AICPA Trust Services Criteria (2017)
Overview of AICPA Trust Services Criteria
The AICPA Trust Services Criteria (TSC) represents the foundation for SOC 2 and SOC 3 attestation engagements, providing standardized criteria for evaluating controls relevant to security, availability, processing integrity, confidentiality, and privacy. Published by the American Institute of Certified Public Accountants (AICPA) in 2017, the Trust Services Criteria enables service organizations to demonstrate the effectiveness of their controls to customers, regulators, and business partners through independent CPA attestation.
The 2017 update consolidated and streamlined previous trust services principles and criteria, creating a more cohesive framework that addresses modern technology and business models including cloud computing, software-as-a-service (SaaS), and managed service providers. The Trust Services Criteria has become the de facto standard for technology and service provider assurance, with thousands of organizations pursuing SOC 2 reports annually to satisfy customer due diligence requirements and differentiate themselves in competitive markets.
The Five Trust Service Categories
The Trust Services Criteria organizes control requirements into five categories, with Security serving as the foundation required for all SOC 2 engagements, and the other four categories selected based on the services provided and commitments made to customers.
Security (Common Criteria)
The Security category is required for all SOC 2 reports and addresses controls that protect system resources against unauthorized access, use, disclosure, disruption, modification, or destruction. Security controls span organizational governance, risk assessment, logical and physical access controls, system operations, change management, and security incident management. Organizations must demonstrate comprehensive security programs including documented policies, defined responsibilities, employee background checks, access provisioning and deprovisioning processes, security monitoring, vulnerability management, and incident response capabilities.
The Security criteria establishes nine common criteria categories: organization and management (CC1), communication and information (CC2), risk assessment (CC3), monitoring activities (CC4), control activities (CC5), logical and physical access controls (CC6), system operations (CC7), change management (CC8), and risk mitigation (CC9). These common criteria form the foundation upon which the additional trust service categories build.
Availability
The Availability category addresses controls ensuring systems and data are available for operation and use as committed or agreed. Organizations pursuing Availability criteria must demonstrate redundancy, backup and recovery capabilities, capacity planning, system monitoring, and incident management processes that minimize downtime. Availability criteria typically apply to organizations providing services with defined service level agreements (SLAs) or uptime commitments.
Control objectives include availability of systems for operation, monitoring of system capacity and performance, implementation of backup and disaster recovery procedures, and environmental protections against physical threats like fire, flood, or power failure. Organizations should track availability metrics, conduct disaster recovery testing, and demonstrate that commitments to customers are met consistently.
Processing Integrity
Processing Integrity criteria ensure that system processing is complete, valid, accurate, timely, and authorized to meet the entity's objectives. This category addresses quality and accuracy of data processing rather than security or confidentiality. Organizations processing financial transactions, healthcare data, or other information requiring accuracy and completeness typically include Processing Integrity in their SOC 2 reports.
Control objectives cover input validation, processing controls to ensure accuracy and completeness, output verification, error detection and correction procedures, and monitoring of processing activities. Organizations must demonstrate controls over data integrity throughout the processing lifecycle, from input through output, and maintain audit trails that enable verification of processing accuracy.
Confidentiality
The Confidentiality category addresses protection of information designated as confidential, which is a subset of all information requiring security protection. While Security protects all information, Confidentiality specifically addresses information that organizations have contractually or legally committed to protect beyond basic security requirements. This typically includes customer data, intellectual property, financial information, and proprietary business information.
Control objectives include identification and classification of confidential information, protection of confidential data during storage and transmission through encryption, access restrictions based on need-to-know principles, secure disposal of confidential information, and contractual commitments with third parties handling confidential data. Organizations must define what constitutes confidential information, implement appropriate technical and procedural controls, and demonstrate compliance with confidentiality commitments.
Privacy
The Privacy category addresses personal information collection, use, retention, disclosure, and disposal in conformity with the entity's privacy notice and with criteria set forth in Generally Accepted Privacy Principles (GAPP). This category is essential for organizations collecting or processing personally identifiable information (PII) or protected health information (PHI). Privacy requirements have gained prominence with regulations like GDPR, CCPA, and HIPAA creating compliance obligations.
Control objectives encompass notice of privacy practices provided to data subjects, choice and consent regarding personal information collection and use, collection practices limited to necessary information, use and retention according to stated purposes, access rights enabling individuals to review and correct their information, disclosure practices consistent with privacy notices, security controls protecting personal information, quality controls ensuring accuracy, and monitoring and enforcement of privacy commitments. Organizations must maintain privacy policies, implement privacy-by-design principles, respond to data subject requests, and demonstrate compliance with applicable privacy regulations.
