The Trust Services Criteria (TSC) Explained: Choosing Your Scope

The trust services
Written By

CISOSHARE

Post Date

10
Minute Read


You've decided to pursue SOC 2 compliance. You've talked to auditors, read the requirements, and started mapping your security programs. Then someone mentions "Trust Services Criteria" and asks which ones you're including in scope.

Wait, there are options?

If you're staring at the five Trust Services Criteria wondering which boxes to check, you're not alone. This is one of the most misunderstood aspects of SOC 2 readiness. The good news? Choosing your scope doesn't have to be complicated when you understand what each criterion actually covers and how it maps to your business commitments.

What Are the Trust Services Criteria?

The Trust Services Criteria (TSC) are the foundation of SOC 2 audits. Developed by the AICPA, they provide a standardized framework for evaluating the effectiveness of your internal controls over information and systems.

Think of the TSC as the measuring stick your auditor uses to assess whether your program security actually protects the data and services you've promised to safeguard.

The framework consists of five categories:

  • Security – Protection against unauthorized access
  • Availability – System uptime and operational readiness
  • Processing Integrity – Accurate, complete, and timely processing
  • Confidentiality – Protection of designated confidential information
  • Privacy – Collection, use, retention, and disclosure of personal information

Here's what most organizations don't realize at first: only Security is mandatory. The other four are optional and should be selected based on your specific service commitments and customer expectations.

Five colored folders representing the Trust Services Criteria for SOC 2 compliance

Breaking Down the Five Criteria

Security: The Non-Negotiable Foundation

Every SOC 2 report includes the Security criterion because it addresses fundamental questions every customer asks: Is my data protected? Can unauthorized users access your systems?

Security covers nine common criteria (CC1 through CC9) that span your entire control environment:

  • Control environment and governance
  • Communication and information systems
  • Risk assessment and monitoring
  • Logical and physical access controls
  • System operations and change management
  • Risk mitigation strategies

This criterion evaluates whether you have appropriate safeguards to protect against vulnerabilities, unauthorized access, and security incidents. Your security programs: from access management to incident response: all fall under this umbrella.

If you're only pursuing one criterion (and many organizations start here), Security is your baseline.

Availability: Keeping the Lights On

The Availability criterion answers one question: Can users access your systems when they need them?

This becomes relevant when you've made specific uptime commitments to customers. If your SLA promises 99.9% availability, your auditor will examine the controls that support that promise:

  • System monitoring and performance management
  • Backup and disaster recovery procedures
  • Incident management and escalation
  • Capacity planning and resource allocation

Software-as-a-service providers, cloud platforms, and any organization selling "always-on" services typically include Availability in their scope.

Processing Integrity: Getting the Job Done Right

Processing Integrity verifies that your systems process data completely, accurately, and in a timely manner: and only for authorized purposes.

This criterion matters when the quality and accuracy of your processing directly impacts your customers. Think about:

  • Payment processors handling financial transactions
  • Healthcare platforms managing patient records
  • Data analytics services producing reports
  • Payroll systems calculating compensation

If your service commitments include guarantees about data accuracy, completeness, or timeliness, Processing Integrity demonstrates you have controls to back those promises.

Five interconnected pillars representing SOC 2 Trust Services Criteria security framework

Confidentiality: Beyond Basic Security

While Security protects against unauthorized access in general, Confidentiality specifically addresses information designated as confidential by agreement or by nature.

This criterion becomes important when you're handling:

  • Proprietary business information
  • Trade secrets or intellectual property
  • Competitive data
  • Information explicitly labeled "confidential" in contracts

The key difference? Security is about protecting all information and systems. Confidentiality focuses on controls for specifically classified confidential data, including how it's accessed, stored, transmitted, and eventually disposed of.

Privacy: Personal Information Protection

Privacy addresses the lifecycle of personal information: how you collect it, use it, retain it, disclose it, and dispose of it.

With data privacy regulations multiplying globally (GDPR, CCPA, and beyond), many organizations include Privacy to demonstrate compliance with privacy frameworks. This criterion evaluates:

  • Notice and disclosure practices
  • Consent and choice mechanisms
  • Data collection and use limitations
  • Access and correction procedures
  • Disclosure to third parties
  • Security safeguards for personal information
  • Data quality and retention policies

If you're processing personal data: especially sensitive categories like health information or financial data: Privacy shows you're managing it responsibly according to regulatory and contractual requirements.

How to Choose Your SOC 2 Scope

Selecting the right criteria isn't about checking every box. It's about aligning your audit scope with your actual service commitments and customer expectations.

