Category-Specific Criteria
In a SOC 2 examination, category-specific criteria are the additional standards that apply when a company chooses to include one or more optional Trust Services categories beyond the required Security category. These extra criteria address specific concerns such as system uptime, accurate processing, keeping information confidential, or protecting personal data, depending on which categories the company selects. Which criteria apply depends on the scope chosen for the engagement.
Within the AICPA Trust Services Criteria framework used for SOC 2 attestation examinations, category-specific criteria are those criteria associated with the individual Trust Services categories other than the Common Criteria (Security). The Trust Services Criteria are organized into five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security (the Common Criteria) is the only required category and applies to every SOC 2 engagement; the remaining four categories are optional and selected based on the scope of the examination. When a category such as Availability, Processing Integrity, Confidentiality, or Privacy is in scope, its associated category-specific criteria are evaluated in addition to the Common Criteria. Because inclusion depends on scoping decisions, the applicable category-specific criteria vary by engagement. These criteria are distinct from ISO/IEC 27001 Annex A reference controls and should not be conflated with them; a SOC 2 report attests only to the controls and categories within the defined scope over the period covered.
Why it matters
Category-specific criteria determine what a SOC 2 examination actually covers beyond the baseline. Because Security (the Common Criteria) is the only required category, two SOC 2 reports can look superficially similar while covering very different ground. A service organization that includes Availability, for example, is evaluated against criteria addressing system uptime and resilience that a Security-only engagement would never touch. For anyone reading or relying on a SOC 2 report, understanding which category-specific criteria were in scope is essential to knowing what assurance the report does and does not provide.
This matters most when a customer's own compliance obligations hinge on a particular concern. An organization handling regulated personal data may need its vendor's report to include the Privacy category, while one depending on continuous service availability may look for the Availability category. Assuming a SOC 2 report covers these areas without checking the scope can create a false sense of coverage, since a report attests only to the controls and categories within its defined scope over the period covered.
Because the applicable category-specific criteria vary by engagement based on scoping decisions, they cannot be treated as a fixed checklist. They are distinct from ISO/IEC 27001 Annex A reference controls and should not be conflated with them; satisfying category-specific criteria in a SOC 2 examination does not by itself demonstrate conformity with a different framework.
Who it's relevant to
Inside Category-Specific Criteria
Common questions
Answers to the questions practitioners most commonly ask about Category-Specific Criteria.