Framework Applicability and Adoption
The Trust Services Criteria applies primarily to technology and service organizations providing services to other entities, including SaaS providers, cloud infrastructure providers, managed service providers, data centers, payment processors, and business process outsourcers. Organizations pursue SOC 2 reports to satisfy customer due diligence requirements, support sales processes, meet contractual obligations, demonstrate compliance with industry standards, and differentiate themselves competitively.
SOC 2 Type II reports (examining control effectiveness over a period, typically 6-12 months) have become standard requirements in technology vendor evaluations. Enterprises increasingly require SOC 2 reports from vendors processing sensitive data, with many refusing to engage vendors lacking appropriate attestations. Organizations serving healthcare, financial services, government, or other regulated industries face particularly strong expectations for SOC 2 compliance.
SOC 2 vs SOC 3 Reports
The Trust Services Criteria underpins two primary report types: SOC 2 and SOC 3. SOC 2 reports provide detailed descriptions of the organization's systems, control objectives, control activities, test procedures performed by auditors, and results. These reports are restricted-use documents shared only with parties having sufficient understanding to evaluate controls (customers, regulators, business partners). SOC 2 Type I reports evaluate control design at a point in time, while SOC 2 Type II reports evaluate both design and operating effectiveness over a specified period.
SOC 3 reports provide general-use attestations suitable for public disclosure, containing the auditor's opinion without detailed descriptions of testing procedures or results. Organizations often display SOC 3 seals on websites to demonstrate independent validation of controls. SOC 3 reports are based on the same Trust Services Criteria as SOC 2 but provide less detail, making them appropriate for general marketing purposes but insufficient for detailed vendor risk assessments.
Implementation Strategies and Best Practices
Achieving SOC 2 compliance requires systematic control implementation, comprehensive documentation, and organizational commitment to maintaining control effectiveness. Organizations should approach SOC 2 preparation strategically, investing in foundational capabilities that support both compliance and operational excellence.
Conduct Readiness Assessments: Before engaging SOC 2 auditors, conduct internal readiness assessments to identify control gaps and remediation priorities. Many organizations engage consultants or use automated compliance platforms to perform gap analyses against Trust Services Criteria. Readiness assessments should evaluate policies, procedures, technical controls, and evidence availability. Addressing identified gaps before formal audits reduces costly audit findings and enables smoother examinations.
Select Appropriate Trust Service Categories: Organizations should select trust service categories based on services provided and commitments to customers. Security is always required. Availability applies when providing services with uptime commitments. Processing Integrity applies when processing accuracy is critical. Confidentiality applies when handling customer confidential information. Privacy applies when collecting or processing personal information. Over-scoping (including unnecessary categories) increases audit costs and ongoing compliance burden without adding value.
Implement Comprehensive Documentation: SOC 2 audits require extensive documentation including policies, procedures, system descriptions, control matrices, risk assessments, and evidence of control operation. Organizations should create centralized repositories for compliance documentation, implement version control, and establish regular review and update processes. Documentation should be clear, complete, and readily accessible to auditors and internal stakeholders. Well-organized documentation significantly reduces audit duration and cost.
Automate Evidence Collection: Manual evidence collection for SOC 2 audits consumes substantial staff time and introduces human error risk. Implement automated evidence collection through security information and event management (SIEM) systems, identity and access management (IAM) platforms, change management tools, and GRC (governance, risk, and compliance) platforms. Automation ensures complete, consistent evidence and reduces the burden of periodic audits. Many cloud-based security and compliance platforms provide built-in SOC 2 evidence collection capabilities.
Establish Continuous Control Monitoring: Rather than treating SOC 2 as an annual event, implement continuous control monitoring that identifies control failures immediately. Automated monitoring enables rapid remediation before issues accumulate and reduces surprise findings during audits. Continuous monitoring also supports security and operational improvements beyond compliance obligations. Organizations with mature monitoring often achieve better audit outcomes and experience fewer security incidents.
Plan for Type I Then Type II: Organizations new to SOC 2 should consider pursuing Type I reports initially to validate control design before undergoing Type II examinations of operating effectiveness. Type I assessments are less expensive and time-consuming, allowing organizations to address design issues before committing to multi-month Type II examinations. However, customers often require Type II reports, so organizations should plan transitions to Type II within 6-12 months of achieving Type I.
Relationship to Other Frameworks and Standards
The Trust Services Criteria aligns with and complements various cybersecurity and privacy frameworks. Organizations implementing ISO 27001 will find significant overlap in security controls, though ISO 27001 provides more comprehensive risk management context while Trust Services Criteria focus on service organization commitments. Many organizations pursue both ISO 27001 certification and SOC 2 reports, leveraging common control implementations for both.
