Skip to main content
Category: Trust Services Criteria

Trust Services Principles

Also known as: TSP, Trust Services Criteria, TSC, Trust Service Criteria, SOC 2 Trust Principles
Simply put

The Trust Services Principles are a set of five categories the AICPA uses to evaluate an organization's controls during a SOC 2 examination: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Of these, only Security is required in every engagement, while the other four are included based on the scope chosen for the examination. The term 'Trust Services Principles' reflects earlier terminology; current AICPA materials refer to these categories as the Trust Services Criteria.

Formal definition

The Trust Services Principles (now formally the Trust Services Criteria, or TSC) are the AICPA-defined evaluation criteria against which a service organization's controls are assessed in a SOC 2 attestation examination performed under the SSAE 18 standard. The framework comprises five categories: Security (the Common Criteria, required in every SOC 2 engagement), Availability, Processing Integrity, Confidentiality, and Privacy. The four categories beyond Security are optional and selected according to the defined scope of the engagement, typically driven by the nature of the services and commitments made to user entities. The applicable criteria are set out in the 2017 Trust Services Criteria (with revised points of focus), and the outcome of an examination against them is a SOC 2 report, not a certification. The Trust Services Criteria are distinct from ISO 27001 Annex A reference controls; while partial mapping between the two frameworks is possible, satisfying one does not automatically satisfy the other.

Why it matters

The Trust Services Principles define the standard against which a service organization's controls are evaluated in a SOC 2 examination, which makes them the foundation of how trust is assessed and communicated between a service provider and the user entities that rely on it. Because Security (the Common Criteria) is required in every engagement while Availability, Processing Integrity, Confidentiality, and Privacy are selected based on scope, the categories chosen effectively shape what a resulting SOC 2 report does and does not cover. Understanding which criteria are in scope is essential for anyone reading a report, since it determines the assurance boundary being described.

Who it's relevant to

Compliance and GRC managers
Compliance and GRC managers use the Trust Services Criteria to define the scope of a SOC 2 engagement, deciding which optional categories beyond the required Security criteria should be included based on the services offered and commitments made to customers. This scoping decision determines the boundaries of the assurance the resulting report provides.
Auditors and CPA firms
Licensed CPA firms performing SOC 2 examinations under the SSAE 18 standard evaluate a service organization's controls against the applicable Trust Services Criteria and issue a SOC 2 report, not a certification, reflecting their findings within the defined scope and period.
Security engineers and control owners
Security engineers and control owners map their organization's controls to the relevant Trust Services Criteria, focusing first on Security as the Common Criteria and then on any additional categories in scope, such as Availability or Confidentiality, depending on the engagement.
Customers and user entities reviewing reports
Organizations that rely on a service provider read SOC 2 reports to understand which Trust Services Criteria were assessed. Because the report attests only to the controls and criteria within its defined scope, readers need to confirm which categories were included rather than assuming full coverage.

Inside TSP

Security (Common Criteria)
The only required category in a SOC 2 examination. It forms the baseline set of criteria (the Common Criteria) that every SOC 2 engagement must address, covering the protection of information and systems against unauthorized access, use, or modification.
Availability
An optional category selected based on scope. It addresses whether systems are available for operation and use as committed or agreed, typically relevant where uptime or accessibility commitments are made to customers.
Processing Integrity
An optional category selected based on scope. It addresses whether system processing is complete, valid, accurate, timely, and authorized, and is often relevant for services performing transaction or data processing.
Confidentiality
An optional category selected based on scope. It addresses the protection of information designated as confidential in accordance with commitments and requirements.
Privacy
An optional category selected based on scope. It addresses the collection, use, retention, disclosure, and disposal of personal information in line with commitments and applicable criteria. It is distinct from Confidentiality, which concerns confidential information more broadly.
Scoping-driven selection
Beyond the mandatory Security category, the practitioner and service organization select which optional categories to include based on the services provided, customer commitments, and the intended scope of the report.

Common questions

Answers to the questions practitioners most commonly ask about TSP.

Are the 'Trust Services Principles' the same as the Trust Services Criteria used in SOC 2 today?
The term 'Trust Services Principles' reflects earlier AICPA terminology; the current framework refers to the Trust Services Criteria. When you encounter 'Principles' in older documentation, it generally maps to what are now called the categories and criteria. The substance is closely related, but you should use the current 'Trust Services Criteria' terminology to avoid confusion in engagement discussions and scoping.
Do the Trust Services Criteria correspond directly to ISO 27001 Annex A controls?
No. The Trust Services Criteria belong to the SOC 2 framework administered under AICPA standards, while Annex A lists reference controls associated with ISO/IEC 27001. They are separate constructs from separate frameworks. Partial mapping between them is possible, but they are not interchangeable, and satisfying one set does not automatically satisfy the other.
Which Trust Services categories do we actually need to include in scope?
Security, addressed by the Common Criteria, is the only required category in a SOC 2 engagement. Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on your scope, the commitments you make to customers, and the nature of the services provided. In most engagements, organizations add categories that align with their service commitments rather than including all of them.
How do we decide whether to add the Availability or Confidentiality categories?
Selection typically depends on the commitments and system requirements relevant to your services and the expectations of your customers or their auditors. For example, organizations providing hosted services often consider Availability, while those handling sensitive customer data may consider Confidentiality. The appropriate categories vary by scope, so this decision is usually made during scoping in consultation with your service auditor.
Does covering the Trust Services Criteria in a Type II report guarantee we were free from security incidents during the period?
No. A SOC 2 report attests only to the suitability of design and, for Type II, the operating effectiveness of the controls covered over the defined review period. It does not guarantee freedom from breaches or that no incidents occurred, and it does not cover controls or timeframes outside the stated scope.
How should we map our existing controls to the Trust Services Criteria?
In most engagements, organizations work with their service auditor to align existing controls against the applicable criteria for the categories in scope, identifying where current controls address each criterion and where gaps may exist. The specific approach depends on the auditor, your environment, and the categories selected, so the mapping is tailored to each engagement rather than following a single fixed template.

Common misconceptions

All five Trust Services Criteria categories must be included in every SOC 2 examination.
Only Security (the Common Criteria) is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are selected based on the scope of the engagement and the commitments the service organization makes.
The Trust Services Criteria are the same as, or interchangeable with, ISO 27001 Annex A controls.
The Trust Services Criteria belong to the AICPA's SOC 2 framework and are distinct from ISO 27001's Annex A reference controls. While partial mapping between the two is possible, they are structured differently and satisfying one does not automatically satisfy the other.
A SOC 2 report addressing the Trust Services Criteria guarantees the organization is free from breaches.
A SOC 2 report attests only to the controls and the period covered by the examination. It does not guarantee freedom from breaches or assure security outside the defined scope and review conditions.

Best practices

Confirm that the Security (Common Criteria) category is always in scope, and treat it as the mandatory baseline for any SOC 2 examination.
Select optional categories (Availability, Processing Integrity, Confidentiality, Privacy) deliberately based on the services provided and the commitments made to customers, rather than including all categories by default.
Align the chosen categories with actual customer commitments and system boundaries so the report scope accurately reflects the services being assessed.
Keep the Trust Services Criteria conceptually separate from ISO 27001 Annex A controls when planning documentation, even where partial mapping is used to reduce duplicated effort.
Clearly communicate to stakeholders that the report attests only to the controls and period covered and does not guarantee freedom from breaches.
Engage the CPA firm early during scoping to agree on category selection and the review period, since these are set by scoping decisions rather than fixed rules.