Skip to main content
Category: Trust Services Criteria

Availability Criteria (A1)

Also known as: A1, Availability Trust Services Category, Availability Category, Availability TSC
Simply put

Availability is one of the optional categories a company can choose to include in a SOC 2 examination, focusing on whether systems and services are up and reachable as agreed. It looks at things like whether the organization plans for enough capacity, monitors its systems, and can recover after a disruption. It is selected based on the scope of the engagement and is not part of the required Security category.

Formal definition

The Availability category (A1) is one of the four optional Trust Services Criteria categories in a SOC 2 examination, selected in addition to the mandatory Security (Common Criteria) category based on scoping decisions. In the evidence provided, the Availability category comprises criteria including A1.1 (the entity maintains, monitors, and evaluates current processing capacity and use of system components such as infrastructure, data, and software) and A1.3 (addressing the system's ability to recover under disruption). During a SOC 2 Type II engagement, an auditor evaluates both the design and operating effectiveness of controls mapped to these criteria over a defined review period; in a Type I engagement, only suitability of design at a point in time is assessed. Availability addresses whether systems are accessible and operational as committed, but does not itself assess processing accuracy, confidentiality, or privacy, which are covered by separate optional categories. A SOC 2 report scoped to include Availability attests only to the controls and period examined and does not guarantee uninterrupted uptime or freedom from outages.

Why it matters

Availability speaks directly to the commitments an organization makes to its customers about uptime and access. When a service becomes unreachable, the business impact is felt immediately by users who depend on it, which is why many customers and prospects specifically ask whether a vendor's SOC 2 examination includes the Availability category. Selecting Availability signals that the organization has been examined not only on how it secures its systems but also on whether it plans for capacity, monitors its environment, and can recover after a disruption.

Because Availability is an optional category, its inclusion is a scoping decision rather than an automatic feature of every SOC 2 report. This matters when interpreting a report: a SOC 2 that covers only the required Security (Common Criteria) category does not attest to availability-related controls at all. Readers should confirm which categories were in scope before drawing conclusions about a service's resilience.

It is equally important to understand the limits of what an Availability-scoped report conveys. A SOC 2 report attests only to the controls and the period examined; it does not guarantee uninterrupted uptime or freedom from future outages. In a Type II engagement it reflects how controls operated over the defined review period, and in a Type I engagement only the suitability of design at a point in time. Availability also does not address processing accuracy, confidentiality, or privacy, each of which falls under a separate optional category.

Who it's relevant to

Compliance and GRC Managers
Those coordinating a SOC 2 examination decide whether to include Availability in scope, which typically depends on the uptime commitments made to customers. They need to understand that adding the category expands the controls the auditor will assess, including capacity management and recovery, and that these controls are examined only for the categories and period defined in the engagement.
Security and Infrastructure Engineers
Engineers responsible for system capacity, monitoring, and recovery own much of the evidence tied to A1.1 and A1.3. In most engagements they are asked to demonstrate that current processing capacity and system component use are maintained, monitored, and evaluated, and that the system can recover under disruption.
Auditors Performing SOC 2 Examinations
Practitioners evaluate the design and, in a Type II engagement, the operating effectiveness of controls mapped to the Availability criteria over the defined review period. They must keep the scope clear, since Availability addresses whether systems are accessible and operational as committed but not processing accuracy, confidentiality, or privacy, which are separate optional categories.
Customers and Vendor Risk Reviewers
Those reading a SOC 2 report to assess a vendor should confirm whether Availability was among the categories in scope before relying on it for resilience assurance. A report that includes Availability attests only to the controls and period examined and does not guarantee uninterrupted uptime or freedom from outages.

Inside A1

Optional Trust Services Category
Availability is one of the four optional Trust Services Criteria categories that may be added to a SOC 2 examination scope, alongside Processing Integrity, Confidentiality, and Privacy. It is selected based on scoping decisions and is not required; only the Security category (Common Criteria) is mandatory in every SOC 2 engagement.
Availability Series Criteria (A1)
The A1 series comprises the criteria specific to availability, which supplement the Common Criteria when the availability category is in scope. These criteria address whether systems are available for operation and use as committed or agreed, rather than assessing the functionality or usability of the system itself.
Capacity and Resource Management
Availability criteria typically address the identification, monitoring, and management of the capacity and infrastructure resources needed to meet availability commitments, depending on the scope agreed for the engagement.
Environmental and Infrastructure Protections
The criteria commonly consider measures that protect against environmental threats and support the availability of the system, though the specific controls in place vary by organization and are evaluated against the entity's own commitments.
Backup, Recovery, and Continuity Considerations
Availability criteria frequently involve controls for backup, recovery, and business continuity that support the ability to restore or maintain availability, evaluated in the context of the service commitments and system requirements defined by the entity.

