Skip to main content
Category: Trust Services Criteria

Supplemental Criteria

Simply put

In a SOC 2 examination, supplemental criteria are additional control-related criteria that work alongside the core Trust Services Criteria to describe the specific control activities an organization is expected to have in place. They should not be confused with the optional Trust Services Categories (such as Availability or Confidentiality) that an organization chooses to include in its scope. The available evidence provided does not contain authoritative AICPA source material describing supplemental criteria in detail, so this entry cannot be verified against the supplied sources.

Formal definition

Within the AICPA Trust Services Criteria framework used for SOC 2 examinations, the term "supplemental criteria" refers to control-activity criteria that supplement the COSO-based common criteria rather than to the optional Trust Services Categories (Availability, Processing Integrity, Confidentiality, and Privacy). These criteria are distinct from the optional categories, which are selected via scoping decisions, and from ISO 27001 Annex A reference controls. However, the evidence packet supplied contains no authoritative AICPA or Trust Services Criteria source material; the listed sources address unrelated topics (university admissions, Medicare/Medicaid benefits, dietary supplements, and general legal usage of "supplemental"). A precise, citable technical definition therefore cannot be substantiated from the provided evidence, and this term should be re-drafted only once the authoritative AICPA Trust Services Criteria document is available as a source.

Why it matters

Supplemental criteria matter because they shape what a service organization is actually expected to demonstrate during a SOC 2 examination. The core common criteria establish a COSO-based control framework, but supplemental control-activity criteria describe the more granular control activities, spanning areas such as logical and physical access controls, system operations, change management, and risk mitigation, that auditors evaluate. Understanding this distinction helps compliance teams avoid a common conceptual error: treating supplemental criteria as if they were an optional Trust Services Category to be added or dropped through scoping decisions. They are not the same thing.

The practical stakes are significant for teams preparing for an examination. If a compliance manager misunderstands supplemental criteria as equivalent to categories like Availability or Confidentiality, they may under-scope their control activities and enter an engagement with gaps that the auditor identifies as exceptions. Conversely, understanding that supplemental criteria apply alongside the common criteria helps organizations map their controls accurately and prepare evidence that aligns with what a licensed CPA firm will actually test.

It is important to be candid about the limits of this entry: the evidence packet supplied contains no authoritative AICPA or Trust Services Criteria source material, and the listed sources address unrelated topics. The conceptual framing here reflects the standard structure of the AICPA Trust Services Criteria, but readers making audit or scoping decisions should confirm the precise definition, scope, and current wording against the authoritative AICPA Trust Services Criteria document rather than relying on this summary alone.

Who it's relevant to

Compliance and GRC managers
Managers scoping a SOC 2 engagement need to distinguish supplemental control-activity criteria from the optional Trust Services Categories so they do not under- or over-scope their control set. Misclassifying supplemental criteria as a selectable category can lead to preparation gaps that surface as exceptions during the examination.
Auditors and CPA examination teams
Licensed CPA firms performing a SOC 2 examination under SSAE 18 evaluate control activities against the common criteria together with the applicable supplemental criteria. A clear understanding of how these criteria relate helps examiners design and document tests of design and, in a Type II engagement, operating effectiveness over the review period.
Security engineers preparing control evidence
Engineers responsible for implementing and evidencing controls in areas such as access management, change management, and system operations benefit from understanding that supplemental criteria describe expected control activities. This helps them align evidence with what an auditor will test, rather than assuming these criteria are optional scope elements.

Inside Supplemental Criteria

Logical and Physical Access Controls
One of the supplemental criteria sets within the Common Criteria that addresses how an entity restricts logical and physical access, provisions and removes access rights, and protects against unauthorized access. It supplements the COSO framework's control activities principle as applied to the Trust Services Criteria.
System Operations
A supplemental criteria set covering how the entity manages the operation of systems, detects and responds to processing deviations and security events, and monitors for anomalies. It provides control activity criteria beyond the COSO principles alone.
Change Management
A supplemental criteria set addressing how the entity identifies the need for changes, manages those changes through an authorized and controlled process, and prevents unauthorized changes to infrastructure, data, software, and procedures.
Risk Mitigation
A supplemental criteria set concerned with how the entity identifies, selects, and develops risk mitigation activities, including those addressing risks arising from business disruptions and the use of vendors and business partners.
Relationship to COSO Principle 12
The supplemental criteria are the control-activity criteria that supplement COSO Principle 12 within the AICPA Trust Services Criteria. They elaborate control activities specific to a security and technology context rather than introducing a separate category.
Application across categories
The supplemental criteria are part of the Common Criteria (Security) and apply across the Trust Services engagement, including when the optional categories (Availability, Processing Integrity, Confidentiality, Privacy) are in scope. They are not themselves optional categories.

