SOC 2 Trust Services Criteria Explained in Plain English
SOC 2 asks you to prove controls against a published yardstick. Here is what the five trust services criteria cover, which ones you actually need, and how to scope your first report.
By Akam Dasi, Founder and CEO · Published
If a customer, investor or enterprise prospect has asked you for a SOC 2 report, the first thing you run into is a wall of jargon. The SOC 2 trust services criteria sit at the center of that wall. They decide what an auditor looks at, how long the work takes, and how much it costs. This guide explains them in plain English for owners and managers of small and mid-sized businesses, with no accounting background assumed.
Here is the short version. SOC 2 is not a certification and not a law. It is an attestation report written by a licensed CPA firm about the controls you operate. The trust services criteria are the yardstick that firm measures you against.
What the SOC 2 trust services criteria actually are
The criteria are published by the AICPA. The current version is the 2017 Trust Services Criteria with revised points of focus issued in 2022. They cover five categories:
- Security. Information and systems are protected against unauthorized access, unauthorized disclosure and damage.
- Availability. Systems are available for operation and use as committed or agreed.
- Processing integrity. System processing is complete, valid, accurate, timely and authorized.
- Confidentiality. Information designated as confidential is protected as committed or agreed.
- Privacy. Personal information is collected, used, retained, disclosed and disposed of appropriately.
Two things surprise most first-time buyers. First, only the security category is mandatory. Security is often called the common criteria, and every SOC 2 report includes it. The other four are optional and you choose them based on what you promise customers. Second, each criterion comes with points of focus. These are not a checklist you have to satisfy item by item. They are considerations that help you and your auditor decide whether a criterion has been met in your specific environment.
That distinction matters commercially. A vendor that sells you a "SOC 2 checklist" with hundreds of mandatory line items is selling you a product, not the standard.
Which categories should you include?
Adding categories adds cost, evidence and ongoing operational work. Pick them deliberately.
Start with security alone if:
- You are responding to your first enterprise security questionnaire.
- Your contracts do not include uptime commitments backed by penalties.
- You do not process transactions on behalf of customers.
Consider adding availability if you publish an uptime SLA and customers hold you to it. Consider confidentiality if your contracts or NDAs define categories of confidential data you must protect and destroy on schedule. Consider processing integrity if you calculate something customers rely on, such as payroll, billing, claims or order fulfillment. Consider privacy if you act as a controller of personal information rather than simply processing it on a customer's instructions.
A practical rule: include a category only when you can point at a written commitment you already make. If you cannot find the promise in a contract, a service level agreement or your public terms, you probably do not need the category yet.
The other half of the report: description criteria
The trust services criteria describe the controls. A separate set, the 2018 SOC 2 description criteria with revised implementation guidance issued in 2022, governs how you describe your own system in the report.
This is the part small companies underestimate. You write the system description. Your auditor tests it, but the narrative is yours: what the service does, who the users are, what infrastructure and software support it, which subservice organizations you depend on, and which of their controls you assume are working. Cloud providers, payroll platforms and managed IT vendors all show up here.
If you have never written one, budget real time for it. A vague description leads to scope arguments in the middle of fieldwork, and scope arguments are the most common reason a first SOC 2 runs late.
How the criteria turn into an audit
The SOC 2 trust services criteria do not change based on which report you buy, but the evidence does.
- A type 1 report covers control design at a single point in time.
- A type 2 report covers design and operating effectiveness across a period, commonly three to twelve months.
The AICPA publishes an illustrative service auditor's SOC 2 type 2 report that shows the structure of the final document. Reading one before you start is the cheapest hour you will spend on the project. It makes the deliverable concrete and shows you exactly what your customers will receive.
SOC reports are part of the AICPA's System and Organization Controls suite of services, and the examination itself must be performed by a CPA firm. Readiness work, gap assessment and remediation are separate activities that a consultancy can perform. MarkKings Group provides that readiness and advisory work. We do not issue SOC 2 reports, opinions or certifications, and nothing here is legal advice.
Mapping the criteria to what you already have
Most businesses already run controls that satisfy parts of the SOC 2 trust services criteria. They just do not have evidence of them. Before you buy anything, map what exists.
Common overlaps:
- Access control in Microsoft 365 or Google Workspace, including MFA and joiner, mover, leaver steps.
- Endpoint protection and patching through your device management tool.
- Backup and restore testing.
- Vendor contracts and security reviews.
- Incident handling, if it is written down rather than living in someone's head.
If you already align to another framework, crosswalks reduce duplicated effort. NIST publishes a crosswalk between the NIST Privacy Framework and the 2017 Trust Services Criteria, which is useful if you plan to pursue privacy alongside security. Treat any crosswalk as a starting point for your own analysis rather than a finished answer. The NIST resource says as much.
A readiness checklist you can work through this quarter
Use this before you engage an audit firm.
- Write down why you need the report. Name the customer, contract or deal that is asking. This drives every other decision.
- Decide the categories. Security first. Add others only where a written commitment exists.
- Define the system boundary. Which product, which environments, which offices, which people.
- List your subservice organizations. Cloud hosting, payment processing, payroll, managed IT.
- Inventory assets and access. You cannot protect or evidence what you have not listed.
- Collect the policies you already have. Most companies have more than they think, scattered across drives and email.
- Run a gap assessment against the criteria. Record the gap, the owner and the due date for each one.
- Fix the high-risk gaps first. Access management, logging and change control tend to generate the most audit findings.
- Start generating evidence. A type 2 report needs proof that controls ran across a period, so the clock starts when the controls start, not when the auditor arrives.
- Then select an audit firm. Going to market with a clean scope and a working control set gives you better quotes and fewer surprises.
Companies that skip steps one through four almost always pay for it later, usually in a scope expansion halfway through fieldwork.
What this costs you in practice
We avoid publishing fixed prices because the honest answer depends on scope. The variables that move cost the most are the number of trust services categories, the number of in-scope systems and environments, how much evidence is automated versus manual, and how many gaps surface during readiness. A single-product company running one cloud environment with security only is a very different engagement from a multi-product company with four categories and on-premises infrastructure.
What we can say plainly: readiness work done properly reduces audit cost, because auditors bill for the time they spend chasing missing evidence.
Next steps
Pick one action this week rather than trying to solve SOC 2 all at once.
- If you have not decided on scope, start there. Our GRC and compliance services cover scoping, gap assessment and evidence planning.
- If you want a broader view of how security, risk and compliance fit together, see our security, risk and compliance practice.
- If you prefer to self-assess first, work through the readiness toolkit.
- For a timeline view of what a first engagement looks like, read planning SOC 2 readiness.
If you want a second opinion on your scope before you sign with an audit firm, book a consultation and bring your customer's security questionnaire with you. That document usually tells us more about the right scope than anything else.
