Skip to main content
Category: Trust Services Criteria

TSP Section 100

Also known as: TSP Section 100 — 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, 2017 Trust Services Criteria (With Revised Points of Focus)
Simply put

TSP Section 100 is the AICPA document that sets out the 2017 Trust Services Criteria used in SOC 2 examinations. It defines the five categories a service organization's controls can be evaluated against: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Note that 'TSP' here refers to Trust Services Principles/Criteria and is unrelated to the federal Thrift Savings Plan, which shares the same abbreviation.

Formal definition

TSP Section 100 refers to the AICPA's authoritative statement titled '2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus, 2022),' which establishes the criteria against which a CPA firm evaluates controls in a SOC 2 attestation examination conducted under the AICPA's attestation standards. Within this framework, the Security category (the Common Criteria) is the only required category, while Availability, Processing Integrity, Confidentiality, and Privacy are selected based on the engagement's scope. The criteria are accompanied by points of focus that illustrate characteristics practitioners may consider, though these points of focus are not themselves requirements and their application varies by engagement. The Trust Services Criteria are distinct from ISO/IEC 27001 Annex A reference controls, and TSP Section 100 governs the criteria used in SOC 2 (and, where applicable, SOC 3) reporting rather than issuing any certification.

Why it matters

TSP Section 100 is the foundational reference that gives SOC 2 examinations their structure. Because it defines the five Trust Services Criteria categories, Security, Availability, Processing Integrity, Confidentiality, and Privacy, it determines what a CPA firm actually evaluates when it conducts a SOC 2 attestation. Without a common set of criteria, SOC 2 reports would lack the consistency that allows customers, prospects, and their auditors to compare service organizations and place reliance on the resulting reports. Understanding that Security (the Common Criteria) is the only required category, while the other four are selected based on scope, is essential to reading any SOC 2 report accurately.

Who it's relevant to

Compliance and GRC managers
Those preparing for a SOC 2 examination use TSP Section 100 to scope which Trust Services Criteria categories apply and to map internal controls to the relevant criteria. Because Security is the only required category and the other four are optional based on scope, this document helps them make defensible scoping decisions before engaging a CPA firm.
CPA firms and SOC 2 practitioners
Practitioners performing SOC 2 (and, where applicable, SOC 3) engagements evaluate a service organization's controls against the criteria in TSP Section 100. They also draw on the accompanying points of focus, which illustrate characteristics that may be considered but are not themselves requirements, and whose application varies by engagement.
Auditors and customers relying on SOC 2 reports
Readers who rely on a SOC 2 report need to understand which categories from TSP Section 100 were included in scope, since a report attests only to the controls and criteria covered. A report addressing only Security differs materially from one that also includes Availability, Confidentiality, Processing Integrity, or Privacy.
Security engineers designing controls
Engineers translating criteria into technical and operational controls use TSP Section 100 to understand what each category is intended to address. Note that these Trust Services Criteria are distinct from ISO/IEC 27001 Annex A reference controls, so a control designed for one framework does not automatically satisfy the other.

Inside TSP Section 100

Trust Services Criteria (TSC)
TSP Section 100 is the AICPA publication that sets out the Trust Services Criteria used to evaluate controls in SOC 2 (and SOC 3) engagements. The criteria are organized into categories against which a service organization's controls are examined.
Security category (Common Criteria)
The Security category, expressed as the Common Criteria, is the only required category in a SOC 2 examination. It forms the baseline that every SOC 2 engagement must address regardless of scope.
Optional categories
Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on the scope of the engagement. They are added to the Security baseline depending on the service organization's commitments and the users' needs.
Basis for a SOC 2 examination
The criteria provide the framework a licensed CPA firm uses when performing a SOC 2 attestation examination under the AICPA SSAE 18 standard, whether evaluating suitability of design (Type I) or design and operating effectiveness over a period (Type II).

Common questions

Answers to the questions practitioners most commonly ask about TSP Section 100.

Is TSP Section 100 the same as the ISO 27001 Annex A control set?
No. TSP Section 100 contains the Trust Services Criteria used in SOC 2 examinations, which are organized around the Common Criteria (Security) plus the optional categories of Availability, Processing Integrity, Confidentiality, and Privacy. These are distinct from ISO 27001's Annex A reference controls, which are selected through a Statement of Applicability. The two sets can be partially mapped to one another, but they are structured differently and satisfying one does not automatically satisfy the other.
Do I have to address every Trust Services Category in TSP Section 100 for a SOC 2 report?
No. Only the Security category (the Common Criteria) is required in a SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are typically included based on scoping decisions relevant to your service and customer commitments. The categories addressed are set during scoping rather than being universally mandatory.
How do I decide which Trust Services Categories to include in scope?
In most engagements, the categories are selected based on the nature of the service, the commitments made to customers, and applicable requirements. Security is always included as the Common Criteria, while Availability, Processing Integrity, Confidentiality, and Privacy are added when relevant to what you deliver. Scoping decisions are typically made in consultation with the CPA firm performing the examination.
How do the criteria in TSP Section 100 relate to the difference between a Type I and Type II report?
The same Trust Services Criteria apply to both report types, but they are evaluated differently. A Type I report assesses the suitability of design of controls against the applicable criteria at a point in time, while a Type II report assesses both design and operating effectiveness of those controls over a defined review period. The length of that period varies and is set through scoping rather than being fixed.
How do we map our existing controls to the Trust Services Criteria?
Organizations typically map their controls to the applicable criteria in the selected categories, documenting how each control addresses the relevant points of focus. The CPA firm performing the examination evaluates whether the controls, as described and (for Type II) as operated over the period, meet the criteria. The specific mapping approach depends on the environment, scope, and auditor judgment.
Does meeting the criteria in TSP Section 100 guarantee we won't experience a security breach?
No. A SOC 2 report attests only to the controls and the period covered by the examination against the applicable Trust Services Criteria. It does not guarantee freedom from breaches, nor does it cover controls, systems, or time periods outside the defined scope. It reflects the auditor's evaluation within those boundaries rather than an absolute assurance of security.

Common misconceptions

All five Trust Services Criteria categories must be included in every SOC 2 report.
Only the Security category (the Common Criteria) is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are selected based on the scope of the specific engagement.
The Trust Services Criteria are equivalent to, or interchangeable with, ISO 27001 Annex A controls.
The Trust Services Criteria belong to the SOC 2 attestation framework under the AICPA, while Annex A lists reference controls selected via a Statement of Applicability within an ISO 27001 ISMS. Mapping between them is possible but partial, and they should not be conflated.
Meeting the Trust Services Criteria in a SOC 2 report guarantees an organization is free from security breaches.
A SOC 2 report attests only to the controls and, for a Type II, the review period covered by the examination. It does not guarantee freedom from breaches or cover matters outside the defined scope and criteria.

Best practices

Confirm that the Security category (Common Criteria) is addressed as the required baseline before considering any additional categories.
Select optional categories (Availability, Processing Integrity, Confidentiality, Privacy) deliberately, based on the engagement scope and the commitments made to report users, rather than including all by default.
Coordinate scoping decisions with the licensed CPA firm performing the examination so the applicable criteria and, for a Type II, the review period are clearly defined.
Document the boundaries of the examination so readers understand that the report covers only the controls and period addressed and does not extend to matters outside that scope.
Keep the Trust Services Criteria distinct from ISO 27001 Annex A controls when maintaining both frameworks, treating any cross-framework mapping as partial rather than automatic.
Verify whether the engagement is a SOC 2 (versus SOC 1 or SOC 3) so the correct criteria and reporting format are applied to the intended audience.