← Back to Knowledge Base

Understanding Trust Services Criteria (TSC): A Practical Guide to SOC 2 Compliance

SOC 2 Compliance

The Trust Services Criteria (TSC) form the foundation of SOC 2 reporting. They provide five different lenses through which auditors evaluate an organization’s controls. This article explains the five TSC categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. It outlines what each category covers, when it is needed, and common key controls. The article emphasizes that Security is mandatory for every SOC 2 engagement, while the other four categories are optional and should be selected based on business requirements, customer expectations, and contractual obligations. A practical reality check is also provided: most SaaS companies only need Security, may add Availability if they have SLA commitments, and can generally skip Privacy unless it is explicitly required.

Introduction

SOC 2 is built on five Trust Services Criteria. These criteria are not merely a checklist; they are five distinct perspectives that auditors use to examine whether a company’s security program is designed and operating effectively. Understanding each category helps organizations scope their SOC 2 report appropriately, avoid unnecessary audit work, and focus on the controls that matter most to their customers and business model.

1. Security (Required — Everyone Needs This)

Security is the only mandatory TSC category. Every SOC 2 report must include it.

What it covers:

  • Access controls, including who can access what

  • Logical and physical security

  • System operations, such as monitoring and incident response

  • Change management

  • Risk mitigation

Common Criteria (CC): CC1.1 through CC9.2 — 64 total criteria under Security.

In plain English: “Do you have basic security controls in place? Can you prove unauthorized people cannot access customer data?”

Key controls often include:

  • Multi-factor authentication (MFA) on all systems

  • Role-based access control (RBAC)

  • Annual background checks

  • Security awareness training

  • Vulnerability scanning

  • Incident response plan

  • Change management process

  • Encryption at rest and in transit

Security is the baseline. Without it, a SOC 2 report cannot be issued.

2. Availability (Optional)

Availability focuses on whether systems are accessible and performing as expected.

What it covers:

  • System uptime and performance

  • Disaster recovery

  • Business continuity

  • Capacity planning

When you need it:

  • You have SLA commitments, such as 99.9% uptime

  • Customers care about availability

  • You run mission-critical systems

Key controls often include:

  • High availability architecture, such as multi-AZ and load balancing

  • Automated backups and tested recovery

  • Disaster recovery plan with defined RTO and RPO

  • Performance monitoring and alerting

  • Capacity planning process

Availability is optional, but it becomes important when uptime is a contractual promise or a core customer concern.

3. Processing Integrity (Optional)

Processing Integrity addresses whether data is processed accurately, completely, on time, and only when authorized.

What it covers:

  • Data processing accuracy

  • Completeness of processing

  • Timeliness

  • Authorization

When you need it:

  • Financial data processing

  • Billing or invoicing systems

  • Data transformation pipelines

Key controls often include:

  • Input validation and error handling

  • Reconciliation processes

  • Data integrity checks

  • Audit trails for all transactions

This category is most relevant to systems where incorrect or incomplete processing could create material harm or compliance risk.

4. Confidentiality (Optional)

Confidentiality focuses on protecting information that is not necessarily personal but is sensitive or proprietary.

What it covers:

  • Protection of confidential information

  • Encryption

  • Data classification

  • NDA compliance

When you need it:

  • Handling proprietary customer data

  • IP protection requirements

  • Contractual confidentiality obligations

Key controls often include:

  • Data classification scheme

  • Encryption for confidential data

  • NDA tracking and enforcement

  • Secure data disposal procedures

Confidentiality is often confused with Privacy, but they are distinct. Confidentiality applies to a broader set of sensitive business information, while Privacy focuses on personal information.

5. Privacy (Optional — Rarely Needed for SaaS)

Privacy addresses the handling of personal information, often in a manner similar to GDPR requirements.

What it covers:

  • Personal information handling

  • Consent management

  • Data subject rights

  • Privacy notices

When you need it:

  • You explicitly sell “privacy compliance”

  • You process heavy amounts of consumer data

  • You have GDPR or CCPA compliance needs

Key controls often include:

  • Privacy notices and consent mechanisms

  • Data subject request procedures

  • Data retention and deletion policies

  • Privacy impact assessments

For most SaaS companies, Privacy is not necessary unless it is specifically demanded by customers, regulators, or the nature of the data being processed.

Choosing the Right TSC

The five categories can be thought of as a menu. Security is always required. The other four are optional and should be selected based on:

  • Customer requirements

  • Contractual obligations

  • Industry regulations

  • Business model

  • Data types processed

A narrower scope can reduce audit complexity and cost while still meeting customer needs.

Reality Check

Most SaaS companies only need Security, which is mandatory. Add Availability if you have SLA commitments. Skip Privacy unless it is explicitly required. Processing Integrity and Confidentiality should be added only when the business processes or data types justify them.

Conclusion

The Trust Services Criteria provide a flexible framework for SOC 2 compliance. Security is the non-negotiable foundation. Availability, Processing Integrity, Confidentiality, and Privacy are optional and should be chosen deliberately. By understanding what each category covers, when it is needed, and which controls support it, organizations can build a SOC 2 program that is both credible and appropriately scoped.