Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Audit & Certification

Trust Services Criteria

Also known as: TSC, Trust Services Criteria for SOC 2, AICPA Trust Services Criteria, SOC 2 Trust Services Criteria
Simply put

The Trust Services Criteria are a set of control benchmarks used to evaluate an organization's systems in a SOC 2 examination. They are organized into five categories: security, availability, processing integrity, confidentiality, and privacy. An organization generally selects which of these categories apply to the services it wants assessed rather than always being evaluated against all five.

Formal definition

The Trust Services Criteria (TSC) are the control criteria against which service organizations are evaluated in a SOC 2 report. They comprise five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy, with each category containing underlying criteria that an auditor tests. The TSC form the evaluative basis of a SOC 2 attestation rather than a certification, and they represent a framework or professional standard applied under attestation engagements rather than a binding legal regulation; the Security category is generally treated as foundational, while the remaining categories are typically included based on scope selection. TSC apply only within the context of relevant assurance engagements and do not by themselves establish statutory obligations. The specific criteria, category structure, and applicable versions are periodically updated, so practitioners should verify scope and criteria against the current authoritative text before relying on this entry, and application to any particular engagement requires professional judgment.

Why it matters

The Trust Services Criteria matter because they define the substantive benchmarks that determine what a SOC 2 report actually says about an organization's controls. When a customer, partner, or procurement team asks a service provider for a SOC 2 report, the value of that report depends entirely on which TSC categories were in scope and how the underlying criteria were tested. A report scoped only to Security tells a different story than one that also covers Availability, Confidentiality, Processing Integrity, and Privacy. Understanding the TSC is therefore essential to reading, requesting, or preparing a SOC 2 report accurately rather than treating the report as an undifferentiated seal of approval.

Who it's relevant to

Compliance and GRC teams
Teams preparing an organization for a SOC 2 examination use the Trust Services Criteria to determine which categories to include in scope and to map internal controls to the applicable criteria. Understanding that Security is generally foundational and that the other four categories are selected based on the services being assessed helps them define an engagement scope that reflects what the organization actually needs to demonstrate.
Auditors and assurance practitioners
Practitioners conducting SOC 2 engagements apply the TSC as the control criteria against which they test and form an opinion. They should keep in mind that the resulting report is an attestation rather than a certification, and that the criteria, category structure, and applicable versions are periodically updated and should be verified against the current authoritative text.
Procurement, vendor risk, and security teams
Those evaluating third-party service providers rely on SOC 2 reports to assess control environments. Knowing that a provider selects which of the five TSC categories to include allows these teams to check whether the categories relevant to their concerns — for example, Availability, Confidentiality, or Privacy — were actually in scope, rather than assuming a report covers all five.
Legal counsel and contract managers
Counsel negotiating agreements that reference SOC 2 should recognize that the TSC form a framework applied under an attestation engagement and do not by themselves establish statutory obligations. Contract terms that require a SOC 2 report should specify the categories in scope, and counsel should not treat the attestation as equivalent to a legal compliance determination or a formal certification.

Inside TSC

Security (Common Criteria)
The foundational category addressing protection of information and systems against unauthorized access, disclosure, and damage. It is the only category required in every SOC 2 examination and is generally referred to as the Common Criteria that underpin the other categories.
Availability
Criteria addressing whether systems are available for operation and use as committed or agreed, typically in line with service-level commitments. This category is optional and generally included only when relevant to the services being examined.
Processing Integrity
Criteria addressing whether system processing is complete, valid, accurate, timely, and authorized. It focuses on whether a system achieves its purpose in delivering the right data at the right time, rather than on the quality of the data itself. This category is optional.
Confidentiality
Criteria addressing the protection of information designated as confidential according to commitments or agreements. It concerns how such information is collected, used, retained, disclosed, and disposed of. This category is optional and distinct from privacy.
Privacy
Criteria addressing the collection, use, retention, disclosure, and disposal of personal information in conformity with an organization's privacy notice and applicable criteria. This category is optional and applies specifically to personal information, unlike confidentiality, which covers a broader range of designated confidential data.
Relationship to SOC 2
The TSC are the control criteria against which an auditor evaluates a service organization's controls in a SOC 2 examination. They provide the benchmark for the examination but are not themselves a certification standard.

Common questions

Answers to the questions practitioners most commonly ask about TSC.

