Skip to main content
Category: Compliance Frameworks & Standards

AICPA Trust Services Criteria

Also known as: TSC, Trust Services Criteria, 2017 Trust Services Criteria, TSC (with Revised Points of Focus – 2022)
Simply put

The AICPA Trust Services Criteria are a set of standards developed by the American Institute of Certified Public Accountants (AICPA) used to evaluate the controls an organization has in place around its systems and data. They cover five areas: security, availability, processing integrity, confidentiality, and privacy. These criteria form the basis for SOC 2 and SOC 3 examinations that report on how well a service organization manages these areas.

Formal definition

The Trust Services Criteria (TSC) are the control criteria established by the AICPA, most recently published as the 2017 Trust Services Criteria with Revised Points of Focus (2022), against which controls are evaluated in SOC 2 and SOC 3 engagements. The framework is organized into five categories, Security (the common criteria, which is required), Availability, Processing Integrity, Confidentiality, and Privacy, with the applicable categories selected based on the scope of the examination and the commitments a service organization makes to its stakeholders. A virtual CISO may support readiness against these criteria by advising on control design, gap assessment, and evidence preparation, but the criteria themselves are evaluated by an independent CPA or licensed firm in an attestation engagement; supporting readiness is distinct from the issuance of a SOC report, which only the examining practitioner can produce. Accountability for implementing and maintaining the underlying controls remains with the client organization.

Why it matters

The Trust Services Criteria are the backbone of SOC 2 and SOC 3 reporting, which have become common expectations in vendor risk assessments and procurement due diligence, particularly for service organizations handling customer data. When a prospective customer asks a SaaS vendor or managed service provider for a SOC 2 report, they are effectively asking for independent assurance that the organization's controls have been evaluated against these criteria. For many organizations, readiness against the TSC is therefore less a purely internal compliance goal and more a prerequisite for closing deals and maintaining trust with enterprise customers.

The criteria matter because they impose a structured way of thinking about controls across five distinct areas, security, availability, processing integrity, confidentiality, and privacy, rather than treating security as a single undifferentiated concern. Security, which the AICPA designates as the common criteria, is required in every SOC 2 examination, while the other four categories are selected based on the scope of the engagement and the commitments an organization has made to its stakeholders. This scoping decision has real consequences: an organization that promises high uptime may need to include Availability, while one processing regulated personal data may need Privacy. Misunderstanding which categories apply can lead to reports that do not address what customers actually care about.

A critical distinction that experienced practitioners insist on is that supporting readiness against the TSC is not the same as producing a SOC report. A virtual CISO can advise on control design, run gap assessments, and help prepare evidence, but only an independent CPA or licensed firm can perform the attestation engagement and issue the report. Treating a readiness engagement as if it guarantees a clean SOC report, or conflating advisory support with the examination itself, is a common and consequential mistake.

Who it's relevant to

Service organizations pursuing SOC 2 or SOC 3
SaaS providers, managed service providers, and other organizations that host or process customer data are the primary audience, since the TSC form the basis for the SOC reports their customers increasingly request during procurement and vendor risk reviews. These organizations use the criteria to structure their control environment and to determine which of the five categories apply to their commitments.
Virtual and fractional CISOs supporting readiness
A vCISO or fractional CISO can add value by advising on control design, conducting gap assessments against the criteria, and helping prepare evidence for examination. It is important to be clear that this readiness support is distinct from the attestation itself, the vCISO advises and directs, but the SOC report can only be issued by an independent CPA or licensed firm, and accountability for the controls remains with the client organization.
Buyers and vendor risk teams
Enterprise customers and procurement functions that evaluate third-party vendors rely on SOC 2 reports built on the TSC to gain independent assurance about a vendor's controls. Understanding which trust services categories a given report covers helps these teams judge whether the report addresses the risks most relevant to their own use of the service.
Security and compliance leaders scoping engagements
Internal security, GRC, and compliance leaders responsible for defining the scope of a SOC 2 examination benefit from the framework's clear separation of the required Security common criteria from the optional Availability, Processing Integrity, Confidentiality, and Privacy categories. The value of any readiness effort depends heavily on scoping the right categories to match organizational commitments and customer expectations.

Inside TSC

Security (Common Criteria)
The foundational category required in every SOC 2 examination, addressing protection of systems and data against unauthorized access, disclosure, and damage. It is the only mandatory Trust Services Category; the others are included based on the service organization's commitments and system scope.
Availability
An optional category addressing whether systems are available for operation and use as committed or agreed, typically relevant where a service organization makes uptime or accessibility commitments to customers.
Processing Integrity
An optional category addressing whether system processing is complete, valid, accurate, timely, and authorized, often relevant for organizations that process transactions on behalf of customers.
Confidentiality
An optional category addressing whether information designated as confidential is protected according to commitments and agreements, distinct from privacy in that it concerns confidential business information rather than personal information.
Privacy
An optional category addressing how personal information is collected, used, retained, disclosed, and disposed of in conformity with the organization's privacy commitments. It is the category most closely tied to personal data handling.
Category selection based on scope
The criteria are applied selectively; a service organization and its stakeholders determine which categories are in scope based on the services provided and commitments made, which is why not every SOC 2 report covers all five categories.

