Blogs

The 5 SOC 2 Trust Services Criteria in Plain English

Every SOC 2 report is built around five Trust Services Criteria, defined in the AICPA Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory for every SOC 2 report, full stop. The other four are optional, and you only include the ones relevant to what your customers actually need from you, not all five by default.

Here is what each one actually means in plain English, a table showing who needs which, and honest guidance on why most companies starting out only need one of the five. If you are ready to talk specifics, our SOC 2 compliance services start with exactly this kind of scoping conversation.

The 5 Trust Services Criteria at a Glance

What each criterion covers, who actually needs it, and the kind of evidence auditors look for.

Criterion What it covers, plainly Who actually needs it Evidence examples
Security
Mandatory
Protecting your systems from unauthorised access, internal and external Every single company pursuing SOC 2, there is no version of a report without this MFA enforcement, access review logs, firewall configuration, incident response records, penetration test reports
Availability Whether your systems stay up and running as promised Companies whose customers care about uptime commitments, typically anyone with an SLA, or infrastructure and platform providers Uptime monitoring reports, disaster recovery test records, incident logs, capacity planning documentation
Processing Integrity Whether data is processed completely, accurately, and on time Companies handling transactions, calculations, or workflows where an error has real consequences, fintech, payment processors, logistics platforms Data validation logs, error-handling records, reconciliation reports
Confidentiality Protecting sensitive business information that is not personal data, trade secrets, business plans, proprietary data Companies handling client business data under NDA, or B2B platforms storing customer-proprietary information Encryption records, access permission logs, confidentiality agreements with staff
Privacy Protecting personal data specifically, in line with laws like the Australian Privacy Principles, GDPR, or CCPA Companies collecting or processing personal data directly from individuals, consumer apps, healthtech, edtech, e-commerce Consent records, data retention policy, breach notification procedures, data subject request handling

Why Most Companies Start Security-Only

Here is the honest part most guides skip: adding all 5 criteria to your first SOC 2 report is not a sign of thoroughness, it is usually unnecessary cost and scope you do not need yet. Every additional criterion means more controls to design, more evidence to collect, and more for your auditor to test, which adds time and money without necessarily adding anything your customers are asking for.

Most companies pursuing their first SOC 2 report start with Security only, because it is the one every customer expects and it is mandatory regardless. The other four get added later, specifically when a customer contract or RFP requires it, not preemptively. A healthtech company handling patient data will likely need Privacy from day one. A B2B SaaS platform without transaction processing probably does not need Processing Integrity at all, ever.

The practical approach: look at what your actual customers and prospects are asking for in security questionnaires and contracts right now, and scope your first report to that. Add criteria later as your customer base and their requirements grow, rather than guessing upfront.

How Your Criteria Choice Changes Cost and Timeline

More criteria in scope means more controls to design, document, and evidence, which directly affects both how long your first audit takes to prepare for and what it costs. A Security-only report is generally the fastest and least expensive path to a first SOC 2 report. Each additional criterion adds roughly 15 to 30 percent to audit fees on its own, not a rounding error, a genuinely separate body of evidence your auditor needs to test, which is why our guide to SOC 2 cost in Australia breaks this down by company size rather than giving a single number.

This is also where the Type 1 versus Type 2 decision interacts with your criteria choice. A Type 1 report, a design snapshot at a single point in time, with more criteria in scope is still generally faster to prepare for than a Type 2 report, which tests operating effectiveness over a 3 to 12 month window, with fewer criteria. The observation period is the bigger time driver in a Type 2 engagement. If you are still deciding between the two, our breakdown of SOC 2 Type 1 vs Type 2 covers how that decision plays out alongside criteria scope.

FAQs

Is Security the only mandatory Trust Services Criterion?

Yes. Every SOC 2 report, Type 1 or Type 2, must include Security. The other four, Availability, Processing Integrity, Confidentiality, Privacy, are optional and selected based on what is relevant to your business and what your customers require.

Can I add more criteria to a later SOC 2 report after starting with Security only?

Yes, this is common and expected. Many companies start with a Security-only report and expand scope in a later audit cycle as customer requirements grow.

How do I know which criteria my customers actually need?

Look at the security questionnaires, RFPs, and contract clauses your prospects and existing customers are sending you. The specific language they use, uptime guarantees, data processing accuracy, personal data handling, usually points directly to which criteria matter for your business.

Does having more criteria in my SOC 2 report make it more impressive to customers?

Not particularly. Customers generally care whether the criteria relevant to their use case are covered, not the total number included. A well-scoped Security-only report that matches what a customer actually needs is more useful than a report padded with criteria nobody asked for.

Is Privacy the same as complying with a specific privacy law like GDPR or the Australian Privacy Act?

No. The Privacy criterion is a SOC 2-specific set of controls around how personal data is handled, and while it overlaps with principles found in privacy laws, having Privacy in your SOC 2 scope does not automatically mean you are compliant with a specific regulation. They are related but separate obligations.

Ketki Tidke, ISO 27001 Lead Auditor CyberSapiens

Content Reviewed By

Ketki Tidke

Cyber Security and GRC Lead Auditor

ISO 27001 Lead Auditor

ISO 27001 Lead Auditor GRC Specialist CPS 234 Essential Eight

Ketki is a certified ISO 27001 Lead Auditor specialised in Governance, Risk and Compliance, with experience consulting public, private, and government clients. She evaluates threats, risk impacts, and regulatory requirements across multiple industry frameworks.

ISO 27001 SOC 2 PCI DSS NIST CSF Essential Eight VPDSS CPS 234 ISM

Scope your criteria

Tell us what your customers are actually asking for, and we will help you scope a SOC 2 report that covers it, nothing more, nothing less. Our SOC 2 compliance services start with this exact conversation.

Scope Your Criteria

Call Us

1300 507 668

Our Office

Lvl 1, 206 Lorimer St, Port Melbourne, Australia