The 5 SOC 2 Trust Services Criteria Explained in Plain English

Quick Answer

SOC 2 has five trust services criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only mandatory one. The other four are added only when a specific customer, contract, or regulatory requirement calls for them.

The SOC 2 trust services criteria are the five categories an auditor can test during a SOC 2 report: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Every SOC 2 report must include Security. The other four are optional and are only added when a customer contract, regulator, or your own data handling model requires them.

In our work auditing Australian SaaS and cloud businesses, most companies start out assuming they need all five criteria because vendor security questionnaires list them together. In practice, the majority of first-time SOC 2 reports we scope only include Security, with additional criteria added later once a specific customer or regulatory requirement makes it necessary. The rest of this guide breaks down what each criterion actually covers, who needs it, and how the choice affects your cost and timeline.

The official definitions come from the AICPA Trust Services Criteria framework, which every SOC 2 audit is measured against.

The 5 Criteria at a Glance

REQUIRED

Security

Protects systems against unauthorised access. Mandatory in every SOC 2 report.

Availability

Confirms your systems meet agreed uptime and performance commitments.

Processing Integrity

Confirms data processing is complete, accurate, timely, and authorised.

Confidentiality

Protects information designated as confidential, such as contracts or business data.

Privacy

Governs how personal information is collected, used, retained, and disclosed.

SOC 2 Trust Services Criteria Comparison Table

Use this table to see what each criterion actually tests, who typically needs it, and the type of evidence an auditor will ask for. In our audit engagements, the Confidentiality column comes up more often than people expect, particularly for professional services and B2B software firms handling client contracts and business data, while the Privacy criterion is usually reserved for organisations processing consumer personal information directly, such as healthcare or HR platforms.

Criterion What It Covers Who Typically Needs It Example Evidence
Security Protection against unauthorised access, breaches, and system abuse. Every SOC 2 report. This criterion is mandatory. Access control logs, MFA enforcement records, firewall configurations.
Availability System uptime, performance monitoring, and disaster recovery readiness. SaaS platforms and infrastructure providers with uptime commitments in customer contracts. SLA agreements, incident response logs, backup and failover test records.
Processing Integrity Completeness, accuracy, timeliness, and authorisation of data processing. Payment processors, e-commerce platforms, and businesses running data pipelines. Transaction logs, quality control checks, error handling documentation.
Confidentiality Protection of confidential business information, not necessarily personal data. Firms handling client contracts, trade secrets, or intellectual property under NDA. Non-disclosure agreements, encryption records, access restriction policies.
Privacy Collection, use, retention, and disclosure of personal information. Organisations processing consumer personal information directly, such as healthcare or HR platforms. Privacy policies, consent records, data retention schedules.

Why Most Companies Start With Security Only

Security is the only mandatory criterion in a SOC 2 report. Every other criterion is optional, and adding one that your customers do not actually require adds audit time, evidence collection, and cost without adding commercial value. This is the honest starting point most vendors and consultants skip, because a report that covers all five criteria looks more thorough, even when it is not what the customer asked for.

Across the SOC 2 engagements we scope for Australian SaaS and cloud businesses, the deciding factor is almost always the customer security questionnaire or contract clause that triggered the request. When we review that document with a client, it becomes clear which criteria are actually being asked for. In most first-time cases, that is Security alone.

Signs You Need More Than Security

Add Availability if

Your contract includes an uptime or SLA commitment your customer wants independently verified.

Add Processing Integrity if

Your platform processes transactions, payments, or data pipelines where accuracy is a customer concern.

Add Confidentiality if

You hold client contracts, trade secrets, or business data under a non-disclosure agreement.

Add Privacy if

You collect or process consumer personal information directly, such as in healthcare or HR platforms.

Not sure which criteria your customers actually require? Our team reviews your security questionnaires and contracts to confirm the right scope before your audit begins. Scope your criteria with CyberSapiens before committing to a full five-criteria audit.

How Your Criteria Choice Affects Cost and Timeline

Each additional trust services criterion beyond Security adds its own set of controls, evidence requests, and auditor testing hours. In the engagements we run for Australian businesses, the jump from a Security-only report to a two or three criteria report typically adds four to eight weeks to the readiness phase, mainly because of the extra evidence collection and control documentation involved rather than the audit itself.

Scope Typical Readiness Time Relative Cost Impact Main Cost Driver
Security only Baseline timeline for a first-time report. Lowest of the available options. Access control and monitoring evidence only.
Security plus one criterion Adds roughly four to eight weeks to readiness. Moderate increase over baseline. Additional control implementation and evidence for the added criterion.
Security plus two or more criteria Longest readiness phase, especially for a first report. Highest of the available options. Overlapping but distinct evidence sets across multiple criteria.

Customer security questionnaires are one of the most common triggers for scoping decisions, and standardised assessment frameworks such as the Cloud Security Alliance STAR programme can help you cross-reference what your customers are actually asking for before you commit to additional criteria. If you want a clear breakdown of Type 1 versus Type 2 costs on top of criteria selection, our SOC 2 costs and timelines guide covers this in detail.

Frequently Asked Questions

What are the SOC 2 trust services criteria?

The SOC 2 trust services criteria are the five categories a SOC 2 report can be assessed against: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory in every report, while the other four are added only when they are relevant to your business and your customers.

Do I need all 5 SOC 2 trust services criteria?

No. Most first-time SOC 2 reports include Security only, since this is the sole mandatory criterion. The remaining four are optional and should only be added when a customer contract, regulatory requirement, or your data handling model specifically calls for them.

Which SOC 2 criterion is mandatory?

Security is the only mandatory criterion in a SOC 2 report. It covers protection against unauthorised access and is included in every SOC 2 Type 1 or Type 2 report regardless of scope.

How do I choose which SOC 2 criteria to include?

Start by reviewing the customer security questionnaires or contract clauses that triggered your need for SOC 2. These documents usually specify exactly which criteria your customers expect, which prevents you from paying for scope you do not need.

Does adding more SOC 2 criteria increase the cost?

Yes. Each additional criterion adds its own controls and evidence requirements, which increases both readiness time and audit cost. This applies to both SOC 2 Type 1 and Type 2 reports, though the increase is larger for Type 2 given its longer observation period. See our SOC 2 Type 1 vs Type 2 guide for a full cost comparison.

Ketki Tidke, ISO 27001 Lead Auditor CyberSapiens

Content Reviewed By

Ketki Tidke

Cyber Security and GRC Lead Auditor

ISO 27001 Lead Auditor

ISO 27001 Lead Auditor GRC Specialist CPS 234 Essential Eight

Ketki is a certified ISO 27001 Lead Auditor specialised in Governance, Risk and Compliance, with experience consulting public, private, and government clients. She evaluates threats, risk impacts, and regulatory requirements across multiple industry frameworks.

ISO 27001 SOC 2 PCI DSS NIST CSF Essential Eight VPDSS CPS 234 ISM
Book a Call with Ketki LinkedIn ISO 27001 Certified

Not Sure Which SOC 2 Criteria You Actually Need?

CyberSapiens reviews your customer security questionnaires and contracts to confirm the right scope before your audit begins, so you are not paying for criteria your customers never asked for.

Get Certified
1300 507 668
Lvl 1, 206 Lorimer St, Port Melbourne, Australia