Suitable Criteria
Suitable criteria are the benchmarks or standards a practitioner uses to measure and evaluate a subject matter in an attestation engagement, such as a SOC 2 examination. For criteria to be considered suitable, they generally need to be relevant, objective, measurable, and complete enough to allow reasonably consistent conclusions. Without suitable criteria, an examiner cannot form a meaningful opinion, because there would be no agreed yardstick against which to assess the controls.
In an AICPA attestation engagement performed under SSAE 18 (including the AT-C sections governing examinations), suitable criteria are the standards against which the subject matter is measured and reported. Under the applicable AICPA guidance, criteria are typically evaluated for suitability against four attributes: relevance, objectivity, measurability, and completeness. In a SOC 2 examination, the Trust Services Criteria (comprising the required Security/Common Criteria and, depending on scope, the optional Availability, Processing Integrity, Confidentiality, and Privacy categories) commonly serve as the suitable criteria. Suitability is distinct from availability of criteria; criteria must both be suitable and available to intended users. Note that suitable criteria establish only the measurement framework for the controls and period addressed in the report and do not, in themselves, guarantee an entity's freedom from breaches or ensure outcomes beyond the defined scope of the engagement.
Why it matters
Suitable criteria are the foundation on which any attestation opinion rests. In a SOC 2 examination performed under SSAE 18, the practitioner cannot form a meaningful conclusion about an entity's controls unless there is an agreed yardstick against which those controls are measured. If the criteria are vague, subjective, or incomplete, two reasonable examiners could reach materially different conclusions about the same subject matter, undermining the reliability and usefulness of the resulting report. For this reason, the concept of suitability functions as a gatekeeper: without it, the examination lacks the objective basis needed to support a defensible opinion.
For the intended users of a SOC 2 report, such as customers, prospects, and their auditors, suitable criteria are what make the report interpretable and comparable. Because the Trust Services Criteria commonly serve as the suitable criteria in a SOC 2 examination, readers can understand what the controls were measured against and reason about the report's relevance to their own risk decisions. This matters especially when relying parties are evaluating a service organization's controls as part of their own vendor risk management processes.
It is important to keep the boundaries of this concept in view. Suitable criteria establish only the measurement framework for the controls and period addressed in the report; they do not, in themselves, guarantee an entity's freedom from breaches or ensure any outcome beyond the defined scope of the engagement. Suitability is also distinct from availability: criteria must be both suitable and available to intended users for the engagement to serve its purpose.
Who it's relevant to
Inside Suitable Criteria
Common questions
Answers to the questions practitioners most commonly ask about Suitable Criteria.