Skip to main content
Category: SOC Reporting

Suitable Criteria

Also known as: Suitability of Criteria
Simply put

Suitable criteria are the benchmarks or standards a practitioner uses to measure and evaluate a subject matter in an attestation engagement, such as a SOC 2 examination. For criteria to be considered suitable, they generally need to be relevant, objective, measurable, and complete enough to allow reasonably consistent conclusions. Without suitable criteria, an examiner cannot form a meaningful opinion, because there would be no agreed yardstick against which to assess the controls.

Formal definition

In an AICPA attestation engagement performed under SSAE 18 (including the AT-C sections governing examinations), suitable criteria are the standards against which the subject matter is measured and reported. Under the applicable AICPA guidance, criteria are typically evaluated for suitability against four attributes: relevance, objectivity, measurability, and completeness. In a SOC 2 examination, the Trust Services Criteria (comprising the required Security/Common Criteria and, depending on scope, the optional Availability, Processing Integrity, Confidentiality, and Privacy categories) commonly serve as the suitable criteria. Suitability is distinct from availability of criteria; criteria must both be suitable and available to intended users. Note that suitable criteria establish only the measurement framework for the controls and period addressed in the report and do not, in themselves, guarantee an entity's freedom from breaches or ensure outcomes beyond the defined scope of the engagement.

Why it matters

Suitable criteria are the foundation on which any attestation opinion rests. In a SOC 2 examination performed under SSAE 18, the practitioner cannot form a meaningful conclusion about an entity's controls unless there is an agreed yardstick against which those controls are measured. If the criteria are vague, subjective, or incomplete, two reasonable examiners could reach materially different conclusions about the same subject matter, undermining the reliability and usefulness of the resulting report. For this reason, the concept of suitability functions as a gatekeeper: without it, the examination lacks the objective basis needed to support a defensible opinion.

For the intended users of a SOC 2 report, such as customers, prospects, and their auditors, suitable criteria are what make the report interpretable and comparable. Because the Trust Services Criteria commonly serve as the suitable criteria in a SOC 2 examination, readers can understand what the controls were measured against and reason about the report's relevance to their own risk decisions. This matters especially when relying parties are evaluating a service organization's controls as part of their own vendor risk management processes.

It is important to keep the boundaries of this concept in view. Suitable criteria establish only the measurement framework for the controls and period addressed in the report; they do not, in themselves, guarantee an entity's freedom from breaches or ensure any outcome beyond the defined scope of the engagement. Suitability is also distinct from availability: criteria must be both suitable and available to intended users for the engagement to serve its purpose.

Who it's relevant to

Compliance and GRC Managers
Those responsible for preparing for a SOC 2 examination need to understand which criteria will serve as the measurement benchmark and confirm they align with the intended scope. Recognizing that the Trust Services Criteria include the required Security category and optional categories helps them make appropriate scoping decisions before the engagement begins.
CPA Practitioners and Examiners
Licensed practitioners performing attestation engagements under SSAE 18 must evaluate whether the criteria are suitable, typically against relevance, objectivity, measurability, and completeness, and whether they are available to intended users. This assessment underpins the practitioner's ability to form and support a defensible opinion.
Report Readers and Vendor Risk Teams
Customers, prospects, and their auditors who rely on a SOC 2 report benefit from understanding what suitable criteria the controls were measured against. This context helps them interpret the report's conclusions and recognize that the opinion applies only to the controls and period within the defined scope, not to matters outside it.

Inside Suitable Criteria

Relevance
The criteria contribute to conclusions that are meaningful for the intended users' decision-making. In a SOC 2 examination, this means the criteria used to evaluate controls address the subject matter that report users care about within the defined scope.
Objectivity
The criteria are free from bias and are not influenced by the preferences of the party presenting the subject matter or the practitioner. Objective criteria allow different practitioners applying them to the same subject matter to reach reasonably consistent conclusions.
Measurability
The criteria permit reasonably consistent measurement, qualitative or quantitative, of the subject matter. This supports an examination in which the CPA firm can evaluate whether controls are suitably designed and, in a Type II, operating effectively over the review period.
Completeness
The criteria include all relevant factors that could affect the conclusions in the context of the engagement, so that no significant aspect of the subject matter is omitted from evaluation.
Role in SSAE 18 / AT-C engagements
Suitable criteria are a foundational requirement for an attestation examination such as SOC 2, performed by a licensed CPA firm under the AICPA's attestation standards. Without suitable criteria, the practitioner cannot form or express a conclusion. The Trust Services Criteria commonly serve as the suitable criteria in SOC 2 engagements.
Availability to users
Suitable criteria are typically expected to be available to intended users, for example through inclusion in or reference within the report, so users can understand the basis on which the subject matter was evaluated.

Common questions

Answers to the questions practitioners most commonly ask about Suitable Criteria.

