Skip to main content
Category: Trust Services Criteria

Category-Specific Criteria

Also known as: Category-Specific Trust Services Criteria, Additional Criteria
Simply put

In a SOC 2 examination, category-specific criteria are the additional standards that apply when a company chooses to include one or more optional Trust Services categories beyond the required Security category. These extra criteria address specific concerns such as system uptime, accurate processing, keeping information confidential, or protecting personal data, depending on which categories the company selects. Which criteria apply depends on the scope chosen for the engagement.

Formal definition

Within the AICPA Trust Services Criteria framework used for SOC 2 attestation examinations, category-specific criteria are those criteria associated with the individual Trust Services categories other than the Common Criteria (Security). The Trust Services Criteria are organized into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security (the Common Criteria) is the only required category and applies to every SOC 2 engagement; the remaining four categories are optional and selected based on the scope of the examination. When a category such as Availability, Processing Integrity, Confidentiality, or Privacy is in scope, its associated category-specific criteria are evaluated in addition to the Common Criteria. Because inclusion depends on scoping decisions, the applicable category-specific criteria vary by engagement. These criteria are distinct from ISO/IEC 27001 Annex A reference controls and should not be conflated with them; a SOC 2 report attests only to the controls and categories within the defined scope over the period covered.

Why it matters

Category-specific criteria determine what a SOC 2 examination actually covers beyond the baseline. Because Security (the Common Criteria) is the only required category, two SOC 2 reports can look superficially similar while covering very different ground. A service organization that includes Availability, for example, is evaluated against criteria addressing system uptime and resilience that a Security-only engagement would never touch. For anyone reading or relying on a SOC 2 report, understanding which category-specific criteria were in scope is essential to knowing what assurance the report does and does not provide.

This matters most when a customer's own compliance obligations hinge on a particular concern. An organization handling regulated personal data may need its vendor's report to include the Privacy category, while one depending on continuous service availability may look for the Availability category. Assuming a SOC 2 report covers these areas without checking the scope can create a false sense of coverage, since a report attests only to the controls and categories within its defined scope over the period covered.

Because the applicable category-specific criteria vary by engagement based on scoping decisions, they cannot be treated as a fixed checklist. They are distinct from ISO/IEC 27001 Annex A reference controls and should not be conflated with them; satisfying category-specific criteria in a SOC 2 examination does not by itself demonstrate conformity with a different framework.

Who it's relevant to

Compliance and GRC managers
They decide which optional Trust Services categories to include in a SOC 2 engagement, balancing customer expectations and organizational risk against the additional criteria each category brings into scope. Understanding category-specific criteria helps them define an appropriate and defensible scope.
Auditors and CPA firms
The examining firm evaluates the category-specific criteria for whichever optional categories are in scope, in addition to the Common Criteria. Accurate scoping determines exactly which criteria they must assess and report against.
Vendor risk and procurement teams
When relying on a supplier's SOC 2 report, these teams need to confirm which categories were included, since the report attests only to the categories and controls within its defined scope. A Security-only report will not address availability, processing integrity, confidentiality, or privacy concerns.
Security engineers and control owners
Those responsible for implementing and operating controls need to know which category-specific criteria apply so they can design and maintain controls that map to the criteria in scope for their engagement.

Inside Category-Specific Criteria

Security (Common Criteria)
The only required Trust Services category in a SOC 2 examination. The Common Criteria form the baseline that every SOC 2 engagement must address, covering areas such as the control environment, communication, risk assessment, monitoring, and logical and physical access.
Availability criteria
An optional category selected based on scope. When included, it addresses whether systems are available for operation and use as committed or agreed, typically relevant to services with uptime commitments.
Processing Integrity criteria
An optional category addressing whether system processing is complete, valid, accurate, timely, and authorized. It is selected when the completeness and accuracy of processing are material to the services being examined.
Confidentiality criteria
An optional category addressing whether information designated as confidential is protected as committed or agreed. It is selected depending on scope and the sensitivity of the data handled.
Privacy criteria
An optional category addressing the collection, use, retention, disclosure, and disposal of personal information in conformity with commitments. It is selected when personal information is within the scope of the examination.
Scope-driven selection
Beyond the required Security category, the additional criteria applied in a given engagement are determined by scoping decisions, service commitments, and applicable criteria rather than being universally mandated.

