Skip to main content
Category: Trust Services Criteria

Service Commitments

Also known as: Service Level Commitment
Simply put

Service commitments are the promises a service provider makes to its customers about how its systems and services will perform, such as availability, security, or processing performance. In a SOC 2 context, these commitments help define what the provider is expected to deliver, and the controls examined in an engagement are evaluated in relation to these promises. The specific commitments vary from provider to provider depending on the services offered and the agreements in place.

Formal definition

In a SOC 2 examination performed under the AICPA SSAE 18 standard, service commitments are the declarations a service organization makes to user entities regarding the systems used to provide services, typically expressed in customer agreements, service level terms, or published statements. They are assessed alongside system requirements against the applicable Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. The nature and content of service commitments depend on the provider, the services in scope, and the applicable criteria; a SOC 2 report attests only to the controls and, for a Type II, the period covered, and does not guarantee that all commitments were met outside the examined scope or that the organization is free from breaches.

Why it matters

Service commitments sit at the heart of a SOC 2 examination because they establish the benchmark against which controls are evaluated. A service organization's controls are not assessed in a vacuum; they are examined in relation to what the provider has promised its customers about how its systems will perform, whether that concerns availability, security, or processing performance. Without clearly articulated commitments, there is no defined standard against which an auditor can assess whether the design and, for a Type II, the operating effectiveness of controls are suitable.

For customers evaluating a provider, service commitments clarify what is actually being promised and, by extension, what the SOC 2 report speaks to. Because these commitments typically appear in customer agreements, service level terms, or published statements, they connect contractual obligations to the controls an auditor tests. This matters when scoping decisions are made, since the applicable Trust Services Criteria, Security as the required Common Criteria, with Availability, Processing Integrity, Confidentiality, and Privacy selected as needed, are informed by the commitments the provider has made.

It is important to recognize the limits of what service commitments and the resulting report convey. A SOC 2 report attests only to the controls and, for a Type II, the period covered; it does not guarantee that every commitment was met outside the examined scope, nor does it guarantee that the organization is free from breaches. Because commitments vary from provider to provider, readers of a report should examine the specific commitments in scope rather than assume a uniform standard applies.

Who it's relevant to

Compliance and GRC managers
These professionals define and document the service commitments that will be assessed in a SOC 2 examination, ensuring that what the organization promises customers aligns with the controls in place and the Trust Services Criteria selected during scoping.
Auditors and CPA firms
The CPA firm performing the SOC 2 examination evaluates controls in relation to the organization's service commitments and system requirements, assessing suitability of design and, in a Type II, operating effectiveness over the period covered.
Customers and prospective user entities
Organizations relying on a service provider use service commitments to understand what is being promised about system performance and to interpret what a SOC 2 report covers, recognizing that the report attests only to the controls and period examined and does not guarantee freedom from breaches.
Legal and contracts teams
Because service commitments are typically expressed in customer agreements and service level terms, these teams shape the contractual language that defines the minimum level of service performance a provider commits to deliver.

Inside Service Commitments

System Commitments
The declarations a service organization makes to its customers, often in contracts, service level agreements, or published policies, about how it will handle, protect, and process data. In a SOC 2 examination, these commitments form part of the basis against which controls are evaluated.
Relationship to the Trust Services Criteria
Service commitments are typically assessed in the context of the applicable Trust Services Criteria, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on scope. Commitments generally align with whichever categories are in scope for the engagement.
System Requirements
The specifications an organization must meet to achieve its service commitments, which may derive from laws, regulations, contracts, or internal policies. Commitments describe what is promised, while requirements describe what the organization must do operationally to deliver on those promises.
Role in a SOC 2 Report
In a SOC 2 attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard, the service organization's commitments and system requirements are typically described in the system description and used as a reference point for evaluating whether controls are suitably designed and, in a Type II, operating effectively over the review period.

Common questions

Answers to the questions practitioners most commonly ask about Service Commitments.

