Supplemental Criteria
In a SOC 2 examination, supplemental criteria are additional control-related criteria that work alongside the core Trust Services Criteria to describe the specific control activities an organization is expected to have in place. They should not be confused with the optional Trust Services Categories (such as Availability or Confidentiality) that an organization chooses to include in its scope. The available evidence provided does not contain authoritative AICPA source material describing supplemental criteria in detail, so this entry cannot be verified against the supplied sources.
Within the AICPA Trust Services Criteria framework used for SOC 2 examinations, the term "supplemental criteria" refers to control-activity criteria that supplement the COSO-based common criteria rather than to the optional Trust Services Categories (Availability, Processing Integrity, Confidentiality, and Privacy). These criteria are distinct from the optional categories, which are selected via scoping decisions, and from ISO 27001 Annex A reference controls. However, the evidence packet supplied contains no authoritative AICPA or Trust Services Criteria source material; the listed sources address unrelated topics (university admissions, Medicare/Medicaid benefits, dietary supplements, and general legal usage of "supplemental"). A precise, citable technical definition therefore cannot be substantiated from the provided evidence, and this term should be re-drafted only once the authoritative AICPA Trust Services Criteria document is available as a source.
Why it matters
Supplemental criteria matter because they shape what a service organization is actually expected to demonstrate during a SOC 2 examination. The core common criteria establish a COSO-based control framework, but supplemental control-activity criteria describe the more granular control activities, spanning areas such as logical and physical access controls, system operations, change management, and risk mitigation, that auditors evaluate. Understanding this distinction helps compliance teams avoid a common conceptual error: treating supplemental criteria as if they were an optional Trust Services Category to be added or dropped through scoping decisions. They are not the same thing.
The practical stakes are significant for teams preparing for an examination. If a compliance manager misunderstands supplemental criteria as equivalent to categories like Availability or Confidentiality, they may under-scope their control activities and enter an engagement with gaps that the auditor identifies as exceptions. Conversely, understanding that supplemental criteria apply alongside the common criteria helps organizations map their controls accurately and prepare evidence that aligns with what a licensed CPA firm will actually test.
It is important to be candid about the limits of this entry: the evidence packet supplied contains no authoritative AICPA or Trust Services Criteria source material, and the listed sources address unrelated topics. The conceptual framing here reflects the standard structure of the AICPA Trust Services Criteria, but readers making audit or scoping decisions should confirm the precise definition, scope, and current wording against the authoritative AICPA Trust Services Criteria document rather than relying on this summary alone.
Who it's relevant to
Inside Supplemental Criteria
Common questions
Answers to the questions practitioners most commonly ask about Supplemental Criteria.