Live Founding Cohort open, limited seats remaining Back to main site →

The five Trust Services Criteria

Security is mandatory. Availability, Processing Integrity, Confidentiality, Privacy are optional. This lesson walks each of the five and gives you a decision rule for which optional TSCs to add.

Free preview 10 min read Verified
Legal basis
SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only). Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.

The Trust Services Criteria are the criteria your auditor tests against. Five categories. One (Security) is mandatory. Four (Availability, Processing Integrity, Confidentiality, Privacy) are optional. You pick which optional categories to add based on your customer contracts, your industry, and your business risk. This lesson walks all five and gives you the decision rule.

The five categories

CategoryMandatory?What it coversWhen to add
Security (Common Criteria)Yes, alwaysNine Common Criteria CC1 through CC9 covering governance, risk, monitoring, control activities, access, operations, change management, vendor riskAutomatically included
AvailabilityNoUptime commitments, capacity planning, disaster recovery, business continuityWhen customers have SLAs with you, especially uptime commitments above 99.9 percent
Processing IntegrityNoData validation, completeness, accuracy, authorisation, timeliness of processingWhen you process transactions where wrong-processing has direct financial or regulatory consequence (payments, payroll, invoicing, tax)
ConfidentialityNoData classification, encryption at rest and in transit, retention, deletion of confidential (non-personal) informationWhen customers share their trade secrets, source code, IP or commercially sensitive data with you
PrivacyNoNotice, choice and consent, collection, use, retention, access, disclosure of personal informationWhen you process personal information subject to GDPR, DPDP, CCPA, or similar. Not automatic just because you handle data.

Security, the mandatory Common Criteria

Every SOC 2 examination covers Security. The nine Common Criteria are CC1 through CC9 [L4-C1]. CC1 through CC5 (Control Environment, Communication, Risk Assessment, Monitoring, Control Activities) map directly to the five COSO 2013 Internal Control components [L4-C2]. CC6 through CC9 (Logical and Physical Access, System Operations, Change Management, Risk Mitigation) are the technical operating layer that most SaaS engineers recognise as "the security stuff". Modules 2 and 3 of this course walk each of the nine in operational detail.

You cannot do a SOC 2 examination without Security. There is no configuration in which Availability alone or Privacy alone is a valid scope. Security is the anchor.

Availability, the SLA criterion

Add Availability if you commit to uptime SLAs above 99.9 percent, or if you are selling into customer categories that depend on your service being up (healthcare, payments, communications, developer tools that back their production).

The Availability TSC has three sub-criteria: A1.1 (capacity planning), A1.2 (environmental protections, backup, recovery infrastructure), A1.3 (recovery plan testing) [L4-C3]. Adding Availability typically increases the audit fee 10 to 20 percent and adds 5 to 10 controls to your inventory.

Freshworks adds Availability. Zoho adds Availability. If you are a SaaS with any material US enterprise footprint, add it in your second Type II if not your first.

Processing Integrity, the transaction criterion

Add Processing Integrity if wrong processing has direct financial or regulatory consequence. Payments (Razorpay, PhonePe), invoicing (Chargebee, Zoho), payroll (Rippling, Darwinbox), tax (ClearTax, Zoho Books), procurement.

The Processing Integrity TSC has five sub-criteria PI1.1 through PI1.5 covering inputs, processing, outputs, storage and completeness. Most pure marketing SaaS (email, CRM, marketing automation) skip Processing Integrity. Most fintech and back-office SaaS add it.

Confidentiality, the trade-secret criterion

Add Confidentiality if customers routinely share information with you that they would not want disclosed publicly and that is not personal information about individuals. Source code hosting (GitHub, GitLab). Contract lifecycle management (SirionLabs, Icertis). M&A data rooms. Enterprise design tools handling unreleased product designs (Figma).

The Confidentiality TSC has two sub-criteria C1.1 (identify and maintain confidential information) and C1.2 (dispose of confidential information). Adding Confidentiality typically increases the audit fee 5 to 15 percent and adds 3 to 8 controls.

Privacy, the personal-information criterion

Add Privacy if you process personal information subject to GDPR, DPDP Act 2023, CCPA, or similar. Not automatic. Privacy TSC is the heaviest optional criterion by far because it has eight sub-criteria P1 through P8 covering notice, choice, collection, use, retention, access, disclosure, and monitoring.

The pragmatic Indian SaaS calculus: if you are GDPR-exposed (any EU customers) or DPDP-exposed (any Indian customers), you have to run privacy operations anyway. Adding the Privacy TSC to your SOC 2 formalises the assurance. If you are pure B2B US-only, you may satisfy Privacy demand through a separate GDPR readiness statement or a DPDP-alignment memo and skip the Privacy TSC.

Most Indian SaaS start SOC 2 with Security only and add Privacy in the second or third annual audit as GDPR and DPDP pressure grows. Zoho, which is GDPR-exposed heavily, includes Privacy in its SOC 2 scope. Freshworks does the same.

The decision rule

Ask three questions when scoping your first SOC 2.

