Skip to content
compliancebase

Which Trust Services Criteria do I need?

Interactive tool that recommends which SOC 2 Trust Services Categories to include based on what you sell and who buys.

What this tool does

Teams over-scope SOC 2 with Availability, Confidentiality, Processing Integrity, or Privacy without a buyer need — adding months of evidence — or under-scope and fail questionnaires that expect a category they skipped.

Who it's for

Teams scoping a first or next SOC 2 report who need a neutral recommendation on Security plus optional Trust Services Categories.

Try it

Answers stay in your browser only — nothing is uploaded or used for lead capture.

Non-goals

No lead capture, no guarantee that a buyer will accept the recommended scope, and no replacement for scoping with your service auditor.

Educational guidance only — category selection is a management decision with your auditor. Not legal advice. Based on the AICPA Trust Services Criteria (Security and optional categories).

Related pages

Frameworks

Controls