Additional Criteria
Additional Criteria are extra evaluation standards that can be added to a SOC 2 examination beyond the baseline required Security category, depending on what the service organization chooses to include in scope. They let an examination address other areas of concern, such as availability or confidentiality, when they are relevant to the services being assessed. Which additional criteria apply is a scoping decision rather than a fixed universal set.
In the context of a SOC 2 examination performed under the AICPA SSAE 18 attestation standard, 'Additional Criteria' generally refers to evaluation criteria applied beyond the required Security category (the Common Criteria). Depending on scope, an engagement may incorporate one or more of the optional Trust Services Criteria categories, Availability, Processing Integrity, Confidentiality, and Privacy, each of which contributes its own criteria in addition to the Common Criteria. The selection of additional criteria is determined by scoping decisions based on the nature of the services, applicable commitments, and relevant risks, and is set in agreement between the service organization and the CPA firm performing the examination. Because a criterion is a standard against which a judgment or decision is made, the resulting report attests only to the controls addressing the selected criteria over the covered period or point in time; criteria not in scope are not evaluated. This concept is specific to the SOC 2 Trust Services Criteria and should not be conflated with ISO/IEC 27001 Annex A reference controls, which are selected through a Statement of Applicability under a separate certification regime.
Why it matters
Additional Criteria matter because they determine the actual breadth of assurance a SOC 2 report provides. Since Security (the Common Criteria) is the only required category, an examination that addresses only Security says nothing about how a service organization manages availability, processing integrity, confidentiality, or privacy. When a customer or prospect reviews a SOC 2 report, understanding which additional criteria were in scope is essential to knowing what was, and was not, evaluated. A report can be entirely clean yet remain silent on areas that a reader mistakenly assumed were covered.
For service organizations, selecting the right additional criteria aligns the examination with the commitments they make to customers. An organization that markets high uptime, for example, may add the Availability category so that its report speaks directly to that promise, while one handling sensitive data may add Confidentiality or Privacy. Because these are scoping decisions rather than a fixed universal set, they should reflect the nature of the services, applicable commitments, and relevant risks agreed between the organization and its CPA firm.
It is important to remember that a SOC 2 report attests only to the controls addressing the criteria in scope over the covered period or point in time. Criteria not selected are simply not evaluated, and the report does not guarantee freedom from breaches or address any area outside its defined scope. Misreading which additional criteria were included is a common source of misplaced reliance during vendor due diligence.
Who it's relevant to
Inside Additional Criteria
Common questions
Answers to the questions practitioners most commonly ask about Additional Criteria.