Processing Integrity
Processing Integrity is one of the optional categories a company can include in a SOC 2 examination. It focuses on whether a system processes information the way it is supposed to, so that data is complete, accurate, timely, and authorized as it moves through the system. It is not required in every SOC 2 engagement and is typically selected when the reliability of data processing is important to the service being provided.
Processing Integrity is one of the optional Trust Services Criteria categories within a SOC 2 examination, selected based on scope alongside the required Security (Common Criteria) category, and is distinct from Availability, Confidentiality, and Privacy. It addresses whether system processing is complete, valid, accurate, timely, and authorized throughout the information lifecycle, from acceptance of inputs from authorized sources through processing, storage, maintenance, and output. In practice, controls supporting Processing Integrity are evaluated across processing objectives, inputs, and outputs to detect and address processing errors. As with all Trust Services Criteria, a SOC 2 report addressing Processing Integrity attests only to the controls and the period or point in time covered by the engagement and does not, on its own, guarantee error-free processing outside that defined scope. Note that the Trust Services Criteria are separate from ISO 27001 Annex A reference controls; satisfying Processing Integrity in SOC 2 does not automatically satisfy ISO 27001 requirements.
Why it matters
Processing Integrity addresses a question that Security alone does not: even when a system is well protected against unauthorized access, its outputs may still be wrong if inputs are incomplete, transformations introduce errors, or processing occurs at the wrong time. For services where the correctness of computed results directly affects customer decisions or obligations, such as transaction processing, billing, data transformation, or analytics platforms, the reliability of data as it moves through the system can be as important as its confidentiality. Including Processing Integrity in a SOC 2 examination signals to customers and their auditors that the service organization has controls designed to keep processing complete, valid, accurate, timely, and authorized throughout the information lifecycle.
Because Processing Integrity is an optional Trust Services Criteria category rather than a required one, its presence in a report reflects a deliberate scoping decision, typically made when data processing reliability is central to the service being provided. Its absence does not indicate a deficiency; it simply means the engagement did not cover that dimension. Readers of a SOC 2 report should therefore check which categories were in scope before drawing conclusions about processing reliability.
It is important to understand the limits of what Processing Integrity attests to. A SOC 2 report addressing this category speaks only to the controls and the period or point in time covered by the engagement, and does not on its own guarantee error-free processing outside that defined scope. It is also distinct from ISO 27001 Annex A reference controls, so satisfying Processing Integrity within a SOC 2 examination does not automatically satisfy ISO 27001 requirements.
Who it's relevant to
Inside Processing Integrity
Common questions
Answers to the questions practitioners most commonly ask about Processing Integrity.