Are the Trust Services Criteria a legal regulation that organizations are required to comply with?
No. The Trust Services Criteria are not law and carry no independent legal force. They are the control criteria developed and maintained by the AICPA (American Institute of Certified Public Accountants) against which SOC 2 examinations are performed. An organization's use of the TSC is generally voluntary or driven by contractual and customer expectations rather than by statute. They may become effectively mandatory for a particular organization only where a contract, business relationship, or sector-specific requirement calls for a SOC 2 report. This entry is informational; whether the TSC apply in a given situation is a fact-specific matter requiring professional judgment.
Does meeting the Trust Services Criteria mean an organization is 'certified' as secure?
Not in the sense that certification usually implies. A SOC 2 examination results in an attestation report issued by a licensed CPA firm expressing an opinion on whether controls were suitably designed (Type 1) and, where applicable, operating effectively over a period (Type 2) against the selected criteria. It is not a pass/fail certification comparable to, for example, an ISO/IEC 27001 certificate issued by an accredited certification body. A report also does not guarantee that an organization is 'secure' in absolute terms; it reflects an auditor's opinion on specified criteria over a defined scope and timeframe, subject to the report's stated conditions and limitations.
Which of the Trust Services Criteria do we actually need to include in a SOC 2 examination?
In most cases the Security category (often described as the common criteria) is included as the baseline, and the other categories are selected based on relevance to the services provided and to stakeholder needs. Organizations generally choose additional categories where those aspects are material to the commitments they make to customers. Scoping decisions are fact-specific and typically made in consultation with the service auditor and relevant stakeholders. Confirm the current category structure and naming against the latest authoritative AICPA source, as criteria are periodically updated.
How do we define the boundaries of the system covered by a TSC-based examination?
System scope is generally described in terms of the infrastructure, software, people, procedures, and data that support the services in question, and it is documented in the system description that accompanies the report. Defining boundaries typically involves identifying the in-scope services, the supporting components, and any elements that are carried out by subservice organizations. How those subservice organizations are addressed can affect the report. Scope should be determined with the service auditor and verified against current professional guidance, as approaches may evolve.
What is the practical difference between preparing for a Type 1 and a Type 2 report against the criteria?
A Type 1 report generally addresses whether controls are suitably designed as of a point in time, while a Type 2 report addresses design and operating effectiveness over a period. In practice this means a Type 2 engagement typically requires evidence that controls functioned throughout the review period, not just that they existed on a single date. Organizations often begin with a Type 1 to establish a baseline before pursuing a Type 2, though the appropriate path depends on stakeholder expectations. Confirm current definitions and period conventions with your service auditor.
How should we handle the fact that the criteria are periodically updated?
Because the AICPA periodically revises the Trust Services Criteria, organizations should confirm which version applies to a given examination period and align their control mapping accordingly. Controls and documentation that satisfied an earlier version may need to be revisited when criteria change. It is generally advisable to track the effective version used in each report and to verify against the latest authoritative AICPA source rather than assuming continuity. Application to a specific examination is a matter for professional judgment in consultation with the service auditor.

Common misconceptions

The Trust Services Criteria are a regulation that organizations are legally required to comply with.
The TSC are a set of control criteria maintained by a professional standard-setting body and used in voluntary attestation examinations. They generally carry no legal force in themselves and become binding only where incorporated into a contract or agreement. Readers should verify the current criteria against the latest authoritative source.
A SOC 2 examination based on the TSC results in a certification.
A SOC 2 engagement is an attestation examination producing an auditor's report and opinion, not a certification. The distinction matters: an attestation reflects an independent practitioner's evaluation of controls against the criteria for a described scope and period, rather than a certificate issued under a certification scheme.
All five Trust Services Criteria categories must be included in every examination.
Only the Security category (the Common Criteria) is required in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are selected based on the services and commitments relevant to the organization.

Best practices

Determine which TSC categories are in scope based on the services delivered and the commitments made to customers, rather than defaulting to including all five.
Keep the distinction between an attestation report and a certification clear when communicating results to customers, auditors, and stakeholders.
Treat Security as the mandatory foundation and map controls to the Common Criteria before layering in any optional categories.
Distinguish Confidentiality from Privacy in scoping decisions, recognizing that Privacy applies specifically to personal information while Confidentiality covers a broader range of designated confidential data.
Verify the criteria against the current authoritative text before an engagement, since the TSC are periodically revised and version differences can affect scope and control mapping.
Engage qualified professional judgment to apply the criteria to specific circumstances, as scope, commitments, and relevant categories are fact-specific.
Promotional banner for the Penetration Report Template Kit