Availability Criteria (A1)
Availability is one of the optional categories a company can choose to include in a SOC 2 examination, focusing on whether systems and services are up and reachable as agreed. It looks at things like whether the organization plans for enough capacity, monitors its systems, and can recover after a disruption. It is selected based on the scope of the engagement and is not part of the required Security category.
The Availability category (A1) is one of the four optional Trust Services Criteria categories in a SOC 2 examination, selected in addition to the mandatory Security (Common Criteria) category based on scoping decisions. In the evidence provided, the Availability category comprises criteria including A1.1 (the entity maintains, monitors, and evaluates current processing capacity and use of system components such as infrastructure, data, and software) and A1.3 (addressing the system's ability to recover under disruption). During a SOC 2 Type II engagement, an auditor evaluates both the design and operating effectiveness of controls mapped to these criteria over a defined review period; in a Type I engagement, only suitability of design at a point in time is assessed. Availability addresses whether systems are accessible and operational as committed, but does not itself assess processing accuracy, confidentiality, or privacy, which are covered by separate optional categories. A SOC 2 report scoped to include Availability attests only to the controls and period examined and does not guarantee uninterrupted uptime or freedom from outages.
Why it matters
Availability speaks directly to the commitments an organization makes to its customers about uptime and access. When a service becomes unreachable, the business impact is felt immediately by users who depend on it, which is why many customers and prospects specifically ask whether a vendor's SOC 2 examination includes the Availability category. Selecting Availability signals that the organization has been examined not only on how it secures its systems but also on whether it plans for capacity, monitors its environment, and can recover after a disruption.
Because Availability is an optional category, its inclusion is a scoping decision rather than an automatic feature of every SOC 2 report. This matters when interpreting a report: a SOC 2 that covers only the required Security (Common Criteria) category does not attest to availability-related controls at all. Readers should confirm which categories were in scope before drawing conclusions about a service's resilience.
It is equally important to understand the limits of what an Availability-scoped report conveys. A SOC 2 report attests only to the controls and the period examined; it does not guarantee uninterrupted uptime or freedom from future outages. In a Type II engagement it reflects how controls operated over the defined review period, and in a Type I engagement only the suitability of design at a point in time. Availability also does not address processing accuracy, confidentiality, or privacy, each of which falls under a separate optional category.
Who it's relevant to
Inside A1
Common questions
Answers to the questions practitioners most commonly ask about A1.