Common questions

Answers to the questions practitioners most commonly ask about TSC.

Does meeting the AICPA Trust Services Criteria mean my organization is certified compliant?
No, and this is a common point of confusion. The Trust Services Criteria are the control criteria against which a SOC 2 examination is conducted; they are not a certification program. A SOC 2 report is an attestation performed by a licensed CPA firm that expresses an opinion on whether controls are suitably designed (Type I) and, for Type II, operating effectively over a period. There is no certificate issued and no governing body that declares an organization certified. Describing yourself as SOC 2 certified is technically inaccurate; the correct framing is that you have undergone a SOC 2 examination and received a report. A virtual CISO can help you prepare for such an examination, but readiness support is distinct from the CPA firm's independent attestation.
Do I have to address all five Trust Services Criteria categories?
Not typically. Only the Security category, often called the common criteria, is required in every SOC 2 examination. The remaining four categories, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and selected based on the commitments your organization makes to customers and the nature of the services you provide. Including categories that are not relevant to your service can add unnecessary scope and effort. Scoping decisions should reflect actual customer commitments and business context, and this is an area where a virtual CISO can advise, though the final scope is usually confirmed with the examining CPA firm. Scope choices vary by organization.
How does a virtual CISO typically support readiness against the Trust Services Criteria?
In many engagements, a virtual CISO helps translate the applicable criteria into a governance and control program, conducts or oversees a readiness assessment or gap analysis, prioritizes remediation, and helps establish the policies, risk management processes, and evidence practices the criteria expect. They generally operate at the strategy, governance, and program-direction level rather than performing hands-on operational tasks such as configuring tools or running monitoring. The value depends heavily on organizational maturity, stakeholder access, and defined scope. The vCISO advises and directs, but accountability for control decisions and the ultimate examination outcome remains with the client organization and its officers.
What is the difference between readiness support and the actual SOC 2 examination?
Readiness support prepares your organization to be examined; the examination is the independent attestation itself. A virtual CISO or consultant can help you design controls, close gaps, and organize evidence against the applicable Trust Services Criteria, but they cannot issue the report. The examination must be performed by a licensed, independent CPA firm, which for independence reasons is generally not the same party that performed extensive readiness or remediation work. Keeping these roles distinct matters, because the CPA firm's independence is central to the credibility of the resulting report.
How do the Trust Services Criteria relate to frameworks like NIST CSF or ISO 27001 that we may already use?
The Trust Services Criteria are outcome-oriented control criteria used specifically for SOC 2 attestation, whereas frameworks such as NIST CSF or ISO 27001 serve broader program and, in the case of ISO 27001, certification purposes. In practice, controls implemented for one often support another, and many organizations map their existing controls to the applicable criteria rather than building separate programs. A virtual CISO can help build this mapping so that a single, coherent control set supports multiple objectives. Mapping reduces duplication but does not guarantee that any one examination or certification requirement is fully satisfied; each has its own evaluation.
What determines whether a readiness effort against the criteria actually succeeds?
Success depends less on the criteria themselves and more on organizational factors: the maturity of existing processes, cooperation from stakeholders across engineering, operations, and leadership, clearly defined scope, and consistent access to the people and evidence needed to demonstrate that controls operate over time. Because SOC 2 Type II examinations evaluate operating effectiveness over a period, sustained execution matters more than one-time preparation. A virtual CISO engagement can direct and structure this work, but outcomes vary by provider and by how well the client organization sustains the controls after the vCISO's guidance.

Common misconceptions

A SOC 2 report based on the Trust Services Criteria is a certification that a virtual CISO engagement can guarantee.
SOC 2 is an attestation examination performed by an independent CPA firm, not a certification, and the outcome depends on the organization's own controls and cooperation. A virtual CISO can typically support readiness and help design and govern controls, but the engagement generally does not guarantee a favorable report or assume accountability for the attestation result, which remains with the service organization.
Every SOC 2 report addresses all five Trust Services Categories.
Only the Security category is required. Availability, Processing Integrity, Confidentiality, and Privacy are optional and included based on the organization's commitments and system scope, so reports vary in which categories they cover.
Meeting the Trust Services Criteria is a purely technical exercise handled by security tools or a managed service provider.
The criteria address governance, risk management, and control design as much as technology. Conflating this work with tool administration or a managed security service provider overlooks the executive-level oversight involved. A virtual CISO advises and directs at the governance level and typically does not perform hands-on operational tasks unless explicitly contracted.

Best practices

Confirm which Trust Services Categories are in scope before beginning work, since Security is required while the other four are optional and driven by organizational commitments and system scope.
Frame the effort as supporting readiness rather than promising a favorable SOC 2 report, and document that legal and organizational accountability for controls remains with the service organization and its officers.
Treat the criteria as a governance and business risk function, not just a technical checklist, ensuring control design, oversight, and evidence practices are addressed alongside technology.
Clarify scope boundaries in the engagement, distinguishing strategy, governance, and control-design guidance from hands-on operational tasks that are typically out of scope unless explicitly contracted.
Recognize that outcomes depend on organizational maturity, client cooperation, and access to stakeholders, and set expectations accordingly rather than implying guaranteed results.
Align internal control descriptions with the specific categories selected so that evidence maps clearly to Security and any optional categories included in the examination.