A SOC 2 report is based on the AICPA Trust Services Criteria. Those criteria form the framework against which a service organisation's controls are tested. There are five categories, of which Security is always in scope. You choose the other four yourself, and that choice determines how many controls you implement, how much evidence you collect during the observation period and what the report is worth to your customers. Yet the scope is regularly set without looking at customer contracts, or on the assumption that more categories produce a stronger report. Both lead to regret, usually halfway through the observation period.
Security: the common criteria
Security, also known as the common criteria, covers the protection of information and systems against unauthorised access and abuse, both physical and logical. The controls touch governance, risk assessment, access security, network and application security, change management, monitoring and incident handling.
In practice this category is not optional. The other four each add criteria on top of this foundation, so without the common criteria there is nothing to build on. For many organisations, Security alone is also the most common scope, certainly in the first audit year.
Availability: include it when you commit to uptime
Availability covers the availability of the system as agreed with customers. The additional criteria touch capacity management, monitoring, backup and recovery, failover and incident management.
The rule of thumb is simple: if you make availability commitments, for example through an SLA with uptime percentages, customers expect the report to say something about it. Whoever includes this category must demonstrate that availability is monitored and that recovery procedures work. A backup process that has never been tested with an actual restore is a classic finding. Vendors of software that customers run themselves can usually leave Availability out without any problem.
Confidentiality: include it when you hold confidential customer data
Confidentiality revolves around information designated as confidential by contract or policy. That goes beyond personal data: trade secrets, intellectual property, financial data and customer source code fall under it too. The criteria require that confidential information is identified, protected throughout its life cycle through classification, encryption and access restriction, and demonstrably deleted or destroyed at the end of it.
For B2B service providers working with customer data this is a logical addition, because many customers read their confidentiality clause and want to see it reflected in the report. Pay particular attention to the deletion side. A commitment such as "we delete your data within thirty days after contract end" must be fulfilled and evidenced, including in backups and at subprocessors. That is where audits go wrong most often.
Processing Integrity: include it when customers rely on your processing
Processing Integrity covers the completeness, accuracy, timeliness and authorisation of processing. The controls include input validation, reconciliations, exception queues with follow-up, and detection and correction of processing errors.
This category becomes relevant as soon as customers rely on the outcome of your processing: payments, payroll, billing, order handling, data pipelines whose output feeds directly into a customer's decisions or reporting. For a classic SaaS application without transaction processing, Processing Integrity adds little. For a payment processor or payroll provider it is exactly the category customers look at first.
Privacy: the heaviest choice
The Privacy category is the most extensive and the most frequently underestimated. The criteria span the full life cycle of personal information: notice to data subjects, purpose limitation, collection, use, retention, disclosure to third parties, quality and data subject rights. Among other things, the criteria test whether you do what your own privacy notice promises. That requires a mature privacy programme, not just technical security.
For European organisations the GDPR already provides a legal framework and customers usually arrange their assurances through data processing agreements. In our practice, Dutch and European buyers rarely ask for the Privacy category, while American customers do so more often. Include Privacy only when customers concretely ask for it and your programme can carry it. Organisations that want to provide privacy assurance without the full category can also consider an ISO 27701 certification or a targeted ISAE 3000 report alongside SOC 2.
How to make the choice in practice
The scoping decision does not start with the criteria but with your commitments. Put three sources side by side. First, your customer contracts and SLAs: what do you promise about security, availability, confidentiality, processing and personal data? Second, the security questionnaires and due diligence requests from prospects: what do they demonstrably ask about? Third, what is customary in your sector, because a payroll processor is held to different expectations than a marketing tool.
Categories that appear in none of the three sources can safely stay out of scope. The scope is set per audit period, so expanding in a later report is always possible. The reverse is more painful: dropping a category that was in scope last year raises questions with customers.
Common mistakes
The most expensive mistake is wanting everything at once. Five categories in the first audit year means implementing and evidencing the maximum number of controls while the organisation is still getting used to the audit cycle. The result is often a report with many findings, and that is commercially more damaging than a narrower scope without them.
The second mistake is the mirror image: including only Security while the SLAs contain hard uptime guarantees. Customers who put the report next to their contract spot the gap immediately.
The third mistake is including Privacy as a sales argument without an underlying programme. Whoever does not have their privacy notice firmly in place mainly buys findings with this category.
What the choice means for lead time and cost
Every additional category means additional criteria, additional controls and additional evidence throughout the entire observation period, and therefore more hours for your own team and for the auditor. The step from Security to Security plus Availability is limited for most organisations, because monitoring and backup are usually already in place. The step to Privacy is by far the largest.
If in doubt, discuss the scoping decision with your auditor during the readiness phase. Per category it then quickly becomes clear which controls already exist and where the real work is. Secure Audit performs SOC 2 audits in accordance with the AICPA standards and helps with scoping up front. Get in touch for a scoping conversation.
Frequently asked questions
Is Security mandatory in every SOC 2 audit?+
In practice, yes. Security consists of the common criteria, the shared foundation on which the other categories build. A SOC 2 report without Security does not occur in practice; the other four categories are additions on top of it.
How many Trust Services Criteria should I include?+
As many as your services and customer commitments justify, and no more. For many SaaS providers, Security plus Availability is a logical starting point, often complemented with Confidentiality. Add Processing Integrity and Privacy when transaction processing or commitments about personal data call for them.
Can I add criteria to my SOC 2 report later?+
Yes. The scope is set per audit period, so you can add or drop categories in a subsequent report. Many organisations start narrow and expand once customers ask for it. Do inform your auditor of a scope change in time, because additional criteria mean additional controls and evidence throughout the entire observation period.
Does a broader report make my SOC 2 more valuable to customers?+
Only if the additional categories match what your customers actually buy from you. A Privacy category without a mature privacy programme mainly produces findings, and a report full of exceptions inspires less confidence than a narrower report without them. Relevance outweighs breadth.
What is the difference between Confidentiality and Privacy?+
Confidentiality covers all information designated as confidential, including trade secrets, source code and financial data. Privacy covers personal information specifically and tests its full life cycle against your own privacy notice. Privacy is therefore the heavier of the two.
Need help with it-audit?
Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.
Explore IT-Audit ServicesAbout the author
Partner | IT Auditor