Trust Services Principles
The Trust Services Principles are a set of five categories the AICPA uses to evaluate an organization's controls during a SOC 2 examination: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Of these, only Security is required in every engagement, while the other four are included based on the scope chosen for the examination. The term 'Trust Services Principles' reflects earlier terminology; current AICPA materials refer to these categories as the Trust Services Criteria.
The Trust Services Principles (now formally the Trust Services Criteria, or TSC) are the AICPA-defined evaluation criteria against which a service organization's controls are assessed in a SOC 2 attestation examination performed under the SSAE 18 standard. The framework comprises five categories: Security (the Common Criteria, required in every SOC 2 engagement), Availability, Processing Integrity, Confidentiality, and Privacy. The four categories beyond Security are optional and selected according to the defined scope of the engagement, typically driven by the nature of the services and commitments made to user entities. The applicable criteria are set out in the 2017 Trust Services Criteria (with revised points of focus), and the outcome of an examination against them is a SOC 2 report, not a certification. The Trust Services Criteria are distinct from ISO 27001 Annex A reference controls; while partial mapping between the two frameworks is possible, satisfying one does not automatically satisfy the other.
Why it matters
The Trust Services Principles define the standard against which a service organization's controls are evaluated in a SOC 2 examination, which makes them the foundation of how trust is assessed and communicated between a service provider and the user entities that rely on it. Because Security (the Common Criteria) is required in every engagement while Availability, Processing Integrity, Confidentiality, and Privacy are selected based on scope, the categories chosen effectively shape what a resulting SOC 2 report does and does not cover. Understanding which criteria are in scope is essential for anyone reading a report, since it determines the assurance boundary being described.
Who it's relevant to
Inside TSP
Common questions
Answers to the questions practitioners most commonly ask about TSP.