Skip to main content
Category: Trust Services Criteria

Security

Also known as: Common Criteria, Security Category, Security Trust Services Criteria
Simply put

In SOC 2, Security is the core set of expectations that an organization protects its systems and information against unauthorized access, use, or changes. It is the one category every SOC 2 examination must include, and the other categories are added only if they fit the organization's scope. Because the provided evidence covers only general, dictionary, and legal meanings of the word 'security', the SOC 2-specific characterization here reflects framework structure rather than the cited sources.

Formal definition

Within the AICPA Trust Services Criteria, Security is designated as the Common Criteria and is the only category required in every SOC 2 attestation examination; the remaining categories (Availability, Processing Integrity, Confidentiality, and Privacy) are optional and selected based on the engagement's scope. The Security category addresses protection of information and systems against unauthorized access, unauthorized disclosure, and damage that could compromise the availability, integrity, and confidentiality of information or systems. It should not be conflated with ISO/IEC 27001 Annex A reference controls; the Trust Services Criteria are a distinct AICPA framework evaluated in an SSAE 18 attestation report rather than an ISO management-system certification. Note that the sources in the evidence packet address only the general lexical, philosophical, and legal senses of 'security' and do not substantiate the SOC 2-specific details stated here, which derive from the framework's own structure.

Why it matters

Security occupies a uniquely foundational position in the SOC 2 framework: it is the Common Criteria, the one Trust Services Criteria category that every SOC 2 examination must include. The other four categories, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and are added only when they fit an organization's scope. This means that regardless of what an organization chooses to emphasize, the Security category always forms the baseline against which its controls are evaluated. Understanding this structure is essential for anyone scoping an engagement, because omitting Security is not an option, whereas including additional categories is a deliberate scoping decision.

For compliance and GRC teams, the practical importance of Security lies in what it does and does not represent. A SOC 2 report covering the Security category attests to the controls in scope over the period examined (for a Type II) or their design at a point in time (for a Type I); it does not guarantee that an organization is immune from breaches or that no unauthorized access will ever occur. Treating a favorable report as a blanket assurance of safety is a common misreading that can create false confidence among stakeholders and customers.

It is also worth keeping the frameworks distinct. The Security category belongs to the AICPA Trust Services Criteria and is evaluated in an SSAE 18 attestation report, not an ISO management-system certification. While it may be tempting to equate the SOC 2 Security category with ISO/IEC 27001 Annex A reference controls, they are separate constructs, and satisfying one does not automatically satisfy the other. Any mapping between them is partial and should be treated with care.

Who it's relevant to

Compliance and GRC Managers
Because Security is the mandatory Common Criteria, compliance managers scoping a SOC 2 engagement must ensure it is always included and then decide, based on scope and stakeholder commitments, whether to add Availability, Processing Integrity, Confidentiality, or Privacy. Understanding that Security is non-negotiable while the other categories are optional helps set accurate expectations with leadership and customers.
Security Engineers and Control Owners
Engineers responsible for protecting systems against unauthorized access, disclosure, and damage implement and maintain the controls evaluated under the Security category. Knowing that a Type II examination assesses operating effectiveness over a review period, rather than a single point in time, underscores the need for controls to function consistently throughout the period covered.
Auditors and CPA Firms
Practitioners performing SOC 2 attestation examinations evaluate the Security category in every engagement under the SSAE 18 standard. They must distinguish the Trust Services Criteria from ISO/IEC 27001 Annex A reference controls and be clear that the resulting report attests only to the controls and period in scope, not to freedom from breaches.
Customers and Third-Party Risk Reviewers
Organizations relying on a vendor's SOC 2 report should read the Security category as evidence about specified controls over a defined period, not as a guarantee of absolute safety. Reviewers should also recognize that a SOC 2 report is not an ISO 27001 certification, and that a vendor holding one does not automatically satisfy the requirements of the other.

