The Five Trust Services Criteria, Explained
Security, availability, confidentiality, processing integrity, and privacy, what each covers and how to choose your SOC 2 scope.
8 min read
Every SOC 2 report is built on the Trust Services Criteria, a set of control objectives the AICPA maintains. There are five. You choose which ones apply to your service, and each one you include is a set of controls the auditor will test. Security is always required; the other four are optional.
Security (Required)
Security, sometimes called the Common Criteria, is the foundation, and it is the only criterion every SOC 2 report must include. It covers protecting systems and data against unauthorized access, both physical and logical: access controls, authentication, network security, change management, and how you detect and respond to incidents. If you scope a report to Security alone, you still have a complete, useful SOC 2.
Availability
Availability asks whether the system is up and reachable as you have committed. It is the right addition when customers depend on your uptime, for example if you sell an SLA. Controls here cover monitoring, capacity planning, backups, and disaster recovery. It does not set a specific uptime target; it checks that you manage availability against your own commitments.
Confidentiality
Confidentiality covers information you have agreed to restrict, such as data marked confidential in a contract. It overlaps with Security but is narrower and promise-based: it is about honoring confidentiality commitments through encryption, access limits, and controlled disposal. Include it when you handle customer data that carries specific confidentiality terms.
Processing Integrity
Processing integrity asks whether your system processes data completely, accurately, and on time. It matters most for services where the output is the product, think billing, payroll, or analytics, where a wrong number is a real harm. Many SaaS companies leave this one out, because their systems store and move data rather than transform it.
Privacy
Privacy covers how you collect, use, retain, and dispose of personal information, measured against your own privacy notice. It is distinct from the other four because it is about personal data specifically, and it overlaps with privacy laws like GDPR and CCPA/CPRA. Include it when personal data is central to what you do.
How to Choose Your Scope
Most first reports scope to Security alone, then add criteria as customers ask for them. Adding a criterion is not free: it means more controls to maintain and more evidence to produce, so add one because a buyer needs it or because it genuinely reflects your service, not to look thorough. The right scope is the smallest one that answers your customers' real questions.
How Concord Fits
Concord Trust's control library is organized so the controls behind each criterion sit together, which makes scoping a matter of adopting the right set rather than inventing controls from scratch. When you adopt a framework, your controls map onto the criteria you chose, so you can see coverage per criterion before an auditor ever looks.