Skip to content
compliancebase

Trust Services Criteria

The AICPA criteria (security, availability, processing integrity, confidentiality, privacy) used as the basis for SOC 2 examinations under TSP Section 100.

In practice

A SOC 2 report scopes in Security — the mandatory Common Criteria, CC1 through CC9 — and, optionally, Availability, Processing Integrity, Confidentiality, or Privacy, based on what the service organization's customers actually need attested. Most SaaS companies start with Security only and add Availability or Confidentiality later as enterprise customers request it in due-diligence questionnaires.

Common confusion

People sometimes use "SOC 2 compliant" and "meets the Trust Services Criteria" interchangeably with "passed an exam," but SOC 2 is an attestation of controls against the TSC, not a pass/fail certification. The auditor's opinion addresses whether controls were suitably designed (Type I) or operated effectively over a period (Type II) — not whether the company is "compliant" in the abstract.

Related controls

Framework versions referenced in this page:

Last verified: July 2026 · Primary sources linked above