Inside Security

Common Criteria (CC)
In SOC 2, the Security category is expressed through the Common Criteria, which form the baseline Trust Services Criteria applicable to every SOC 2 examination regardless of which optional categories are added.
Required Trust Services category
Security is the only Trust Services category required in a SOC 2 engagement; Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope.
Control environment coverage
Security typically addresses areas such as access controls, system operations, change management, and risk mitigation, though the specific controls in scope depend on the service organization and its scoping decisions.
Relationship to ISO 27001
Security under SOC 2 is a distinct concept from ISO 27001's Annex A reference controls and its clause 4-10 ISMS requirements; the two frameworks can be partially mapped but are not equivalent.

Common questions

Answers to the questions practitioners most commonly ask about Security.

Is the Security category the same thing as ISO 27001's Annex A controls?
No. Security in SOC 2 refers to the Common Criteria within the Trust Services Criteria, evaluated in a CPA-performed attestation under SSAE 18. ISO 27001 Annex A is a separate list of reference controls selected via a Statement of Applicability within an ISMS certification. While the two can be partially mapped to each other, they belong to different frameworks and satisfying one does not automatically satisfy the other.
Do I have to select the other Trust Services Criteria categories in addition to Security?
No. Security (the Common Criteria) is the only required category in a SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are included based on scoping decisions. Many engagements are scoped to Security alone, and additional categories are added only when they are relevant to the services and commitments being assessed.
How do I determine which controls to include under the Security category?
In most engagements, the controls are mapped to the Common Criteria and reflect how your organization addresses areas such as access, change management, and monitoring. The specific controls depend on your environment, the services in scope, and the commitments you make to customers. The service auditor evaluates whether the selected controls meet the applicable criteria, so control selection is typically a collaborative scoping exercise rather than a fixed checklist.
Should I pursue a Type I or Type II report when covering the Security category?
It depends on your objective. A Type I assesses the suitability of the design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions. Many organizations begin with a Type I to establish design and then move to Type II to demonstrate operating effectiveness over time, though the right path varies by stakeholder needs.
What does a report covering the Security category actually assure a customer of?
It attests to the controls described and, in a Type II, their operating effectiveness over the period covered. It does not guarantee freedom from breaches, nor does it cover controls, systems, or time periods outside the defined scope. Readers should review the scope, the period, and the auditor's opinion to understand exactly what the report addresses.
How does the Security category relate to reports like SOC 1 or SOC 3?
The Security category is part of the SOC 2 Trust Services Criteria and concerns controls relevant to security. SOC 1 addresses controls relevant to financial reporting and uses a different framework, while SOC 3 is a general-use summary report based on the same Trust Services Criteria as SOC 2 but with less detail. Choosing among them depends on the intended audience and the nature of the controls being reported on.

Common misconceptions

The Security category is one of several optional Trust Services Criteria that an organization can choose to leave out.
Security, expressed as the Common Criteria, is the only required Trust Services category in a SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are the optional categories selected based on scope.
A SOC 2 examination covering Security proves the organization is free from security breaches.
A SOC 2 report attests only to the controls and the period covered by the engagement. It does not guarantee freedom from breaches, and its scope is bounded by the controls and criteria examined.
The SOC 2 Security category is interchangeable with ISO 27001's security controls, so meeting one satisfies the other.
The SOC 2 Common Criteria are distinct from ISO 27001's Annex A controls and ISMS clause requirements. Mapping between the two is possible but partial, and satisfying one framework does not automatically satisfy the other.

Best practices

Confirm that Security (the Common Criteria) is included in every SOC 2 scope, and evaluate separately whether Availability, Processing Integrity, Confidentiality, or Privacy should be added based on your services and commitments.
Define the boundary of the systems and controls in scope before the engagement, since the Security controls examined depend on scoping decisions made with the CPA firm.
For a Type II examination, work with the auditor to set an appropriate review period, recognizing that the length varies and is determined by scoping rather than a fixed duration.
Avoid representing a SOC 2 outcome as a certification; it is an attestation report, and communicate its coverage and period limitations accurately to stakeholders.
If pursuing both frameworks, treat SOC 2 Security and ISO 27001 controls as partially mappable but distinct, and validate any crosswalk rather than assuming automatic coverage.
Document how your controls address the relevant Common Criteria areas and retain evidence covering the full examination period to support operating-effectiveness testing in a Type II engagement.