Step 1: Review Your Service Commitments

Start with the promises you've already made. Pull out your:

  • Service Level Agreements (SLAs)
  • Master Service Agreements (MSAs)
  • Terms of Service
  • Data Processing Agreements (DPAs)
  • Customer questionnaires and security requirements

Look for specific commitments about uptime, data accuracy, confidentiality, or privacy protections. These documents tell you which criteria matter most to your stakeholders.

Step 2: Map Your System Boundaries

Define what's in scope for your audit. This includes:

  • Applications and software systems
  • Infrastructure (cloud, on-premise, hybrid)
  • Data storage and transmission pathways
  • People and organizational structure
  • Policies, procedures, and documentation

Understanding your system boundaries helps you identify which controls are relevant and which criteria those controls support.

Business workspace showing SOC 2 scope selection checklist and audit criteria planning

Step 3: Assess Your Current Controls

Conduct an honest evaluation of the controls you've already implemented. Where are your security programs mature? Where do gaps exist?

If you've built robust availability monitoring but have minimal privacy processes, that signals where you're ready to be audited versus where you need development work.

Step 4: Consider Customer Expectations

Talk to your sales team. What criteria do prospects consistently ask about? What's showing up in customer security questionnaires?

In B2B SaaS environments, Security and Availability are almost universal expectations. Privacy is increasingly common. Processing Integrity and Confidentiality are more specialized based on your service type.

Step 5: Plan for Growth

Your first SOC 2 report doesn't need to include everything. Many organizations start with Security only, then add criteria in subsequent audits as their program security matures and customer demands evolve.

Starting smaller allows you to nail the fundamentals before expanding scope. You can always add criteria in your next audit cycle.

Common Scope Combinations

Based on industry patterns, here are typical scope selections:

Security Only: Appropriate for early-stage companies, organizations new to SOC 2, or services where other criteria don't apply to service commitments.

Security + Availability: The most common combination for SaaS platforms, cloud services, and any organization with uptime guarantees.

Security + Availability + Confidentiality: Common in B2B services handling proprietary client data, financial services, or professional services firms.

Security + Privacy: Increasingly popular for healthcare platforms, HR/payroll systems, and any service processing significant personal information under privacy regulations.

All Five Criteria: Reserved for comprehensive services where all aspects apply: think enterprise platforms handling sensitive data with strict uptime and processing requirements.

The Risks of Getting Scope Wrong

Over-Scoping: Including criteria that don't align with your actual service commitments creates unnecessary audit complexity and cost. You'll spend time building controls and gathering evidence for areas that don't provide meaningful assurance to your customers.

Under-Scoping: Excluding relevant criteria leaves gaps in your report that customers notice. If your SLA promises 99.95% uptime but your report only covers Security, expect questions about why Availability wasn't included.

The right scope gives customers confidence that your audit actually addresses the commitments you've made to them.

Interlocking pieces illustrating SOC 2 criteria alignment with business commitments

What This Means for Your Security Programs

Your Trust Services Criteria selection directly shapes how you build and document your program security:

  • More criteria = broader control coverage: Each additional criterion requires specific policies, procedures, and evidence.
  • Control overlap is your friend: Many controls support multiple criteria. Strong access management serves both Security and Confidentiality. Backup procedures support both Availability and Processing Integrity.
  • Documentation requirements multiply: Each criterion needs supporting evidence. Plan your evidence collection strategy accordingly.

The most successful organizations align their security program development with their intended scope from day one, rather than trying to retrofit controls later.

Making the Decision

When you're ready to finalize your scope, ask yourself three questions:

  1. What have we contractually promised to protect or provide?
  2. What controls do we already have in place to support those promises?
  3. What will our customers expect to see in our report?

If you can answer all three confidently for a given criterion, it belongs in your scope. If you're uncertain, that's a signal you need either more control development or clarification on your service commitments.

Next Steps

Choosing your Trust Services Criteria is a strategic decision that sets the foundation for your entire SOC 2 journey. Start with your service commitments, be honest about your current program security maturity, and select criteria that demonstrate you're protecting what matters most to your customers.

Need help evaluating which criteria align with your specific situation? CISOSHARE's security assessment services include SOC 2 readiness evaluations that map your current controls to the Trust Services Criteria and identify gaps before you engage with an auditor.

Remember: your first SOC 2 report doesn't need to include everything. Choose the scope that accurately reflects your commitments today, execute it well, and expand in future audits as your security programs mature.

The right scope isn't the longest one: it's the one that gives your customers confidence you're actually protecting what you promised to protect.


Latest Insights