  1. What do your top five prospect customers demand? Look at their vendor security questionnaires. They will name the TSCs they expect. If three of five ask for Availability, add Availability.
  2. What is your industry norm? Look at your two nearest peer SaaS. If both include Confidentiality, you probably need to as well. Sales cycles will suffer if you do not match the peer bar.
  3. What is your appetite for scope creep in the first audit? Every additional TSC adds 5 to 15 percent to the audit fee and 3 to 10 additional controls to build and evidence. For first-time filers, staying at Security-only is often the right call, with a plan to add Availability plus Confidentiality (most common pair) in the second annual audit.

Most Indian SaaS SOC 2 Type II reports carry Security plus Availability plus Confidentiality by the second annual audit. Privacy gets added by the third year for GDPR-exposed and DPDP-exposed SaaS.

Next lesson: the operating timeline from month zero to first Type II report for an Indian SaaS post Series A.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
AICPA Trust Services Criteria 2017 (2022 PoF), 2017 TSC with Revised Points of Focus (2022) (Current operative TSC document) L4-C1
2017 Trust Services Criteria with Revised Points of Focus (2022). Five categories: Security (Common Criteria mandatory), Availability, Processing Integrity, Confidentiality, Privacy. Common Criteria structure CC1 through CC9. 2022 refresh added Points of Focus without altering criteria. Key 2022 additions: system documentation must include network and data-flow diagrams plus hardware inventory; asset retrieval and immediate access restriction on employee or contractor termination including remote workforce; patch management process with identification, testing, approval, verification.
COSO Framework, COSO Internal Control Framework 2013 (COSO 2013 (underlies CC1 through CC5)) L4-C2
COSO Internal Control Integrated Framework 2013 published by the Committee of Sponsoring Organizations of the Treadway Commission. Five components (Control Environment, Risk Assessment, Control Activities, Information and Communication, Monitoring Activities) supported by 17 principles. Underlies the SOC 2 Common Criteria CC1 through CC5.
AICPA Trust Services Criteria 2017 (2022 PoF), Availability TSC (A-series) (Availability Trust Services Criterion) L4-C3
Availability Trust Services Criterion. Optional. Includes A1.1 (capacity and performance planning), A1.2 (environmental protections and backup / recovery infrastructure) and A1.3 (recovery plan testing).
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The story of SOC 2
Module 2: Common Criteria Part 1: CC1 to CC5, governance and risk
  • CC1 Control Environment: tone at the top, board oversight, org structure
  • CC2 Communication and Information: internal comms, external commitments, the Trust Portal
  • CC3 Risk Assessment: asset inventory, threat identification, likelihood, impact, residual risk
  • CC4 Monitoring Activities: continuous monitoring, deficiency reporting, remediation tracking
  • CC5 Control Activities: selection, technology-general controls, segregation of duties
Module 3: Common Criteria Part 2: CC6 to CC9, operations
  • CC6 Logical and Physical Access Controls: IAM, MFA, provisioning, remote access, keys
  • CC7 System Operations: detection tooling, incident response, backup and recovery
  • CC8 Change Management: dev lifecycle, code review, testing, approval, deployment, rollback
  • CC9 Risk Mitigation: vendor risk, third-party risk, business continuity, insurance
  • The 2022 Revised Points of Focus: what auditors now specifically look for
Module 4: The optional four Trust Services Criteria
  • Availability TSC — the uptime criterion
  • Processing Integrity TSC — the transaction criterion
  • Confidentiality TSC — the trade-secret criterion
  • Privacy TSC — and the GDPR / DPDP Act 2023 / CCPA overlap
  • TSC decision matrix — which to add and when, by industry
Module 5: The Control Framework and Policy Pack
  • The Control Matrix — mapping TSC clauses to controls, owners and evidence
  • The 10-Policy Pack — draft skeletons your auditor will ask to see
  • Risk Assessment Framework — asset, threat, likelihood, impact, residual risk
  • Vendor Risk Register — the working register your auditor tests against CC9.2
  • Incident Response Plan and Tabletop Runbook
Module 6: Evidence Collection Operating Model
  • Continuous vs point-in-time evidence, and how the auditor samples
  • Buy vs Build: Vanta, Drata, Sprinto, Secureframe, Comply.ai, or in-house
  • Evidence types: what makes evidence auditor-quality vs unusable
  • The Evidence Collection Calendar, a twelve-month template
  • Audit trail hygiene: organising the evidence pack for the first 48 hours of fieldwork
Module 7: Selecting the Auditor and the Audit Cycle
  • What makes a SOC 2 auditor: licensing, independence, sector experience
  • The Auditor RFP and Selection Matrix: running Big 4 against mid-tier against boutique
  • The SOC 2 Engagement Letter, full SSAE 18 template
  • The audit cycle week by week, kickoff to report issuance
  • Auditor opinion types: unqualified, qualified, adverse, disclaimer
Module 8: Post-Audit and Continuous Compliance
  • Publishing the SOC 2 report on your customer trust portal
  • Answering vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report
  • The annual re-audit cycle and the bridge letter
  • Adding TSCs beyond Security: Availability, then Confidentiality, then Privacy
  • SOC 2 to ISO 27001 upgrade path and emerging AI controls