Trust Services Criteria
The AICPA criteria (security, availability, processing integrity, confidentiality, privacy) used as the basis for SOC 2 examinations under TSP Section 100.
In practice
A SOC 2 report scopes in Security — the mandatory Common Criteria, CC1 through CC9 — and, optionally, Availability, Processing Integrity, Confidentiality, or Privacy, based on what the service organization's customers actually need attested. Most SaaS companies start with Security only and add Availability or Confidentiality later as enterprise customers request it in due-diligence questionnaires.
Common confusion
People sometimes use "SOC 2 compliant" and "meets the Trust Services Criteria" interchangeably with "passed an exam," but SOC 2 is an attestation of controls against the TSC, not a pass/fail certification. The auditor's opinion addresses whether controls were suitably designed (Type I) or operated effectively over a period (Type II) — not whether the company is "compliant" in the abstract.