All articlesSOC 2

SOC 2 Trust Services Criteria: the five explained

SOC 2 Trust Services Criteria: the five explained

In short

  • SOC 2's five Trust Services Criteria are Security, Availability, Processing Integrity, Confidentiality and Privacy.
  • Only Security (the Common Criteria) is mandatory; the other four are scoped in based on your service commitments.
  • Type I assesses control design at a point in time; Type II assesses operating effectiveness over a period.
  • SOC 2 is an attestation report issued by a CPA firm, not a certification — there is no "SOC 2 certified".
  • The right scope mirrors what you promise customers; adding criteria you do not need only adds cost.

What are the five SOC 2 Trust Services Criteria?

SOC 2 is built on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Only Security — the Common Criteria — is mandatory; the other four are included when they match the commitments a service makes to its customers. SOC 2 is not a certification: it is an attestation report issued by a CPA firm.

SOC 2 is one of the most requested assurances in a B2B sales cycle, and one of the most misunderstood. It is not a certificate you pass or fail, and you do not have to cover all five criteria. Getting the scope right starts with knowing what the five Trust Services Criteria are and which of them actually apply to you.

The five Trust Services Criteria at a glance

The Trust Services Criteria, defined by the AICPA, are the yardstick a SOC 2 report is measured against:

  • Security — protection of systems and data against unauthorised access, use or modification.
  • Availability — the system is available for operation and use as committed.
  • Processing Integrity — processing is complete, valid, accurate, timely and authorised.
  • Confidentiality — information designated as confidential is protected as committed.
  • Privacy — personal information is collected, used, retained and disposed of in line with commitments.

Security is the only mandatory criterion

Every SOC 2 report includes Security, which is why it is also called the Common Criteria. It is the baseline that all other criteria build on, and a report cannot omit it. When people say "the five principles of SOC 2", this is the one that is never optional.

The four optional criteria, and when you need them

The other four are selected based on the commitments your service actually makes, not added by default:

  • Add Availability if you promise uptime or run infrastructure customers depend on.
  • Add Processing Integrity if you process transactions or data where completeness and accuracy are the product (payments, analytics).
  • Add Confidentiality if customers entrust you with confidential business data under NDA-style commitments.
  • Add Privacy if you handle personal information and make privacy commitments to individuals.

Scoping in a criterion you do not need adds cost and audit surface for no benefit. Scoping one out that your customers care about weakens the report. The right set is the one that mirrors your commitments.

Type I vs Type II

The criteria define what is assessed; the report type defines how:

  • Type I assesses whether controls are suitably designed at a single point in time.
  • Type II assesses whether those controls operated effectively over a period — typically three to twelve months.

Type I answers "is the design right today?"; Type II answers "did it actually work over time?". Most enterprise buyers eventually want Type II, because operating effectiveness over a period is what gives the report its assurance value. The same point-in-time versus over-a-period distinction is explored in what a certification audit actually tests.

SOC 2 is an attestation, and not a certification

This distinction matters and is often stated wrongly. There is no "SOC 2 certificate" and no "SOC 2 certified" status. SOC 2 is an attestation engagement: a licensed CPA firm examines your controls against the selected criteria and issues a report with its opinion. You share the report, under NDA, with customers who ask for it — you do not display a certificate. Describing SOC 2 as a certification is a small error that a technical buyer notices immediately.

Which criteria should you scope?

Start with Security, then add only the criteria that match what you promise customers. That decision — plus choosing Type I or Type II and the observation period — is the scoping work that determines cost, timeline and how useful the report is in your sales cycle. Underneath a SOC 2 sits the same governance discipline as an ISMS: Qalea runs the security function the report attests to and maintains the evidence over the Type II period, so the report describes something that is actually running, not a snapshot assembled for the auditor.

Scope your SOC 2 around what you actually promise customers.

Frequently asked questions

No items found.

More articles

All articles