The SOC 2 Trust Services Criteria: which to include in your first audit
Security is always in a SOC 2. The other four criteria, Availability, Processing Integrity, Confidentiality and Privacy, are optional. For a first audit, include only what you already promise customers in contracts; you can add more at renewal.
What are the five Trust Services Criteria?
Security: protection of systems and data against unauthorised access and damage. Its criteria are often called the common criteria because they apply to every SOC 2.
Availability: whether the system is available for operation and use as committed or agreed, which matters if you promise uptime.
Processing Integrity: whether system processing is complete, valid, accurate, timely and authorised, which matters if customers rely on you to process transactions or calculations.
Confidentiality: protection of information designated as confidential, such as customer business data you agree to keep private.
Privacy: how personal information is collected, used, retained, disclosed and disposed of.
Which criteria should a startup include first?
Start with Security. Add Availability if your contracts include uptime commitments or an SLA. Add Confidentiality if you handle customer data under confidentiality terms, which is common for business software. Processing Integrity and Privacy are usually added when a customer asks for them or when your product's core promise depends on them. Each criterion you add means more controls, more evidence and more audit work.
How do the criteria affect the tool you choose?
Most compliance tools map controls to all five criteria out of the box, so the choice rarely limits your software. What changes is the amount of evidence. If you add Availability, expect evidence about monitoring, backups and incident response to carry more weight. If you add Privacy, expect questions about how personal data flows through your systems.
Can we change the criteria later?
Yes. Each report covers the criteria agreed for that examination. Many companies start with Security, or Security and Confidentiality, and add others when a customer or a new product needs them.
What should we ask customers before deciding?
Ask the customer who requested the report which criteria they need. Security teams often specify them in the security review or the contract. Scoping to what customers actually need keeps the first audit smaller.
What should you read next?
Next lesson · 3 of 10SOC 2 Type I vs Type II: which should a startup do first?
Questions founders ask
Is Security required in SOC 2?
Yes. Every SOC 2 report covers Security; the other four criteria are optional.
Which Trust Services Criteria do most startups choose?
We have no published statistic to cite. In practice, Security alone or Security with Availability and Confidentiality are common first scopes; ask your auditor and your customers.