Are the attributes of suitable criteria 'clear, reliable, neutral, understandable, and complete'?
That is a common misstatement. Under the AICPA attestation standards (AT-C 105, aligned with SSAE 18), criteria are evaluated against four authoritative attributes: relevance, objectivity, measurability, and completeness. Terms such as 'clear' or 'understandable' may appear in informal descriptions, but they are not the authoritative attribute set. When assessing whether criteria are suitable, practitioners should reference relevance, objectivity, measurability, and completeness rather than a substituted list.
Do the Trust Services Criteria automatically qualify as 'suitable criteria' for any SOC 2 engagement?
The Trust Services Criteria are established by the AICPA and are generally accepted as suitable criteria for SOC 2 engagements, but suitability still depends on how they are applied to the scope of a given engagement. Suitable criteria must exhibit relevance, objectivity, measurability, and completeness in the context of the specific subject matter. In most engagements the Security (Common Criteria) category is used, with Availability, Processing Integrity, Confidentiality, or Privacy added depending on scope. The criteria must fit the described system and covered period to be considered suitable for that particular examination.
How do we determine whether the criteria we plan to use are suitable before an engagement begins?
Assess the proposed criteria against the four authoritative attributes: relevance (do the criteria bear on the users' decisions?), objectivity (are they free from bias?), measurability (do they permit reasonably consistent measurement or evaluation?), and completeness (are relevant factors that could affect conclusions included?). In practice this evaluation is made in the context of the defined scope and the intended users of the report. The CPA firm performing the SOC 2 examination typically confirms that the criteria meet these attributes as part of engagement acceptance.
Who is responsible for establishing the criteria in a SOC 2 examination?
For SOC 2, the Trust Services Criteria are established by the AICPA, so they are considered established criteria available to users rather than criteria developed by the individual service organization. The service organization is responsible for describing its system and the controls intended to meet the applicable criteria, while the CPA firm evaluates suitability and reports on the results. This differs from engagements where an entity must develop and disclose its own criteria.
Do suitable criteria need to be available to the users of the report?
Yes. Beyond meeting the attributes of relevance, objectivity, measurability, and completeness, criteria generally need to be available to intended users so they can understand the basis on which the subject matter was evaluated. For SOC 2, the Trust Services Criteria are publicly established by the AICPA, which supports availability. When criteria are not publicly established, availability is typically addressed by including or referencing them within the report itself, depending on the engagement.
How does the concept of suitable criteria differ between SOC 2 and ISO 27001?
Suitable criteria is a concept specific to attestation engagements under the AICPA standards, and it governs the benchmarks against which a SOC 2 examination evaluates controls. ISO/IEC 27001 does not use 'suitable criteria' in this sense; it is a certification against management system requirements in clauses 4 through 10, with reference controls in Annex A selected via a Statement of Applicability. Because the frameworks operate differently, satisfying the suitable criteria requirements of a SOC 2 examination does not by itself address ISO 27001 conformity, and mapping between the two is only partial.

Common misconceptions

Any reasonable-sounding set of qualities, such as 'clear, reliable, neutral, and understandable,' defines whether criteria are suitable.
Under the AICPA attestation standards (SSAE 18 / AT-C 105), the attributes that make criteria suitable are Relevance, Objectivity, Measurability, and Completeness. Other descriptors are informal paraphrases and should not be treated as the authoritative list.
Suitable criteria are unique to SOC 2 and equivalent to ISO 27001's requirements.
Suitable criteria are a general attestation concept applied across engagements performed under the AICPA standards, not solely SOC 2. ISO/IEC 27001 is a certification against a management system standard and does not use the 'suitable criteria' construct; the concepts are not interchangeable, and satisfying one framework does not automatically satisfy the other.
Because criteria are suitable, the resulting report guarantees the controls were effective in all respects.
Suitable criteria establish the basis for evaluation, but the report attests only to the controls and the period or point in time covered by the engagement. It does not guarantee freedom from breaches or address matters outside the defined scope.

Best practices

Confirm that the criteria selected for an examination meet all four attributes, Relevance, Objectivity, Measurability, and Completeness, before scoping the engagement, rather than relying on informal descriptors.
In SOC 2 engagements, use the Trust Services Criteria as the suitable criteria and document how the selected categories (Security is required; Availability, Processing Integrity, Confidentiality, and Privacy are optional and scope-driven) map to your controls.
Ensure the criteria are made available to intended users, typically by referencing or including them in the report so users understand the basis of evaluation.
Document how each control is measurable against the criteria, since measurability underpins the CPA firm's ability to evaluate suitability of design and, in a Type II, operating effectiveness over the review period.
Review criteria for completeness with respect to the defined scope so that no significant aspect of the subject matter is omitted, and revisit this whenever scope changes.
Avoid presenting suitable criteria as equivalent to ISO 27001 requirements; if pursuing both frameworks, treat any mapping as partial and validate it independently with the relevant CPA firm and certification body.