Common questions

Answers to the questions practitioners most commonly ask about Category-Specific Criteria.

Are the Category-Specific Criteria the same thing as ISO 27001 Annex A controls?
No. The Category-Specific Criteria belong to the AICPA Trust Services Criteria used in a SOC 2 examination, while Annex A controls are reference controls listed in ISO/IEC 27001 and selected via a Statement of Applicability. The two frameworks are structured differently, and mapping between them is partial. Satisfying the criteria for one category in SOC 2 does not automatically satisfy the corresponding Annex A controls, and vice versa.
Do I have to include all of the Category-Specific Criteria in every SOC 2 engagement?
No. The Security category (the Common Criteria) is the only required category in a SOC 2 examination. The Category-Specific Criteria for Availability, Processing Integrity, Confidentiality, and Privacy are optional and are selected based on the scope you define. In most engagements, organizations choose additional categories that reflect the commitments they make to their customers rather than including all of them by default.
How do I decide which category-specific criteria to include in my SOC 2 scope?
Selection typically depends on the commitments and service arrangements you make to customers and the nature of the services you provide. For example, organizations that commit to system uptime often add Availability, while those handling sensitive data may add Confidentiality or Privacy. Scoping decisions are made in consultation with your service auditor, and the appropriate categories vary by engagement rather than following a fixed formula.
How do the Category-Specific Criteria relate to the Common Criteria in an engagement?
The Common Criteria (Security) form the baseline that applies in every SOC 2 examination. When you add an optional category, its Category-Specific Criteria are evaluated in addition to the Common Criteria, not as a replacement. In practice this means the auditor assesses your controls against both the shared baseline and the additional criteria relevant to each selected category.
Do Category-Specific Criteria get evaluated differently in a Type I versus a Type II report?
The criteria themselves are the same, but the nature of the assessment differs by report type. In a Type I engagement, the auditor assesses the suitability of design of the controls addressing those criteria at a point in time. In a Type II engagement, the auditor assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions rather than being fixed.
If my report covers additional category-specific criteria, does that guarantee those areas are secure or breach-free?
No. A SOC 2 report attests only to the controls and the criteria covered over the period examined, and it does not guarantee freedom from breaches or issues outside that scope. Including additional Category-Specific Criteria expands what the auditor evaluated, but the report's assurance is still limited to the defined scope, the selected categories, and the period or point in time covered.

Common misconceptions

All five Trust Services categories must be included in every SOC 2 report.
Only Security (the Common Criteria) is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are selected based on the scope and commitments of the specific engagement.
The Trust Services Criteria are the same as ISO 27001 Annex A controls.
They are distinct. The Trust Services Criteria belong to the AICPA SOC 2 framework, while Annex A lists reference controls selected via a Statement of Applicability under ISO/IEC 27001. Mapping between the two is possible but only partial, and satisfying one does not automatically satisfy the other.
Meeting the category-specific criteria guarantees the organization is free from breaches.
A SOC 2 report attests only to the controls and the period covered by the examination. It does not guarantee freedom from breaches or that controls will remain effective outside the scope and timeframe assessed.

Best practices

Confirm the required Security (Common Criteria) category is addressed first, then determine which optional categories to include based on documented scoping decisions and service commitments.
Select Availability, Processing Integrity, Confidentiality, or Privacy criteria only where they are relevant to the services and data in scope, rather than adding categories that do not apply.
Document the rationale for including or excluding each optional category so the scope of the examination is clear to report users.
Coordinate with the licensed CPA firm performing the examination early to align the selected criteria with the intended report and review period.
Communicate clearly to stakeholders that the report attests only to the controls and period covered, and does not extend beyond the defined scope.
When also pursuing ISO 27001, treat any mapping between the Trust Services Criteria and Annex A controls as partial, and validate each framework's requirements independently.