📋 SOC 2📘 Phase 1 · Basics🎯 Scoping

Understanding SOC 2 Trust Service Criteria — A Plain-English Guide

Five categories, one of them mandatory, and a lot of jargon hiding a simple idea: these are the promises a SOC 2 report tests.

GK
Gauri Khatate
🔐 Cybersecurity Expert & Technical Writer·📖 5 min read
📅 June 2026·🏢 SecComply
SOC 2 Trust Service Criteria security availability processing integrity confidentiality privacy scope

The criteria are the specific promises an organisation makes about how it handles a customer’s data — and a SOC 2 is an auditor checking whether those promises are real.

The Trust Service Criteria are the spine of every SOC 2 report, and they’re also where most beginners’ eyes glaze over — a wall of categories, common criteria, and “points of focus” that reads like it was written to be skimmed. Underneath the jargon is something straightforward: the criteria are the specific promises an organisation makes about how it handles a customer’s data, and SOC 2 is the exercise of an auditor checking whether those promises are real. Knowing the five — and which ones a company has chosen to be measured against — is most of the game.

5 categories
Security, Availability, Processing Integrity, Confidentiality, Privacy
1 mandatory
Security — the “Common Criteria” — is always in scope
4 optional
The rest are included only if relevant to the service
You choose
The criteria you select define the report’s scope and its promises

Five Promises, One Always Required

The Trust Service Criteria break into five categories, and the most important fact about them is that they are not all mandatory. Security — known as the Common Criteria — is always in scope; there is no SOC 2 without it. The other four — Availability, Processing Integrity, Confidentiality, and Privacy — are optional, included only when they reflect something the service actually promises its customers. Each one a company adds is a set of additional commitments it’s asking an auditor to test. The criteria, in other words, are chosen, and the choice is part of the report’s meaning.

Security: The One Everyone Includes

Security, the Common Criteria, is the foundation the other four build on. In plain terms it’s the promise that the system is protected against unauthorised access — both logical (accounts, permissions, networks) and physical (data centres, devices). It spans the control environment, risk assessment, access controls, change management, monitoring, and incident response. Every SOC 2 report includes it, because without it the others mean little: there’s no point promising a system is available or accurate if anyone can walk into it.

CriterionThe promise, plainlyWhen it belongs in scope
Security (required)“We protect your data from unauthorised access”Always — it’s the foundation
Availability“The system will be up when you need it”Uptime and SLAs matter to customers
Processing Integrity“We process data completely and accurately”You transform, calculate on, or move data
Confidentiality“We keep confidential information confidential”You handle sensitive business data
Privacy“We handle personal data as our notice says”You collect personal information from people

Don’t Include Criteria You Don’t Need

More criteria is not better — it’s more to evidence and more for an auditor to test against, and every added category is another place an exception can surface. Including Availability when uptime isn’t part of the promise, or Privacy when the service barely touches personal data, just inflates the audit without telling a buyer anything they needed to know. The discipline is to scope to what the service genuinely commits to: pick the promises the company actually makes and can keep, and leave the rest out rather than collecting criteria like trophies.

THE PRIVACY-CRITERION MISCONCEPTION

The single most common mistake with the criteria is assuming the SOC 2 “Privacy” category is the same thing as privacy law — that a report including Privacy means a company is GDPR-compliant. It doesn’t. The SOC 2 Privacy criterion is built on the American accounting profession’s privacy principles: notice, choice, collection, use, retention, and disclosure as the company describes them. It tests whether the company handles personal data the way its own privacy notice claims — not whether that handling satisfies the enforceable individual rights, lawful-basis requirements, or transfer rules that European law imposes. A company can earn a clean SOC 2 that includes Privacy and still be exposed under GDPR, because the two are answering different questions. Treating the Privacy criterion as a privacy-law shield is exactly the kind of scope confusion that surfaces, expensively, later.

The Common Criteria, Plainly

Inside the Security category sits a structured set of common criteria that auditors work through, and they’re less intimidating once translated. They cover the control environment and tone from the top; how the company communicates information and responsibilities; how it assesses risk; how it monitors whether controls are working; the control activities themselves; logical and physical access; system operations; change management; and how it mitigates risks from vendors and disruptions. It reads as a long list, but it’s really one idea expressed in layers: know your risks, put controls in place, restrict access, watch that it’s all working, and manage change without breaking it.

Misreads the TSC vs Understands Them

Pattern-matching from real scoping conversations — the gap between misreading the criteria and understanding them tends to follow the same shape:

Misreads the criteriaUnderstands the criteria
✗ Thinks all five always apply✓ Knows Security is required, four are optional
✗ Adds every criterion “to be safe”✓ Scopes to what the service actually promises
✗ Assumes “Privacy” means GDPR✓ Knows it’s the AICPA privacy principles, not law
✗ Treats criteria as abstract checkboxes✓ Reads each as a concrete promise to customers
✗ Ignores which criteria a vendor chose✓ Checks the scope before trusting the report
✗ Collects criteria like trophies✓ Picks the promises the company can keep

Pick the Promises You Can Keep

The strategic takeaway is almost the opposite of the instinct. The goal isn’t the widest possible scope; it’s the honest one. A SOC 2 covering Security and the one or two criteria that genuinely match the service — cleanly, with few exceptions — tells a buyer far more than a sprawling report that includes everything and is riddled with the controls the company couldn’t actually sustain. Choose the criteria that map to real commitments, and the report becomes a true description of the company rather than an aspirational one. The same scoping discipline carries into the Type I versus Type II decision, where over-reach costs even more.

Final Thought

The Trust Service Criteria look like a jargon problem and are really a clarity tool: five promises, one mandatory, the rest chosen to match what a service actually commits to. Understood that way, the criteria stop being a wall to skim past and start being the most honest summary of what a SOC 2 report does — and the choice of which to include becomes a statement, to every buyer who reads it, about what the company is genuinely prepared to be held to.

The test: for the company’s own service, name which of the five criteria genuinely reflect a promise it makes — and which it would be including only to look thorough. If the honest list and the planned scope don’t match, the report is being scoped for appearances rather than truth.

Are the Chosen Criteria the Promises the Company Actually Keeps?

SecComply scopes SOC 2 to the criteria that genuinely match a service — Security as the foundation, plus only the optional categories that reflect real commitments — so the report is honest, lean, and free of exceptions you couldn’t sustain. You walk away with a scope that tells buyers the truth, not a trophy cabinet of criteria you can’t back up.

Frequently Asked Questions

What are the five SOC 2 Trust Service Criteria?

Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security — the Common Criteria — is mandatory and always in scope. The other four are optional and are included only when they reflect a promise the service actually makes to its customers.

Which Trust Service Criteria are mandatory?

Only Security, known as the Common Criteria. There is no SOC 2 without it, because it is the foundation the others build on. Availability, Processing Integrity, Confidentiality, and Privacy are all optional and chosen to match what the service genuinely commits to.

Does a SOC 2 report that includes Privacy mean a company is GDPR compliant?

No. The SOC 2 Privacy criterion is built on the AICPA’s privacy principles and tests whether a company handles personal data the way its own privacy notice claims. It does not test the enforceable individual rights, lawful-basis requirements, or transfer rules that GDPR imposes. A company can earn a clean SOC 2 including Privacy and still be exposed under GDPR.

Should I include more Trust Service Criteria to look thorough?

No. More criteria is not better — it is more to evidence and more for an auditor to test, and every added category is another place an exception can surface. The discipline is to scope to the promises the service genuinely makes and can keep, and leave the rest out rather than collecting criteria like trophies.