SOC 2 Trust Service Criteria Explained | Certifyi
SOC 2

SOC 2 Trust Service Criteria explained (and which to include)

6 min read · Certifyi research team · Updated July 2026

Short answer

There are five Trust Service Criteria. Security is mandatory and is known as the common criteria. Availability, Confidentiality, Processing Integrity and Privacy are optional and should be included only where you make a real commitment to customers. Most SaaS companies scope Security, Availability and Confidentiality.

Security: the common criteria

Security is in scope for every SOC 2 engagement. It covers protection against unauthorised access, both logical and physical, and maps to the bulk of what people think of as a security programme: access control, change management, risk assessment, monitoring, incident response and vendor oversight.

Availability

Availability addresses whether the system is available for operation and use as committed. Include it when you publish an SLA or your customers care about uptime.

Expect to evidence monitoring, capacity planning, backup, and a tested disaster recovery process. Backups that have never been restore-tested are a frequent finding.

Confidentiality

Confidentiality covers information designated as confidential, typically under NDA or contract. Include it when you hold customer data that carries contractual confidentiality obligations, which for most B2B SaaS is true.

Evidence centres on classification, access restriction, encryption and defined retention and disposal.

Processing Integrity

Processing Integrity concerns whether system processing is complete, valid, accurate, timely and authorised. It matters if you move money, calculate payroll, process claims or produce outputs customers rely on numerically.

Most pure SaaS products do not need it. Fintech, payroll and billing platforms usually do.

Privacy

Privacy addresses collection, use, retention, disclosure and disposal of personal information against your own privacy notice. It overlaps with GDPR work but is not the same thing.

Include it when you handle personal data directly rather than purely on behalf of a business customer.

How to choose without over-scoping

Scope is a commercial decision, not a maturity badge. Each added criterion increases evidence volume, audit hours and fee.

  1. List what you actually promise in contracts, SLAs and your privacy notice.
  2. Ask your three largest prospects what their security review requires.
  3. Include a criterion only if it appears in one of the above.
  4. Revisit at each annual cycle rather than trying to predict years ahead.

Key takeaways

  • Security is mandatory; the other four are elective.
  • Most SaaS scope Security, Availability and Confidentiality.
  • Processing Integrity is for transaction and calculation-heavy products.
  • Every added criterion costs evidence, hours and audit fee.

Frequently asked questions

Can we add a criterion later?

Yes. Criteria are chosen per engagement, so you can expand scope at the next annual cycle as customer demands change.

Does Privacy replace GDPR compliance?

No. The Privacy criterion tests you against your own stated privacy commitments. GDPR is a legal regime with separate obligations.

Which criteria do enterprise buyers ask for most?

Security is assumed. Availability and Confidentiality are the two most commonly requested additions in B2B SaaS security reviews.

Does more criteria mean a better report?

No. It means a broader report. A clean Security-only report reads better than a broad report with exceptions.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.

Book a 20-min deal readiness call

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top