TSP Section 100
TSP Section 100 is the AICPA document that sets out the 2017 Trust Services Criteria used in SOC 2 examinations. It defines the five categories a service organization's controls can be evaluated against: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Note that 'TSP' here refers to Trust Services Principles/Criteria and is unrelated to the federal Thrift Savings Plan, which shares the same abbreviation.
TSP Section 100 refers to the AICPA's authoritative statement titled '2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus, 2022),' which establishes the criteria against which a CPA firm evaluates controls in a SOC 2 attestation examination conducted under the AICPA's attestation standards. Within this framework, the Security category (the Common Criteria) is the only required category, while Availability, Processing Integrity, Confidentiality, and Privacy are selected based on the engagement's scope. The criteria are accompanied by points of focus that illustrate characteristics practitioners may consider, though these points of focus are not themselves requirements and their application varies by engagement. The Trust Services Criteria are distinct from ISO/IEC 27001 Annex A reference controls, and TSP Section 100 governs the criteria used in SOC 2 (and, where applicable, SOC 3) reporting rather than issuing any certification.
Why it matters
TSP Section 100 is the foundational reference that gives SOC 2 examinations their structure. Because it defines the five Trust Services Criteria categories, Security, Availability, Processing Integrity, Confidentiality, and Privacy, it determines what a CPA firm actually evaluates when it conducts a SOC 2 attestation. Without a common set of criteria, SOC 2 reports would lack the consistency that allows customers, prospects, and their auditors to compare service organizations and place reliance on the resulting reports. Understanding that Security (the Common Criteria) is the only required category, while the other four are selected based on scope, is essential to reading any SOC 2 report accurately.
Who it's relevant to
Inside TSP Section 100
Common questions
Answers to the questions practitioners most commonly ask about TSP Section 100.