The Trust Services Criteria are the criteria your auditor tests against. Five categories. One (Security) is mandatory. Four (Availability, Processing Integrity, Confidentiality, Privacy) are optional. You pick which optional categories to add based on your customer contracts, your industry, and your business risk. This lesson walks all five and gives you the decision rule.
The five categories
| Category | Mandatory? | What it covers | When to add |
|---|---|---|---|
| Security (Common Criteria) | Yes, always | Nine Common Criteria CC1 through CC9 covering governance, risk, monitoring, control activities, access, operations, change management, vendor risk | Automatically included |
| Availability | No | Uptime commitments, capacity planning, disaster recovery, business continuity | When customers have SLAs with you, especially uptime commitments above 99.9 percent |
| Processing Integrity | No | Data validation, completeness, accuracy, authorisation, timeliness of processing | When you process transactions where wrong-processing has direct financial or regulatory consequence (payments, payroll, invoicing, tax) |
| Confidentiality | No | Data classification, encryption at rest and in transit, retention, deletion of confidential (non-personal) information | When customers share their trade secrets, source code, IP or commercially sensitive data with you |
| Privacy | No | Notice, choice and consent, collection, use, retention, access, disclosure of personal information | When you process personal information subject to GDPR, DPDP, CCPA, or similar. Not automatic just because you handle data. |
Security, the mandatory Common Criteria
Every SOC 2 examination covers Security. The nine Common Criteria are CC1 through CC9 [L4-C1]. CC1 through CC5 (Control Environment, Communication, Risk Assessment, Monitoring, Control Activities) map directly to the five COSO 2013 Internal Control components [L4-C2]. CC6 through CC9 (Logical and Physical Access, System Operations, Change Management, Risk Mitigation) are the technical operating layer that most SaaS engineers recognise as "the security stuff". Modules 2 and 3 of this course walk each of the nine in operational detail.
You cannot do a SOC 2 examination without Security. There is no configuration in which Availability alone or Privacy alone is a valid scope. Security is the anchor.
Availability, the SLA criterion
Add Availability if you commit to uptime SLAs above 99.9 percent, or if you are selling into customer categories that depend on your service being up (healthcare, payments, communications, developer tools that back their production).
The Availability TSC has three sub-criteria: A1.1 (capacity planning), A1.2 (environmental protections, backup, recovery infrastructure), A1.3 (recovery plan testing) [L4-C3]. Adding Availability typically increases the audit fee 10 to 20 percent and adds 5 to 10 controls to your inventory.
Freshworks adds Availability. Zoho adds Availability. If you are a SaaS with any material US enterprise footprint, add it in your second Type II if not your first.
Processing Integrity, the transaction criterion
Add Processing Integrity if wrong processing has direct financial or regulatory consequence. Payments (Razorpay, PhonePe), invoicing (Chargebee, Zoho), payroll (Rippling, Darwinbox), tax (ClearTax, Zoho Books), procurement.
The Processing Integrity TSC has five sub-criteria PI1.1 through PI1.5 covering inputs, processing, outputs, storage and completeness. Most pure marketing SaaS (email, CRM, marketing automation) skip Processing Integrity. Most fintech and back-office SaaS add it.
Confidentiality, the trade-secret criterion
Add Confidentiality if customers routinely share information with you that they would not want disclosed publicly and that is not personal information about individuals. Source code hosting (GitHub, GitLab). Contract lifecycle management (SirionLabs, Icertis). M&A data rooms. Enterprise design tools handling unreleased product designs (Figma).
The Confidentiality TSC has two sub-criteria C1.1 (identify and maintain confidential information) and C1.2 (dispose of confidential information). Adding Confidentiality typically increases the audit fee 5 to 15 percent and adds 3 to 8 controls.
Privacy, the personal-information criterion
Add Privacy if you process personal information subject to GDPR, DPDP Act 2023, CCPA, or similar. Not automatic. Privacy TSC is the heaviest optional criterion by far because it has eight sub-criteria P1 through P8 covering notice, choice, collection, use, retention, access, disclosure, and monitoring.
The pragmatic Indian SaaS calculus: if you are GDPR-exposed (any EU customers) or DPDP-exposed (any Indian customers), you have to run privacy operations anyway. Adding the Privacy TSC to your SOC 2 formalises the assurance. If you are pure B2B US-only, you may satisfy Privacy demand through a separate GDPR readiness statement or a DPDP-alignment memo and skip the Privacy TSC.
Most Indian SaaS start SOC 2 with Security only and add Privacy in the second or third annual audit as GDPR and DPDP pressure grows. Zoho, which is GDPR-exposed heavily, includes Privacy in its SOC 2 scope. Freshworks does the same.
The decision rule
Ask three questions when scoping your first SOC 2.
- What do your top five prospect customers demand? Look at their vendor security questionnaires. They will name the TSCs they expect. If three of five ask for Availability, add Availability.
- What is your industry norm? Look at your two nearest peer SaaS. If both include Confidentiality, you probably need to as well. Sales cycles will suffer if you do not match the peer bar.
- What is your appetite for scope creep in the first audit? Every additional TSC adds 5 to 15 percent to the audit fee and 3 to 10 additional controls to build and evidence. For first-time filers, staying at Security-only is often the right call, with a plan to add Availability plus Confidentiality (most common pair) in the second annual audit.
Most Indian SaaS SOC 2 Type II reports carry Security plus Availability plus Confidentiality by the second annual audit. Privacy gets added by the third year for GDPR-exposed and DPDP-exposed SaaS.
Next lesson: the operating timeline from month zero to first Type II report for an Indian SaaS post Series A.