Are service commitments the same as the Trust Services Criteria in a SOC 2 examination?
No. The Trust Services Criteria are the standardized criteria published by the AICPA against which controls are evaluated, while service commitments are the specific promises a service organization makes to its user entities about the system. In a SOC 2 examination, the auditor typically assesses whether the organization's controls provide reasonable assurance that its service commitments and system requirements were achieved based on the applicable Trust Services Criteria. The two concepts are related but distinct: the criteria are the framework, and the commitments are what the organization has undertaken to deliver within that framework.
Does a SOC 2 report confirm that a service organization always meets its service commitments?
No. A SOC 2 report attests only to the controls and, for a Type II, the operating effectiveness over the defined review period covered by the engagement. It expresses an opinion about whether controls were suitably designed and, in most Type II engagements, operating effectively to meet the stated service commitments during that period. It does not guarantee that commitments will be met in the future, does not cover periods outside the scope, and does not guarantee freedom from breaches. Readers should interpret the report as evidence about the specific commitments and period examined.
Where are service commitments typically documented so they can be examined?
Service commitments are commonly found in customer-facing documents such as service level agreements, terms of service, contracts, published policies, and security or availability statements. In most engagements, the auditor reviews these sources together with management's description of the system to understand what the organization has committed to its user entities. Because the specific commitments vary by organization and offering, there is no single mandatory location; the description of the system is generally where they are consolidated for the examination.
How do service commitments relate to the optional Trust Services Categories an organization selects?
The categories included in scope typically shape the nature of the relevant service commitments. Security (the Common Criteria) is always required, so security-related commitments generally apply. If an organization also selects Availability, Processing Integrity, Confidentiality, or Privacy, its commitments in those areas, such as uptime targets under Availability or handling of personal data under Privacy, become relevant to the examination. Which commitments matter depends on the scope and the categories chosen for the engagement.
How should an organization define its service commitments before a SOC 2 examination?
In practice, organizations work to state their commitments clearly enough that controls can be mapped to them and their achievement can be evaluated. This typically involves reviewing existing contracts and published statements for consistency, confirming that commitments align with the system as actually operated, and identifying the system requirements needed to support each commitment. Overly broad or unsupportable commitments can create difficulty during the examination, so clarity and accuracy tend to matter more than breadth. The precise approach depends on the organization's scope and the auditor's expectations.
Do service commitments have a direct equivalent in ISO 27001?
ISO 27001 does not use the term service commitments in the same way SOC 2 does. Its certifiable requirements are in clauses 4 through 10, which establish an information security management system, with Annex A providing reference controls selected via a Statement of Applicability. Concepts such as interested parties' requirements and contractual obligations addressed within the ISMS can overlap conceptually with service commitments, but the frameworks structure these ideas differently. Mapping between them is possible but partial, and meeting SOC 2 commitments does not automatically satisfy ISO 27001 requirements.

Common misconceptions

Meeting service commitments guarantees that no security breach will occur.
A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches. Service commitments describe what the organization promises and the controls intended to support those promises; they do not eliminate residual risk.
Service commitments are an ISO 27001 concept and map directly to Annex A controls.
Service commitments are associated with the SOC 2 framework and the Trust Services Criteria, which should not be conflated with ISO 27001's Annex A reference controls or its ISMS requirements in clauses 4 through 10. Any mapping between the frameworks is partial, and satisfying one does not automatically satisfy the other.
There is a single, standardized set of service commitments every organization must make.
Commitments vary depending on scope, the criteria selected, and the organization's contracts and customer relationships. In most engagements they are defined by the service organization rather than dictated by a universal rule.

Best practices

Document service commitments clearly in contracts, SLAs, and customer-facing policies so they can be referenced consistently during a SOC 2 examination.
Align documented commitments with the Trust Services Criteria categories that are actually in scope, recognizing that Security is required while other categories are optional.
Translate each commitment into corresponding system requirements and specific controls so auditors can evaluate suitability of design and, for a Type II, operating effectiveness over the review period.
Review commitments periodically to confirm they remain accurate and achievable as services, contracts, and applicable regulations change.
Avoid overstating what commitments deliver; make clear internally and to customers that they describe intended controls rather than a guarantee against breaches.
Coordinate with your CPA firm early during scoping to confirm which commitments and requirements will be described in the system description and assessed in the report.