Trust Services Category
A Trust Services Category is one of five subject areas that a SOC 2 examination can cover: Security, Availability, Processing Integrity, Confidentiality, and Privacy. An organization selects which categories apply based on the scope of its examination, though Security is included in every SOC 2 engagement. The categories describe the aspects of a service that the controls are intended to protect.
The Trust Services Categories, defined in the AICPA's 2017 Trust Services Criteria (with revised points of focus), organize the criteria used in a SOC 2 attestation examination into five areas: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security category, commonly referred to as the Common Criteria, is required in all SOC 2 engagements; the remaining four categories are optional and selected during scoping based on the nature of the service and the assurance needs of report users. A SOC 2 report attests only to the controls relevant to the categories included within the defined scope over (or as of) the period covered, and Trust Services Categories should not be conflated with ISO/IEC 27001 Annex A reference controls, which serve a different structural purpose within an ISMS.
Why it matters
The Trust Services Categories determine what a SOC 2 examination actually covers, which is why they sit at the center of scoping decisions. Because Security (the Common Criteria) is the only category included in every engagement, and the other four are selected based on the nature of the service, the categories a report addresses directly shape what assurance a reader can draw from it. A report that includes only Security speaks to a narrower set of concerns than one that also covers, for example, Availability and Confidentiality.
For report users, understanding which categories are in scope prevents overreading the assurance provided. A SOC 2 report attests only to the controls relevant to the categories included within the defined scope, and only over (or as of) the period covered. It does not guarantee freedom from breaches, nor does it speak to categories that were excluded from scope. A prospective customer evaluating a service provider needs to confirm that the categories relevant to their own risk concerns, such as Privacy when personal data is involved, were actually part of the examination rather than assuming that a SOC 2 report covers all five areas by default.
The categories also help keep frameworks distinct. Trust Services Categories organize the criteria used in a SOC 2 attestation examination and should not be conflated with ISO/IEC 27001 Annex A reference controls, which serve a different structural purpose within an information security management system. Selecting categories thoughtfully during scoping is what allows an organization to align the examination with the assurance needs of its report users rather than producing a report that is broader or narrower than intended.
Who it's relevant to
Inside Trust Services Category
Common questions
Answers to the questions practitioners most commonly ask about Trust Services Category.