Skip to main content
Category: Trust Services Criteria

Trust Services Category

Also known as: Trust Services Categories, TSC categories, Trust Services Criteria categories
Simply put

A Trust Services Category is one of five subject areas that a SOC 2 examination can cover: Security, Availability, Processing Integrity, Confidentiality, and Privacy. An organization selects which categories apply based on the scope of its examination, though Security is included in every SOC 2 engagement. The categories describe the aspects of a service that the controls are intended to protect.

Formal definition

The Trust Services Categories, defined in the AICPA's 2017 Trust Services Criteria (with revised points of focus), organize the criteria used in a SOC 2 attestation examination into five areas: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Security category, commonly referred to as the Common Criteria, is required in all SOC 2 engagements; the remaining four categories are optional and selected during scoping based on the nature of the service and the assurance needs of report users. A SOC 2 report attests only to the controls relevant to the categories included within the defined scope over (or as of) the period covered, and Trust Services Categories should not be conflated with ISO/IEC 27001 Annex A reference controls, which serve a different structural purpose within an ISMS.

Why it matters

The Trust Services Categories determine what a SOC 2 examination actually covers, which is why they sit at the center of scoping decisions. Because Security (the Common Criteria) is the only category included in every engagement, and the other four are selected based on the nature of the service, the categories a report addresses directly shape what assurance a reader can draw from it. A report that includes only Security speaks to a narrower set of concerns than one that also covers, for example, Availability and Confidentiality.

For report users, understanding which categories are in scope prevents overreading the assurance provided. A SOC 2 report attests only to the controls relevant to the categories included within the defined scope, and only over (or as of) the period covered. It does not guarantee freedom from breaches, nor does it speak to categories that were excluded from scope. A prospective customer evaluating a service provider needs to confirm that the categories relevant to their own risk concerns, such as Privacy when personal data is involved, were actually part of the examination rather than assuming that a SOC 2 report covers all five areas by default.

The categories also help keep frameworks distinct. Trust Services Categories organize the criteria used in a SOC 2 attestation examination and should not be conflated with ISO/IEC 27001 Annex A reference controls, which serve a different structural purpose within an information security management system. Selecting categories thoughtfully during scoping is what allows an organization to align the examination with the assurance needs of its report users rather than producing a report that is broader or narrower than intended.

Who it's relevant to

Compliance and GRC managers
These professionals lead the scoping decisions that determine which categories beyond the required Security category are included in an examination. They weigh the nature of the service and the assurance needs of report users to align the engagement's scope with customer and stakeholder expectations.
Auditors and CPA firms
The licensed CPA firm performing the SOC 2 examination evaluates the organization's controls against the criteria within the selected categories under the applicable AICPA standards. The categories in scope define the boundaries of what the resulting report attests to.
Security engineers and control owners
Engineers responsible for implementing and operating controls map their work to the criteria within the applicable categories. Understanding which categories are in scope helps them prioritize the controls that the examination will actually assess.
Customers and report readers
Prospective and current customers reviewing a SOC 2 report need to confirm which Trust Services Categories were included, since a report addresses only the categories within its defined scope and only over the period covered. This helps them judge whether the assurance provided matches their own risk concerns, such as those addressed by the Confidentiality or Privacy categories.

Inside Trust Services Category

Security (Common Criteria)
The only required Trust Services Category in a SOC 2 examination. It comprises the Common Criteria that address protection of information and systems against unauthorized access, use, or modification. Every SOC 2 engagement includes this category regardless of scope.
Availability
An optional category selected based on scope. It addresses whether systems are available for operation and use as committed or agreed, typically relevant when service commitments include uptime or accessibility obligations.
Processing Integrity
An optional category that addresses whether system processing is complete, valid, accurate, timely, and authorized. It is generally selected when the accuracy and completeness of transaction processing is central to the services provided.
Confidentiality
An optional category addressing the protection of information designated as confidential in accordance with commitments or agreements. It is distinct from Privacy and focuses on information restricted from disclosure rather than personal data specifically.
Privacy
An optional category addressing the collection, use, retention, disclosure, and disposal of personal information in conformity with the entity's privacy notice and applicable criteria. It is selected when handling of personal information is in scope.
Scope-driven selection
The categories included in a SOC 2 report are determined by scoping decisions. Security is always included, while the remaining four categories are added when relevant to the service organization's commitments and the needs of report users.

