Trust Services Criteria
The Trust Services Criteria are a set of control benchmarks used to evaluate an organization's systems in a SOC 2 examination. They are organized into five categories: security, availability, processing integrity, confidentiality, and privacy. An organization generally selects which of these categories apply to the services it wants assessed rather than always being evaluated against all five.
The Trust Services Criteria (TSC) are the control criteria against which service organizations are evaluated in a SOC 2 report. They comprise five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy, with each category containing underlying criteria that an auditor tests. The TSC form the evaluative basis of a SOC 2 attestation rather than a certification, and they represent a framework or professional standard applied under attestation engagements rather than a binding legal regulation; the Security category is generally treated as foundational, while the remaining categories are typically included based on scope selection. TSC apply only within the context of relevant assurance engagements and do not by themselves establish statutory obligations. The specific criteria, category structure, and applicable versions are periodically updated, so practitioners should verify scope and criteria against the current authoritative text before relying on this entry, and application to any particular engagement requires professional judgment.
Why it matters
The Trust Services Criteria matter because they define the substantive benchmarks that determine what a SOC 2 report actually says about an organization's controls. When a customer, partner, or procurement team asks a service provider for a SOC 2 report, the value of that report depends entirely on which TSC categories were in scope and how the underlying criteria were tested. A report scoped only to Security tells a different story than one that also covers Availability, Confidentiality, Processing Integrity, and Privacy. Understanding the TSC is therefore essential to reading, requesting, or preparing a SOC 2 report accurately rather than treating the report as an undifferentiated seal of approval.
Who it's relevant to
Inside TSC
Common questions
Answers to the questions practitioners most commonly ask about TSC.