Common questions

Answers to the questions practitioners most commonly ask about A1.

Is the Availability category a required part of every SOC 2 examination?
No. Security, expressed through the Common Criteria, is the only required Trust Services Category. Availability is one of the optional categories (alongside Processing Integrity, Confidentiality, and Privacy) and is included only when scoping decisions call for it. In most engagements, an organization selects Availability when its service commitments involve system uptime or accessibility obligations, but it is not automatically part of a SOC 2 report.
Are the Availability Criteria the same as the availability-related controls in ISO 27001 Annex A?
No. The Availability Criteria are part of the AICPA Trust Services Criteria used in a SOC 2 attestation examination and should not be conflated with ISO 27001's Annex A reference controls. While both frameworks address availability-related concerns, they are structured differently, evaluated through different processes, and satisfying one does not automatically satisfy the other. Any mapping between them is partial and depends on scope.
When should we include the Availability category in our SOC 2 scope?
Availability is typically included when your service commitments and system requirements involve uptime, accessibility, or performance obligations to customers or users. The decision depends on the commitments you make to those users and the expectations your service creates. Because inclusion is a scoping decision, it is worth reviewing your customer contracts and service-level commitments with your auditor before finalizing the categories in scope.
How does the Availability category differ between a SOC 2 Type I and Type II report?
In a Type I report, the auditor assesses the suitability of the design of your availability-related controls at a point in time. In a Type II report, the auditor assesses both the design and the operating effectiveness of those controls over a defined review period, the length of which is set by scoping decisions rather than fixed. This means Type II typically requires evidence that availability controls operated consistently throughout the period covered.
What kinds of controls typically support the Availability Criteria?
Depending on scope, controls supporting Availability often address areas such as capacity monitoring, environmental protections, backup and recovery processes, incident handling, and business continuity or disaster recovery arrangements. The specific controls and how they are evaluated depend on your environment, service commitments, and the auditor's assessment, so there is no single mandatory set of controls.
Does including the Availability category mean our report guarantees a certain level of uptime?
No. A SOC 2 report attests only to the controls and the period covered by the examination and does not guarantee freedom from outages, breaches, or downtime. Including the Availability category means the auditor evaluated whether your availability-related controls were suitably designed and, in a Type II, operating effectively over the review period. It is not a service-level guarantee, and its assurance is limited to the defined scope and time frame.

Common misconceptions

The Availability Criteria guarantee a specific uptime percentage or that the system will never experience an outage.
A SOC 2 report addressing availability attests only to the controls in scope over the period covered and does not guarantee any particular uptime figure or freedom from outages. Availability criteria assess whether systems are available as committed or agreed by the entity, not against a universal uptime standard.
The Availability category is a required part of every SOC 2 examination.
Only the Security category (Common Criteria) is required in a SOC 2 examination. Availability is optional and is included based on scoping decisions relevant to the entity's commitments and its customers' needs.
The Availability Criteria are equivalent to ISO 27001 Annex A availability-related controls, so satisfying one satisfies the other.
The Trust Services Criteria are distinct from ISO 27001 Annex A reference controls. Mapping between the two frameworks is possible but partial, and addressing availability under SOC 2 does not automatically satisfy any corresponding ISO 27001 requirement or control.

Best practices

Confirm during scoping whether the Availability category should be included, based on the service commitments made to customers rather than adding it by default.
Define availability commitments and system requirements explicitly, so that the A1 criteria are assessed against clear, documented expectations.
For a Type II examination, ensure availability-related controls operate consistently across the defined review period, since Type II assesses both design and operating effectiveness over time.
Maintain evidence of capacity monitoring, backup, and recovery activities appropriate to the availability commitments in scope.
Communicate clearly to report users that the availability opinion covers only the controls and period examined and does not guarantee freedom from outages or breaches.
Where the organization also pursues ISO 27001, treat any mapping between SOC 2 availability criteria and ISO requirements as partial, and validate each framework's requirements independently.