Service Commitments
Service commitments are the promises a service provider makes to its customers about how its systems and services will perform, such as availability, security, or processing performance. In a SOC 2 context, these commitments help define what the provider is expected to deliver, and the controls examined in an engagement are evaluated in relation to these promises. The specific commitments vary from provider to provider depending on the services offered and the agreements in place.
In a SOC 2 examination performed under the AICPA SSAE 18 standard, service commitments are the declarations a service organization makes to user entities regarding the systems used to provide services, typically expressed in customer agreements, service level terms, or published statements. They are assessed alongside system requirements against the applicable Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. The nature and content of service commitments depend on the provider, the services in scope, and the applicable criteria; a SOC 2 report attests only to the controls and, for a Type II, the period covered, and does not guarantee that all commitments were met outside the examined scope or that the organization is free from breaches.
Why it matters
Service commitments sit at the heart of a SOC 2 examination because they establish the benchmark against which controls are evaluated. A service organization's controls are not assessed in a vacuum; they are examined in relation to what the provider has promised its customers about how its systems will perform, whether that concerns availability, security, or processing performance. Without clearly articulated commitments, there is no defined standard against which an auditor can assess whether the design and, for a Type II, the operating effectiveness of controls are suitable.
For customers evaluating a provider, service commitments clarify what is actually being promised and, by extension, what the SOC 2 report speaks to. Because these commitments typically appear in customer agreements, service level terms, or published statements, they connect contractual obligations to the controls an auditor tests. This matters when scoping decisions are made, since the applicable Trust Services Criteria, Security as the required Common Criteria, with Availability, Processing Integrity, Confidentiality, and Privacy selected as needed, are informed by the commitments the provider has made.
It is important to recognize the limits of what service commitments and the resulting report convey. A SOC 2 report attests only to the controls and, for a Type II, the period covered; it does not guarantee that every commitment was met outside the examined scope, nor does it guarantee that the organization is free from breaches. Because commitments vary from provider to provider, readers of a report should examine the specific commitments in scope rather than assume a uniform standard applies.
Who it's relevant to
Inside Service Commitments
Common questions
Answers to the questions practitioners most commonly ask about Service Commitments.