FRAMEWORKS & CERTIFICATIONS
What Is Trust Services Criteria?
DEFINITION
Trust Services Criteria are the AICPA's evaluation criteria used in SOC 2 examinations, organized into five categories: security, availability, processing integrity, confidentiality, and privacy. Security, known as the common criteria, is mandatory in every SOC 2 report, while the other four categories are added based on the commitments a company makes to customers. The current version is the 2017 criteria with revised points of focus issued in 2023.
The Trust Services Criteria (TSC) define what a SOC 2 auditor evaluates. The security category, built on the COSO internal control framework and expressed as the common criteria (CC series), covers areas such as control environment, risk assessment, access controls, change management, and monitoring. Each criterion is accompanied by points of focus, which are illustrative guidance rather than requirements. The AICPA revised those points of focus in September 2023 but left the underlying 2017 criteria unchanged, and no new criteria have been issued for 2026.
Auditors apply the TSC directly, but buyers encounter them too: the categories listed on a SOC 2 report tell a customer exactly what was examined, which is why security questionnaires often ask which categories a report covers.
For a mid-market company, category selection is the main scoping decision, since each added category expands the control set, evidence burden, and audit cost. Most first-time reports cover security alone or security plus availability. Z Cyber's SOC 2 readiness solution includes guidance on which categories match actual customer commitments.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →