Skip to main content
Category: Trust Services Criteria

Additional Criteria

Also known as: Supplemental Criteria, Additional Trust Services Criteria
Simply put

Additional Criteria are extra evaluation standards that can be added to a SOC 2 examination beyond the baseline required Security category, depending on what the service organization chooses to include in scope. They let an examination address other areas of concern, such as availability or confidentiality, when they are relevant to the services being assessed. Which additional criteria apply is a scoping decision rather than a fixed universal set.

Formal definition

In the context of a SOC 2 examination performed under the AICPA SSAE 18 attestation standard, 'Additional Criteria' generally refers to evaluation criteria applied beyond the required Security category (the Common Criteria). Depending on scope, an engagement may incorporate one or more of the optional Trust Services Criteria categories, Availability, Processing Integrity, Confidentiality, and Privacy, each of which contributes its own criteria in addition to the Common Criteria. The selection of additional criteria is determined by scoping decisions based on the nature of the services, applicable commitments, and relevant risks, and is set in agreement between the service organization and the CPA firm performing the examination. Because a criterion is a standard against which a judgment or decision is made, the resulting report attests only to the controls addressing the selected criteria over the covered period or point in time; criteria not in scope are not evaluated. This concept is specific to the SOC 2 Trust Services Criteria and should not be conflated with ISO/IEC 27001 Annex A reference controls, which are selected through a Statement of Applicability under a separate certification regime.

Why it matters

Additional Criteria matter because they determine the actual breadth of assurance a SOC 2 report provides. Since Security (the Common Criteria) is the only required category, an examination that addresses only Security says nothing about how a service organization manages availability, processing integrity, confidentiality, or privacy. When a customer or prospect reviews a SOC 2 report, understanding which additional criteria were in scope is essential to knowing what was, and was not, evaluated. A report can be entirely clean yet remain silent on areas that a reader mistakenly assumed were covered.

For service organizations, selecting the right additional criteria aligns the examination with the commitments they make to customers. An organization that markets high uptime, for example, may add the Availability category so that its report speaks directly to that promise, while one handling sensitive data may add Confidentiality or Privacy. Because these are scoping decisions rather than a fixed universal set, they should reflect the nature of the services, applicable commitments, and relevant risks agreed between the organization and its CPA firm.

It is important to remember that a SOC 2 report attests only to the controls addressing the criteria in scope over the covered period or point in time. Criteria not selected are simply not evaluated, and the report does not guarantee freedom from breaches or address any area outside its defined scope. Misreading which additional criteria were included is a common source of misplaced reliance during vendor due diligence.

Who it's relevant to

Compliance and GRC Managers
They decide, in coordination with leadership and the CPA firm, which additional criteria to bring into scope so the examination reflects the organization's actual customer commitments and risk profile. Choosing too narrowly may leave customer questions unanswered; choosing too broadly may add effort in areas not material to the services.
Auditors and CPA Firms
The examining firm agrees the scope with the service organization and applies the selected criteria under the SSAE 18 attestation standard. They are responsible for evaluating controls against only the criteria in scope and for clearly reflecting that scope in the report.
Vendor Risk and Procurement Teams
When relying on a vendor's SOC 2 report, these teams must confirm which additional criteria were included before drawing conclusions. A report covering only Security does not speak to availability, confidentiality, privacy, or processing integrity, so understanding the scope prevents misplaced reliance.
Service Organization Leadership
Executives use the selection of additional criteria to signal which commitments their SOC 2 report substantiates to prospects and customers, aligning the assurance offered with the promises made in contracts and marketing.

Inside Additional Criteria

Supplemental Criteria Beyond the Common Criteria
Additional Criteria refers to the trust services criteria layered on top of the Security category (the Common Criteria) when the scope of a SOC 2 examination includes one or more of the optional categories: Availability, Processing Integrity, Confidentiality, or Privacy. Security is the only required category, so these additional criteria are selected based on scoping decisions.
Availability Criteria
Additional criteria addressing whether systems are available for operation and use as committed or agreed. Typically included when service commitments relate to uptime or system accessibility, depending on scope.
Processing Integrity Criteria
Additional criteria addressing whether system processing is complete, valid, accurate, timely, and authorized. Often relevant where the service performs transaction or data processing on behalf of user entities.
Confidentiality Criteria
Additional criteria addressing the protection of information designated as confidential, from collection through disposal. Selected when confidentiality commitments extend beyond the baseline security controls.
Privacy Criteria
Additional criteria addressing the collection, use, retention, disclosure, and disposal of personal information in conformity with the service organization's privacy commitments. Included when personal information handling is within scope.
Scope-Driven Selection
The additional criteria included in a given SOC 2 examination are determined by scoping decisions based on the service organization's commitments and system, rather than being mandated uniformly across all engagements.

Common questions

Answers to the questions practitioners most commonly ask about Additional Criteria.

Are the Additional Criteria (Availability, Processing Integrity, Confidentiality, and Privacy) required for a SOC 2 examination?
No. Within the Trust Services Criteria, only the Security category (the Common Criteria) is required in a SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional categories, often described as the additional criteria, and are selected based on the scope of the engagement rather than mandated. Depending on scope, an organization may include one, several, or none of them beyond Security.
Are the Additional Criteria the same as ISO 27001 Annex A controls?
No. The Trust Services Criteria, including the additional criteria beyond Security, belong to the AICPA framework used in a SOC 2 attestation examination and should not be conflated with ISO 27001's Annex A reference controls. ISO 27001's certifiable requirements sit in clauses 4 through 10, while Annex A lists reference controls selected through a Statement of Applicability. Mapping between the two frameworks is possible but partial, and meeting one does not automatically satisfy the other.
How does an organization decide which Additional Criteria to include in its SOC 2 scope?
Selection is typically a scoping decision informed by the commitments the organization makes to customers, the nature of the services provided, and the assurances stakeholders are seeking. For example, an organization that makes uptime commitments may include Availability, while one handling sensitive personal information may consider Confidentiality or Privacy. In most engagements this is determined in consultation with the CPA firm performing the examination rather than by a fixed rule.
Can Additional Criteria be added to both SOC 2 Type I and Type II examinations?
In most engagements, additional criteria can be incorporated into either report type, but the nature of the assessment differs. A Type I examination assesses the suitability of design of the relevant controls at a point in time, whereas a Type II examination assesses both design and operating effectiveness over a defined review period. The period length for a Type II varies and is set by scoping decisions.
Does including more Additional Criteria strengthen a SOC 2 report?
Adding criteria expands the scope of what the examination covers, but broader scope is not inherently better; the appropriate categories depend on the organization's commitments and the assurances its stakeholders need. A SOC 2 report attests only to the controls and criteria included and the period covered, so including criteria that are not relevant to the services provided may add effort without providing meaningful assurance to report users.
What are the limitations of the Additional Criteria within a SOC 2 report?
A SOC 2 report attests only to the controls and criteria within its defined scope and, for a Type II, over the specified review period. Including additional criteria does not guarantee freedom from breaches or extend assurance beyond the boundaries described in the report. It also does not equate to an ISO 27001 certification, which covers only the defined scope of the ISMS and is issued through a different framework and process.

Common misconceptions

All five Trust Services Criteria categories are required in every SOC 2 report.
Only the Security category (the Common Criteria) is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on the scope of the engagement, so the additional criteria present in one report may differ from those in another.
The additional Trust Services Criteria correspond directly to ISO 27001 Annex A controls.
The Trust Services Criteria and ISO 27001 Annex A controls are distinct constructs from different frameworks. Mapping between them is possible but only partial, and including additional criteria in a SOC 2 examination does not equate to satisfying any ISO 27001 requirement.
Including additional criteria means the SOC 2 report guarantees that area is fully secure or free from incidents.
A SOC 2 report attests only to the controls and the period covered by the examination. Even when additional criteria such as Availability or Confidentiality are in scope, the report does not guarantee freedom from breaches or outages outside the described controls and period.

Best practices

Begin by confirming that Security (the Common Criteria) is in scope, then select additional criteria based on the service organization's actual commitments to user entities rather than defaulting to all categories.
Map each selected additional category (Availability, Processing Integrity, Confidentiality, or Privacy) back to specific service commitments and system boundaries so the scope is defensible during the examination.
Coordinate scoping decisions with the licensed CPA firm performing the SSAE 18 examination early, since the chosen additional criteria shape the controls tested and the evidence required.
Document clearly which additional criteria are included and excluded, and communicate to report users that the report attests only to the controls and period covered.
Avoid asserting equivalence between selected additional criteria and ISO 27001 outcomes; treat any cross-framework mapping as partial and validate coverage separately for each framework.
For a Type II examination, ensure controls supporting the additional criteria are operating over the entire defined review period, whose length is set by scoping decisions rather than a fixed duration.