Availability Requirements
Availability requirements specify how accessible and operational a system or service must be when users need it, usually expressed as a target percentage of uptime over a defined period. These targets are commonly tied to a service level agreement (SLA) that sets an agreed minimum level of availability and performance. In practice, the specific target and how it is measured vary depending on the system, the business need, and the agreement in place.
Availability requirements define measurable conditions under which a system, application, or service must remain accessible and operational when required. They are typically stated as a target availability percentage over a specified time period, often derived from a service level agreement, and may incorporate a defined minimum uptime and performance threshold below which the system is considered to have failed. Availability itself can be framed as the probability that a system performs as required at the time it is needed over a defined mission or operating window. In a SOC 2 context, availability is addressed under the optional Availability Trust Services Criteria category (in addition to the required Security/Common Criteria) and is included only when selected during scoping; the specific commitments and thresholds depend on the service commitments and system requirements defined for the engagement rather than on any fixed universal value.
Why it matters
Availability requirements translate a business need for accessible, operational systems into a measurable commitment, typically expressed as a target uptime percentage over a defined period. Without a stated target, expectations between a service provider and its customers remain ambiguous, and it becomes difficult to determine whether a system has actually met its obligations. Because these requirements are commonly tied to a service level agreement, they also carry contractual and sometimes financial consequences when the agreed minimum uptime or performance threshold is not met.
In a SOC 2 context, availability matters specifically when the Availability Trust Services Criteria category is selected during scoping. Availability is an optional category in addition to the required Security (Common Criteria) category, so it is examined only when the service commitments and system requirements defined for the engagement call for it. When it is in scope, the availability commitments and thresholds documented for the engagement become the benchmark against which the auditor evaluates whether controls are suitably designed and, in a Type II examination, operating effectively over the review period.
It is important to recognize the boundary of what an availability requirement establishes: it defines a target and how failure is measured, but meeting a stated availability percentage does not by itself guarantee freedom from outages, breaches, or other disruptions outside the defined measurement. The specific target and measurement approach vary depending on the system, the business need, and the agreement in place, so the requirement is meaningful only in relation to the commitments it references.
Who it's relevant to
Inside Availability Requirements
Common questions
Answers to the questions practitioners most commonly ask about Availability Requirements.