What Are the 5 SOC 2 Criteria? A Complete Guide

A SOC 2 examination does not begin with five boxes waiting to be checked. It begins with a much harder question: What can your organization demonstrate about the way it operates? A company may have MFA enabled across its environment, documented incident response procedures, tested backups, data classification policies, and access reviews. But those individual controls only become meaningful when they can be connected to the risks they are intended to address and the commitments the organization makes to its customers.
The five SOC 2 Trust Services Criteria provide the lens through which those controls are evaluated. Security, Availability, Processing Integrity, Confidentiality, and Privacy offer the foundation for evaluating whether an organization's controls address the areas that matter to its customers and stakeholders. The AICPA's Trust Services Criteria provide the basis for evaluating controls across these five areas.
This article breaks down all five SOC 2 criteria, explains what each means in practice, and explores how organizations can connect them to controls, evidence, and audit preparation.
What Are the 5 Criteria for SOC 2?
The AICPA's 2017 Trust Services Criteria, with revised Points of Focus issued in 2022, provide the criteria used to evaluate controls over security, availability, processing integrity, confidentiality, and privacy. However, organizations do not necessarily need to include all five criteria in every SOC 2 examination. Security is the common criterion, while the other four are included based on the nature of the organization's services, commitments, risks, and system. A clear understanding of these principles helps organizations focus their compliance efforts where they matter most and build confidence before an audit.
Security
Security is the foundation of a SOC 2 examination. It focuses on whether systems are protected against unauthorized access, use, modification, destruction, disclosure, and other unauthorized activities. This can involve identity and access management, authentication, MFA, privileged access, change management, vulnerability management, security monitoring, incident response, risk assessment, and physical and logical access controls.
For example, a U.S.-based SaaS company may require MFA for administrative accounts, conduct periodic access reviews, perform vulnerability scans, maintain incident response procedures, and require approval for production changes. However, documenting these controls is only part of the process. The organization must also demonstrate how controls are designed and, depending on the examination type, how they operated during the relevant period.
A corporate compliance risk assessment helps connect these controls to specific risks by identifying what could go wrong, which controls address those risks, who owns them, and what evidence demonstrates their operation.
Availability
Availability addresses whether systems are available for operation and use as committed or agreed. It goes beyond simply keeping a website online and can include customer commitments, business continuity, disaster recovery, infrastructure resilience, system monitoring, and incident response.
A cloud software provider, for example, may use uptime monitoring, backup and restoration procedures, disaster recovery plans, infrastructure redundancy, capacity monitoring, and recovery testing to meet its availability commitments. From a business leadership perspective, the key consideration is operational resilience: strong security controls cannot prevent significant business disruption if critical systems cannot be restored after an outage.
Processing Integrity
Processing Integrity addresses whether system processing is complete, valid, accurate, timely, and authorized. It is particularly relevant to organizations that rely on automated systems to perform important business processes.Consider a SaaS platform that automatically calculates customer invoices. Controls may include input validation, defined processing rules, error detection, exception handling, transaction reconciliation, output validation, and change controls over processing logic. The underlying question is whether the organization can demonstrate that its systems consistently produce the results they are designed to produce. This makes Processing Integrity an important consideration within a broader compliance audit and risk assessment process.
Confidentiality
Confidentiality focuses on protecting information that an organization has designated as confidential. This may include customer contracts, source code, intellectual property, product plans, internal financial information, and proprietary business information. Controls can include data classification, access restrictions, encryption, secure transmission, retention requirements, and secure disposal.
Confidentiality should not be confused with Privacy. Confidentiality protects information designated as confidential, while Privacy focuses on the appropriate handling of personal information. For example, a proprietary product roadmap may be confidential without containing personal information. Understanding this distinction is important when developing a compliance risk management framework for companies, as different information types may require different controls and evidence.
Privacy
Privacy addresses the organization's handling of personal information. Where the Privacy criterion is included in a SOC 2 examination, relevant controls may cover the collection, notice, use, retention, disclosure, access, disposal, and third-party sharing of personal information. The AICPA provides specific privacy criteria and considerations for SOC 2 examinations that include Privacy.
For example, a U.S.-based SaaS provider may establish controls governing what personal information it collects from customer employees, why it is collected, how it is used and retained, who can access it, and how it is ultimately disposed of. However, SOC 2 does not replace applicable privacy laws. A U.S. organization operating internationally may need to assess jurisdiction-specific obligations separately, including regulatory compliance risk management India requirements where relevant.
Need a Trusted SOC 2 Audit Partner?Strengthen customer confidence with an independent SOC 2 examination from INTERCERT.
Are All 5 SOC 2 Criteria Mandatory?
No. This is one of the most important points for organizations beginning their SOC 2 journey. Security is the common criterion, while Availability, Processing Integrity, Confidentiality, and Privacy are included when they are relevant to the organization's services, systems, commitments, and risks.
For example, a cloud SaaS provider may include Security, Availability, and Confidentiality because customers depend on the protection and availability of its platform and data. A transaction-processing platform may place greater emphasis on Security, Availability, and Processing Integrity because accurate and reliable processing is central to its service. An organization that handles substantial amounts of personal information may also include the Privacy criterion.
The goal is not to select all five criteria simply because a broader scope may appear more comprehensive. Instead, organizations should determine which criteria provide meaningful assurance over the systems and services their customers rely on. This risk-based approach is consistent with how a risk based compliance program should operate, with controls and assurance activities aligned to actual business risks and obligations rather than treated as disconnected compliance checkboxes.
SOC 2 Criteria vs. Controls: What's the Difference?
