Guide

The Five Trust Services Criteria, Explained

Security, availability, confidentiality, processing integrity, and privacy, what each covers and how to choose your SOC 2 scope.

8 min read

Every SOC 2 report is built on the Trust Services Criteria, a set of control objectives the AICPA maintains. There are five. You choose which ones apply to your service, and each one you include is a set of controls the auditor will test. Security is always required; the other four are optional.

Security (Required)

Security, sometimes called the Common Criteria, is the foundation, and it is the only criterion every SOC 2 report must include. It covers protecting systems and data against unauthorized access, both physical and logical: access controls, authentication, network security, change management, and how you detect and respond to incidents. If you scope a report to Security alone, you still have a complete, useful SOC 2.

Availability

Availability asks whether the system is up and reachable as you have committed. It is the right addition when customers depend on your uptime, for example if you sell an SLA. Controls here cover monitoring, capacity planning, backups, and disaster recovery. It does not set a specific uptime target; it checks that you manage availability against your own commitments.

Confidentiality

Confidentiality covers information you have agreed to restrict, such as data marked confidential in a contract. It overlaps with Security but is narrower and promise-based: it is about honoring confidentiality commitments through encryption, access limits, and controlled disposal. Include it when you handle customer data that carries specific confidentiality terms.

Processing Integrity

Processing integrity asks whether your system processes data completely, accurately, and on time. It matters most for services where the output is the product, think billing, payroll, or analytics, where a wrong number is a real harm. Many SaaS companies leave this one out, because their systems store and move data rather than transform it.

Privacy

Privacy covers how you collect, use, retain, and dispose of personal information, measured against your own privacy notice. It is distinct from the other four because it is about personal data specifically, and it overlaps with privacy laws like GDPR and CCPA/CPRA. Include it when personal data is central to what you do.

How to Choose Your Scope

Most first reports scope to Security alone, then add criteria as customers ask for them. Adding a criterion is not free: it means more controls to maintain and more evidence to produce, so add one because a buyer needs it or because it genuinely reflects your service, not to look thorough. The right scope is the smallest one that answers your customers' real questions.

How Concord Fits

Concord Trust's control library is organized so the controls behind each criterion sit together, which makes scoping a matter of adopting the right set rather than inventing controls from scratch. When you adopt a framework, your controls map onto the criteria you chose, so you can see coverage per criterion before an auditor ever looks.

Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.