The NIST Cybersecurity Framework maps well to Trust Services Criteria Security and Availability categories, with NIST CSF providing strategic risk management guidance and TSC providing detailed control criteria. Organizations can demonstrate NIST CSF implementation through SOC 2 reports that document specific controls aligned with CSF subcategories. Similarly, CIS Controls provide prescriptive technical control implementation guidance that satisfies many Trust Services Criteria requirements.
For privacy-specific requirements, Trust Services Criteria Privacy aligns with NIST Privacy Framework and supports compliance with GDPR, CCPA, HIPAA, and other privacy regulations. Organizations can reference related frameworks including PCI DSS for payment card data, HIPAA for healthcare information, and NIST SP 800-171 for controlled unclassified information.
Common Challenges and Solutions
Organizations pursuing SOC 2 compliance encounter predictable challenges related to documentation, evidence collection, resource constraints, and maintaining ongoing compliance. Understanding common pitfalls enables proactive mitigation.
Documentation Gaps: Many organizations lack formal policies, procedures, and system documentation required for SOC 2 audits. Auditors expect comprehensive, current documentation that accurately reflects actual practices. Address documentation gaps early in SOC 2 preparation by creating policy templates, documenting procedures as implemented, and establishing regular review processes. Documentation should reflect reality—avoid creating policies that don't match actual practices, as auditors will identify inconsistencies through testing.
Evidence Collection Burden: Manual evidence collection for quarterly or annual audits consumes substantial time. Organizations struggle to locate historical evidence, particularly for controls examined over 6-12 month periods. Implement automated logging and evidence collection from the start of the audit period to avoid retrospective scrambling. Designate clear ownership for evidence collection and establish regular evidence review processes that identify gaps before auditor requests.
Scope Definition Challenges: Organizations often struggle to define appropriate scope for SOC 2 reports, particularly in complex environments with multiple systems and services. Work closely with auditors during scoping to ensure reports cover relevant systems and services without unnecessary expansion. Clearly define system boundaries, document dependencies on third parties, and identify carve-outs (excluded components). Scope changes mid-audit are costly and disruptive—invest time in proper scoping upfront.
Third-Party Risk Management: Service organizations rely on subservice organizations (cloud providers, infrastructure providers, security service providers) whose controls impact the organization's control environment. Organizations must either obtain SOC 2 reports from subservice organizations or implement complementary user entity controls (CUECs). Identify all critical third parties early, ensure current SOC 2 reports are available, and map third-party controls to Trust Services Criteria to identify gaps requiring compensating controls.
Resource Constraints: SOC 2 preparation and audit support require substantial staff time, particularly during initial implementations. Small organizations often lack dedicated compliance personnel, forcing operational staff to balance compliance with regular responsibilities. Consider engaging external consultants for initial implementations to accelerate readiness, establish sustainable processes, and transfer knowledge to internal teams. Automated compliance platforms can also reduce ongoing resource requirements.
Frequently Asked Questions
What is the difference between SOC 1 and SOC 2?
SOC 1 reports address controls relevant to financial reporting and are used primarily by organizations that process financial transactions on behalf of clients (payroll processors, transaction processors). SOC 2 reports based on Trust Services Criteria address broader security, availability, processing integrity, confidentiality, and privacy controls relevant to all service organizations. Most technology service providers pursue SOC 2 rather than SOC 1, while SOC 1 remains relevant for financial services organizations.
How long does it take to achieve SOC 2 compliance?
Organizations new to SOC 2 typically require 6-12 months to implement controls, develop documentation, establish evidence collection processes, and prepare for audits. Type I examinations can then be completed in 4-8 weeks once organizations are ready. Type II examinations require controls to operate effectively for a defined period (typically 6-12 months) plus 4-8 weeks for audit fieldwork. Organizations with mature security programs may accelerate timelines, while those with significant control gaps may require longer preparation periods.
Do we need SOC 2 Type I or Type II?
Most customers and prospects prefer SOC 2 Type II reports that demonstrate controls operated effectively over time rather than Type I reports examining design at a single point in time. Type II provides greater assurance and is typically required for enterprise customers, regulated industries, and competitive differentiation. However, Type I can be valuable for initial validation before pursuing Type II or for demonstrating progress to prospects while preparing for Type II. Organizations should pursue Type I only as a stepping stone to Type II, not as an endpoint.
How often do SOC 2 audits need to be performed?
SOC 2 audits are typically performed annually, with Type II reports covering a 12-month examination period. However, organizations may choose 6-month examination periods to provide more frequent updates to customers. SOC 2 reports remain current for the examination period plus a reasonable time for report issuance (typically 1-2 months), so most organizations maintain continuous coverage through annual or semi-annual audits. Gap periods without current reports can impact sales processes and customer relationships, making consistent audit schedules important.