The Trust Services Criteria (TSC) form the foundation of SOC 2 reporting. They provide five different lenses through which auditors evaluate an organization’s controls. This article explains the five TSC categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. It outlines what each category covers, when it is needed, and common key controls. The article emphasizes that Security is mandatory for every SOC 2 engagement, while the other four categories are optional and should be selected based on business requirements, customer expectations, and contractual obligations. A practical reality check is also provided: most SaaS companies only need Security, may add Availability if they have SLA commitments, and can generally skip Privacy unless it is explicitly required.
Introduction
SOC 2 is built on five Trust Services Criteria. These criteria are not merely a checklist; they are five distinct perspectives that auditors use to examine whether a company’s security program is designed and operating effectively. Understanding each category helps organizations scope their SOC 2 report appropriately, avoid unnecessary audit work, and focus on the controls that matter most to their customers and business model.
1. Security (Required — Everyone Needs This)
Security is the only mandatory TSC category. Every SOC 2 report must include it.
What it covers:
Access controls, including who can access what
Logical and physical security
System operations, such as monitoring and incident response
Change management
Risk mitigation
Common Criteria (CC): CC1.1 through CC9.2 — 64 total criteria under Security.
In plain English: “Do you have basic security controls in place? Can you prove unauthorized people cannot access customer data?”
Key controls often include:
Multi-factor authentication (MFA) on all systems
Role-based access control (RBAC)
Annual background checks
Security awareness training
Vulnerability scanning
Incident response plan
Change management process
Encryption at rest and in transit
Security is the baseline. Without it, a SOC 2 report cannot be issued.
2. Availability (Optional)
Availability focuses on whether systems are accessible and performing as expected.
What it covers:
System uptime and performance
Disaster recovery
Business continuity
Capacity planning
When you need it:
You have SLA commitments, such as 99.9% uptime
Customers care about availability
You run mission-critical systems
Key controls often include:
High availability architecture, such as multi-AZ and load balancing
Automated backups and tested recovery
Disaster recovery plan with defined RTO and RPO
Performance monitoring and alerting
Capacity planning process
Availability is optional, but it becomes important when uptime is a contractual promise or a core customer concern.
3. Processing Integrity (Optional)
Processing Integrity addresses whether data is processed accurately, completely, on time, and only when authorized.
What it covers:
Data processing accuracy
Completeness of processing
Timeliness
Authorization
When you need it:
Financial data processing
Billing or invoicing systems
Data transformation pipelines
Key controls often include:
Input validation and error handling
Reconciliation processes
Data integrity checks
Audit trails for all transactions
This category is most relevant to systems where incorrect or incomplete processing could create material harm or compliance risk.
4. Confidentiality (Optional)
Confidentiality focuses on protecting information that is not necessarily personal but is sensitive or proprietary.
What it covers:
Protection of confidential information
Encryption
Data classification
NDA compliance
When you need it:
Handling proprietary customer data
IP protection requirements
Contractual confidentiality obligations
Key controls often include:
Data classification scheme
Encryption for confidential data
NDA tracking and enforcement
Secure data disposal procedures
Confidentiality is often confused with Privacy, but they are distinct. Confidentiality applies to a broader set of sensitive business information, while Privacy focuses on personal information.
5. Privacy (Optional — Rarely Needed for SaaS)
Privacy addresses the handling of personal information, often in a manner similar to GDPR requirements.
What it covers:
Personal information handling
Consent management
Data subject rights
Privacy notices
When you need it:
You explicitly sell “privacy compliance”
You process heavy amounts of consumer data
You have GDPR or CCPA compliance needs
Key controls often include:
Privacy notices and consent mechanisms
Data subject request procedures
Data retention and deletion policies
Privacy impact assessments
For most SaaS companies, Privacy is not necessary unless it is specifically demanded by customers, regulators, or the nature of the data being processed.
Choosing the Right TSC
The five categories can be thought of as a menu. Security is always required. The other four are optional and should be selected based on:
Customer requirements
Contractual obligations
Industry regulations
Business model
Data types processed
A narrower scope can reduce audit complexity and cost while still meeting customer needs.
Reality Check
Most SaaS companies only need Security, which is mandatory. Add Availability if you have SLA commitments. Skip Privacy unless it is explicitly required. Processing Integrity and Confidentiality should be added only when the business processes or data types justify them.
Conclusion
The Trust Services Criteria provide a flexible framework for SOC 2 compliance. Security is the non-negotiable foundation. Availability, Processing Integrity, Confidentiality, and Privacy are optional and should be chosen deliberately. By understanding what each category covers, when it is needed, and which controls support it, organizations can build a SOC 2 program that is both credible and appropriately scoped.