One of the most common sources of confusion when preparing for SOC 2 is treating criteria and controls as the same thing. They serve different purposes. Criteria describe what is being evaluated, controls describe what the organization does to address relevant risks and objectives, and evidence demonstrates how those controls operated.
For example, under the Security criterion, an organization may identify unauthorized privileged access as a risk. To address it, the organization may implement a quarterly privileged-access review. The completed access review records and documentation showing that identified issues were remediated then provide evidence that the control operated as intended.
This distinction is particularly important when preparing for an audit. An organization may have extensive policies and documented procedures but still face challenges if it cannot demonstrate that its controls operate consistently. The AICPA's SOC 2 guidance addresses the evaluation of control design and operating effectiveness against the applicable Trust Services Criteria.
How the 5 Criteria Affect Audit Preparation
Understanding the five SOC 2 criteria is only the starting point. The real challenge is determining how they apply to the organization's systems, risks, controls, and customer commitments and doing this before the auditor begins requesting evidence. Business leaders can approach audit preparation by working through five fundamental questions:
What Systems Are in Scope?
Define the services, applications, infrastructure, people, processes, and system boundaries that support the services being examined. A clearly defined scope helps prevent confusion about which systems and controls fall within the examination.
Which Criteria Are Relevant?
Determine which Trust Services Criteria apply based on customer commitments, business risks, the nature of the services provided, and the information the organization handles. Not every organization needs all five criteria.
What Controls Already Exist?
Identify the technical, operational, and governance controls already in place and evaluate whether they adequately address the relevant risks. This can include access controls, monitoring, incident response, change management, backup procedures, and data protection controls.
What Evidence Exists?
Determine whether the organization can demonstrate that its controls operated as intended. Evidence may include access reviews, monitoring records, incident documentation, testing results, approvals, and other records generated through normal business operations.
Where Are the Gaps?
Identify missing controls, inconsistent execution, incomplete evidence, unclear ownership, and unresolved exceptions before the examination begins. Addressing these gaps early can reduce unnecessary delays and audit complications.
This process brings corporate governance and compliance risk directly into SOC 2 preparation. Senior leadership needs visibility into who owns critical controls, how significant risks are managed, and whether compliance activities are embedded into day-to-day operations rather than treated as a separate audit exercise. A structured compliance risk assessment framework can help management connect these elements, prioritize remediation, and establish a clearer path toward audit readiness.
Meet Customer Security Expectations Validate your organization's controls through a trusted SOC 2 audit process.
SOC 2 Type 1 vs. Type 2: Why It Matters
The distinction between SOC 2 Type 1 and Type 2 is important when preparing for an examination. A Type 1 examination evaluates whether controls are suitably designed and implemented as of a specified date, while a Type 2 examination goes further by evaluating whether those controls operated effectively over a specified period. The AICPA's SOC 2 guidance addresses both control design and operating effectiveness in relation to the applicable Trust Services Criteria.
For business leaders, the practical lesson is straightforward: a control that exists on paper is not necessarily a control that consistently operates. If an access review is required every quarter, for example, the organization should be able to demonstrate that the reviews were actually performed, that appropriate personnel completed them, and that any identified issues were addressed. This makes consistent control execution and reliable evidence essential when preparing for a Type 2 examination.
Common Mistakes When Preparing for SOC 2
Preparing for a SOC 2 examination is not simply about collecting policies and responding to an auditor's requests. Organizations can encounter avoidable challenges when they approach the process as a documentation exercise rather than as an evaluation of how their controls operate in practice.
Treating SOC 2 as a Cybersecurity Checklist
SOC 2 is broader than cybersecurity. While Security is the common criterion, an examination may also address Availability, Processing Integrity, Confidentiality, and Privacy. Limiting preparation to security controls can leave important areas of the organization's control environment unaddressed.
Selecting Criteria Without Considering Business Risks
The applicable criteria should reflect the organization's services, customer commitments, information handled, and business risks. Selecting criteria simply because they are commonly included in other SOC 2 examinations can result in an unnecessarily broad or poorly aligned scope.
Focusing on Policies Instead of Control Operation
Policies establish expectations, but they do not demonstrate that those expectations are being followed. Organizations should be able to show evidence that controls are consistently performed, reviewed, and addressed when exceptions occur.
Waiting Until the Audit to Identify Evidence Gaps
Evidence should be considered when controls are designed and operated, not when the auditor requests it. Identifying missing records, incomplete reviews, or inconsistent documentation early gives the organization time to correct the underlying issue rather than scrambling to recreate evidence.
Treating Compliance as an Annual Exercise
SOC 2 audit preparation should not depend on a once-a-year push to update documents and gather records. A strong compliance risk management framework for companies provides ongoing visibility into control performance, ownership, risks, and evidence, allowing organizations to address issues before they become audit findings.
SOC 2 as a Foundation for Business Trust
A strong SOC 2 program is not defined by the number of policies an organization has, the security tools it operates, or the number of controls listed in a compliance register. Its strength is reflected in how clearly those controls connect to business risks, customer commitments, and the evidence needed to demonstrate that they operate as intended.
The five Trust Services Criteria provide the structure for making that connection. But understanding Security, Availability, Processing Integrity, Confidentiality, and Privacy is only the beginning. For U.S. businesses preparing for a SOC 2 examination, the greater priority is building a control environment where responsibilities are clear, risks are actively monitored, controls operate consistently, and evidence is generated as part of normal business operations.
This is also where the right certification body can make a difference. As an independent third-party certification and assurance organization, INTERCERT brings an objective perspective to the examination process, with experienced professionals who evaluate controls against applicable SOC 2 criteria and established professional standards.
SOC 2 should not be viewed as a finish line that an organization reaches once an audit report is issued. It is an opportunity to demonstrate that trust is built into the way the business operates.