AICPA Trust Services Criteria
The AICPA Trust Services Criteria are a set of standards developed by the American Institute of Certified Public Accountants (AICPA) used to evaluate the controls an organization has in place around its systems and data. They cover five areas: security, availability, processing integrity, confidentiality, and privacy. These criteria form the basis for SOC 2 and SOC 3 examinations that report on how well a service organization manages these areas.
The Trust Services Criteria (TSC) are the control criteria established by the AICPA, most recently published as the 2017 Trust Services Criteria with Revised Points of Focus (2022), against which controls are evaluated in SOC 2 and SOC 3 engagements. The framework is organized into five categories, Security (the common criteria, which is required), Availability, Processing Integrity, Confidentiality, and Privacy, with the applicable categories selected based on the scope of the examination and the commitments a service organization makes to its stakeholders. A virtual CISO may support readiness against these criteria by advising on control design, gap assessment, and evidence preparation, but the criteria themselves are evaluated by an independent CPA or licensed firm in an attestation engagement; supporting readiness is distinct from the issuance of a SOC report, which only the examining practitioner can produce. Accountability for implementing and maintaining the underlying controls remains with the client organization.
Why it matters
The Trust Services Criteria are the backbone of SOC 2 and SOC 3 reporting, which have become common expectations in vendor risk assessments and procurement due diligence, particularly for service organizations handling customer data. When a prospective customer asks a SaaS vendor or managed service provider for a SOC 2 report, they are effectively asking for independent assurance that the organization's controls have been evaluated against these criteria. For many organizations, readiness against the TSC is therefore less a purely internal compliance goal and more a prerequisite for closing deals and maintaining trust with enterprise customers.
The criteria matter because they impose a structured way of thinking about controls across five distinct areas, security, availability, processing integrity, confidentiality, and privacy, rather than treating security as a single undifferentiated concern. Security, which the AICPA designates as the common criteria, is required in every SOC 2 examination, while the other four categories are selected based on the scope of the engagement and the commitments an organization has made to its stakeholders. This scoping decision has real consequences: an organization that promises high uptime may need to include Availability, while one processing regulated personal data may need Privacy. Misunderstanding which categories apply can lead to reports that do not address what customers actually care about.
A critical distinction that experienced practitioners insist on is that supporting readiness against the TSC is not the same as producing a SOC report. A virtual CISO can advise on control design, run gap assessments, and help prepare evidence, but only an independent CPA or licensed firm can perform the attestation engagement and issue the report. Treating a readiness engagement as if it guarantees a clean SOC report, or conflating advisory support with the examination itself, is a common and consequential mistake.
Who it's relevant to
Inside TSC
Common questions
Answers to the questions practitioners most commonly ask about TSC.