Common questions

Answers to the questions practitioners most commonly ask about Trust Services Category.

Are the Trust Services Criteria the same as ISO 27001 Annex A controls?
No. The Trust Services Criteria are the SOC 2 evaluation categories defined by the AICPA and used in an attestation examination. ISO 27001 Annex A lists reference controls selected via a Statement of Applicability under a management system standard. While partial mapping between the two is possible, they are distinct frameworks, and satisfying one does not automatically satisfy the other.
Do I have to include all five Trust Services Categories in a SOC 2 report?
No. Only Security, also known as the Common Criteria, is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on the scope of the engagement and the commitments relevant to your service. Many reports cover Security alone or Security combined with a subset of the others, depending on scope.
How do I decide which Trust Services Categories to include in scope?
Selection typically depends on the commitments you make to customers and the nature of your service. For example, an organization that promises high uptime may add Availability, while one handling sensitive customer data may add Confidentiality or Privacy. The choice is a scoping decision made with your service auditor and stakeholders, and Security is included in every engagement as the required baseline.
Can I add or remove a Trust Services Category in a later SOC 2 report?
In most engagements, the categories in scope can be adjusted between examinations as your commitments, services, or customer requirements change. Any change in scope is agreed during scoping with your service auditor. Keep in mind that a given report attests only to the categories and controls covered during the defined period.
Does adding more Trust Services Categories make the report stronger?
Not inherently. The appropriate categories are those aligned with your actual commitments and the risks relevant to your service, rather than a maximum count. Adding categories that do not reflect your commitments can expand testing effort without adding meaningful assurance. Scope should be driven by what is relevant to your customers and service, determined together with your service auditor.
What does a report covering a given set of Trust Services Categories actually assure?
It attests only to the controls addressing the selected categories and, for a Type II, their operating effectiveness over the defined review period. It does not cover categories outside the stated scope and does not guarantee freedom from breaches. Readers should review which categories are in scope to understand the boundaries of the assurance provided.

Common misconceptions

All five Trust Services Categories must be included in every SOC 2 report.
Only Security (the Common Criteria) is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope and the service organization's commitments.
The Trust Services Criteria are equivalent to ISO 27001 Annex A controls.
They are distinct constructs from different frameworks. The Trust Services Criteria underpin a SOC 2 attestation examination under AICPA standards, while Annex A lists reference controls selected via a Statement of Applicability under ISO/IEC 27001. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
A SOC 2 report covering these categories guarantees the organization is free from breaches.
A SOC 2 report attests only to the controls and the period or point in time covered by the examination. It does not guarantee freedom from security incidents and its assurance is bounded by the categories and scope selected.

Best practices

Begin by confirming that Security (the Common Criteria) is included, then evaluate which of the four optional categories align with your service commitments and user needs before finalizing scope.
Base category selection on the actual commitments made to customers and the nature of the services provided, rather than defaulting to including all categories.
Document the rationale for including or excluding each optional category so the scope of the examination is clear to report users and the examining CPA firm.
Distinguish the Trust Services Criteria from ISO 27001 Annex A controls when coordinating multiple frameworks, and treat any mapping between them as partial rather than equivalent.
Clearly communicate to stakeholders that the report attests only to the selected categories and the period or point in time covered, and does not extend beyond that defined scope.
Revisit category selection periodically, as changes in services, customer commitments, or handling of personal information may warrant adding or removing optional categories in future engagements.