team design or assess controls for a criterion | Treating every point of focus as a mandatory checklist item |
| Control | Your company | The specific activity you run, such as a quarterly user access review | Expecting the AICPA to tell you which tool or cadence to use |
The AICPA describes points of focus as guidance, not requirements. Your auditor evaluates whether your controls meet the criteria, given your risks and your system.
How the Criteria Are Structured
Common criteria
The Security category is made up of the common criteria, numbered CC1 through CC9. CC1 to CC5 align with the 17 principles in the COSO 2013 Internal Control framework: control environment, communication and information, risk assessment, monitoring activities, and control activities.
CC6 to CC9 add topics that matter for technology services:
- CC6: logical and physical access controls (see access control)
- CC7: system operations, including detection and incident response
- CC8: change management
- CC9: risk mitigation, including vendor and business disruption risk
Category-specific criteria
Availability, Processing Integrity, Confidentiality, and Privacy each add their own criteria on top of the common criteria. For example, the Availability criteria cover capacity, backup and recovery infrastructure, and recovery plan testing.
The 2022 revision
The 2022 update revised the points of focus. The AICPA did not replace the 2017 criteria themselves. Reports and readiness work today generally reference "2017 TSC with revised points of focus (2022)."
What Is Required vs Common Practice
Keep requirements and habits apart when you plan scope.
What the SOC 2 framework sets:
- A SOC 2 examination evaluates controls against the Trust Services Criteria for the categories in scope.
- Security, through the common criteria, is the baseline.
- Management selects any additional categories and describes the system.
What is common practice, not a fixed rule:
- Specific control cadences, such as quarterly access reviews or annual restore tests
- Specific tools, ticket fields, or evidence formats
- Adding Availability or Confidentiality because many customers ask for them
Your auditor may have expectations about cadence and evidence quality. Those expectations come from your risks, your commitments, and their professional judgment, not from a fixed list in the criteria.
Example: One Criterion, Many Controls
A single criterion usually needs several controls, and one control can support more than one criterion.
| Criterion theme | Example controls | Example evidence |
|---|---|---|
| CC6 logical access | SSO with MFA, joiner-mover-leaver workflow, periodic access review | Identity provider settings, offboarding tickets, signed review exports |
| CC8 change management | Peer review, branch protection, deployment approvals | Pull request history, protection rule settings, change tickets |
| A1 availability (if in scope) | Backups, restore tests, documented recovery plan | Backup logs, restore test records, plan versions |
| C1 confidentiality (if in scope) | Data classification, encryption, disposal | Classification policy, encryption settings, disposal records |
This many-to-many link is why control mapping matters. It lets you show which controls and which audit evidence support each criterion.
Framework Notes
SOC 2 Type 1 and Type 2
The criteria are the same for both report types. A Type 1 report looks at control design at a point in time. A Type 2 report also tests whether controls operated over an audit period. See What Is SOC 2 Type 1?, What Is SOC 2 Type 2?, and SOC 2 Type 1 vs Type 2.
SOC 3
A SOC 3 report uses the same Trust Services Criteria but is a general-use summary without the detailed test results found in a SOC 2 report. The AICPA describes both on its SOC suite of services pages.
ISO 27001 and NIST
The TSC are not ISO 27001 or NIST controls. Many teams still map one control set across frameworks to cut duplicate work. Mapping saves effort, but each framework keeps its own requirements. See What Is ISO 27001? and mapping controls across SOC 2 and ISO 27001.
Common Misunderstandings
- "The TSC are a control list." They are criteria. You still design controls.
- "Every point of focus is mandatory." Points of focus are illustrative guidance.
- "We need all five categories." Security is the baseline. Add others only when commitments justify them.
- "Availability means we guarantee uptime." It means controls support your stated availability commitments.
- "Confidentiality and Privacy are the same." Confidentiality covers designated confidential information. Privacy covers personal information.
- "Type 2 uses different criteria." Both types use the same criteria. Type 2 adds operating effectiveness over a period.
How AuditFlo Helps
AuditFlo (auditflo.co) helps teams retain continuous evidence collection and audit-period history for control and readiness artifacts when those records are stored or linked through connected systems and workflows your team already uses, such as GitHub, Jira, Okta, AWS, and Google Workspace.
The focus is organizing dated proof and mapping it to the controls behind each in-scope criterion. AuditFlo is positioned here as evidence and readiness support. It does not select your criteria, does not issue SOC 2 reports, does not certify compliance, does not guarantee any report opinion, and does not replace auditors or your CPA firm.
To see the workflow for your stack, request a demo.
Key Takeaway
The Trust Services Criteria are the AICPA benchmarks a SOC 2 auditor uses to judge your controls. They cover five categories, with Security as the baseline and Availability, Processing Integrity, Confidentiality, and Privacy added when your commitments call for them. The criteria tell you what controls should achieve. Your company still designs the controls, operates them, and keeps the evidence.