Common questions

Answers to the questions practitioners most commonly ask about Supplemental Criteria.

Are supplemental criteria the same as the optional Trust Services Categories like Availability and Confidentiality?
No. This is a common point of confusion. The optional categories (Availability, Processing Integrity, Confidentiality, and Privacy) are Trust Services Categories selected based on the scope of the engagement, alongside the required Security category. Supplemental criteria are a different concept: they are the control-activity criteria within the Common Criteria that supplement COSO Principle 12, addressing areas such as logical and physical access controls, system operations, change management, and risk mitigation. Supplemental criteria are not categories, and selecting them is not the same as adding an optional category to your scope.
Do supplemental criteria function as a sixth Trust Services Category?
No. Supplemental criteria are not a category at all, and there is no sixth category. They exist as part of the Common Criteria structure to supplement the COSO framework principles, particularly around control activities. They apply within the criteria structure rather than being selected the way the optional categories are. Treating them as an additional category misrepresents how the Trust Services Criteria are organized.
How do supplemental criteria relate to the COSO framework used in the Trust Services Criteria?
The Trust Services Criteria align the Common Criteria with the COSO internal control framework principles. Supplemental criteria are added to supplement COSO Principle 12, which concerns the deployment of control activities. They provide additional, more specific criteria in areas such as logical and physical access controls, system operations, change management, and risk mitigation, which are typically central to how a service organization's controls are evaluated in a SOC 2 engagement.
Where do supplemental criteria appear when we design controls for a SOC 2 examination?
Because supplemental criteria sit within the Common Criteria, they are relevant to every SOC 2 examination that includes the Security category, which is required in all engagements. In practice, controls addressing access, operations, change management, and risk mitigation are mapped to these criteria. The exact way controls are mapped and evaluated depends on the auditor, the scope, and the applicable criteria selected for the engagement, so specifics vary from one examination to another.
Do supplemental criteria apply only to the Security category, or across the other categories too?
The supplemental criteria that supplement the COSO principle on control activities apply within the Common Criteria, which underpins the Security category required in every engagement. When additional categories such as Availability, Confidentiality, Processing Integrity, or Privacy are in scope, they bring their own category-specific criteria that operate alongside the Common Criteria. How these interact in a given report depends on scope and the auditor's approach, so the mapping should be confirmed for each engagement rather than assumed to be uniform.
How should we document the supplemental criteria for our auditor?
In most engagements, the service organization works with its CPA firm to map its controls to the applicable Trust Services Criteria, including the supplemental criteria within the Common Criteria. Documentation typically shows how specific controls address each criterion, including those covering logical and physical access, system operations, change management, and risk mitigation. Because a SOC 2 report attests only to the controls and the period covered, the documentation should reflect the actual controls in operation rather than aspirational ones, and the final structure and expectations depend on the auditor and scope.

Common misconceptions

Supplemental criteria are the optional Trust Services Categories, such as Availability, Processing Integrity, Confidentiality, and Privacy.
Supplemental criteria are not the optional categories. In the AICPA Trust Services Criteria they are the control-activity criteria that supplement COSO Principle 12, comprising Logical and Physical Access Controls, System Operations, Change Management, and Risk Mitigation. The optional categories are a separate scoping concept selected based on the engagement.
Supplemental criteria constitute a sixth Trust Services category that must be separately selected.
They are not a separate or sixth category. They form part of the Common Criteria (Security), which is required in every SOC 2 examination, and provide additional control-activity detail rather than an optional scoping choice.
Supplemental criteria are equivalent to ISO 27001 Annex A controls.
They are distinct constructs from different frameworks. The supplemental criteria elaborate control activities within the AICPA Trust Services Criteria, while Annex A of ISO/IEC 27001 lists reference controls selected via a Statement of Applicability. Mapping between them may be possible but is partial, and satisfying one does not automatically satisfy the other.

Best practices

Treat the four supplemental criteria sets, Logical and Physical Access Controls, System Operations, Change Management, and Risk Mitigation, as integral parts of the Common Criteria rather than as optional add-ons.
Map your organization's controls to each supplemental criteria set to confirm that control activities supplementing COSO Principle 12 are addressed, and document how they operate.
When scoping optional Trust Services categories such as Availability or Confidentiality, keep them conceptually separate from the supplemental criteria, which apply as part of the required Security category.
Consult the current AICPA Trust Services Criteria directly, and confirm the applicable version with your CPA firm, since criteria wording and structure are periodically updated.
In a Type II examination, retain evidence demonstrating that supplemental-criteria controls operated effectively throughout the review period, whose length is set by scoping decisions rather than fixed.
If also pursuing ISO/IEC 27001, treat any mapping between the supplemental criteria and Annex A reference controls as partial guidance only, and validate coverage separately for each framework.