SOC 2 (Trust Services Criteria)
The Trust Services Criteria underpinning a SOC 2 examination. The Common Criteria (CC1–CC9) are mandatory for every report; Availability, Confidentiality, Processing Integrity and Privacy are optional categories a service organisation may add.
AICPA · 2017 TSC, revised 2022 · United States (used globally by SaaS vendors) · Official source
The entity demonstrates a commitment to integrity and ethical values through a code of conduct, communicated to all personnel and enforced through defined consequences.
The board of directors, or an equivalent governing body, operates independently of management and exercises oversight of the design and operation of internal control.
Management establishes structures, reporting lines and appropriate authorities and responsibilities in pursuit of the entity's objectives.
The entity demonstrates a commitment to attract, develop and retain competent individuals, including security awareness training and role-specific competence.
The entity holds individuals accountable for their internal control responsibilities, including through performance measures and corrective action.
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support its functioning.
The entity communicates with external parties regarding matters affecting the functioning of internal control, including commitments made to customers.
The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives.
The entity identifies risks to the achievement of its objectives, analyses them as a basis for determining how they should be managed, and selects risk responses.
The entity considers the potential for fraud in assessing risks to the achievement of objectives.
The entity identifies and assesses changes that could significantly affect the system of internal control.
The entity selects, develops and performs ongoing and separate evaluations to ascertain whether the components of internal control are present and functioning.
The entity evaluates and communicates internal control deficiencies in a timely manner to those responsible for taking corrective action.
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
The entity selects and develops general control activities over technology to support the achievement of objectives.
The entity deploys control activities through policies that establish what is expected and procedures that put those policies into action.
The entity implements logical access security software, infrastructure and architectures over protected information assets to protect them from security events. Access is restricted to authorised users and is granted on the principle of least privilege.
Prior to issuing system credentials, the entity registers and authorises new internal and external users, and removes access when it is no longer required.
The entity authorises, modifies or removes access to data and systems based on roles, responsibilities or the system design, and removes access promptly on termination or role change.
The entity restricts physical access to facilities and protected information assets to authorised personnel.
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished.
The entity implements logical access security measures to protect against threats from sources outside its system boundaries.
The entity restricts the transmission, movement and removal of information to authorised users and processes, and protects it during transmission, movement and removal.
The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software.
The entity uses detection and monitoring procedures to identify changes to configurations that introduce new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.
The entity monitors system components and the operation of those components for anomalies indicative of malicious acts, natural disasters and errors, and analyses them to determine whether they represent security events.
The entity evaluates security events to determine whether they could or have resulted in a failure to meet objectives, and if so, takes action to prevent or address such failures.
The entity responds to identified security incidents by executing a defined incident response programme to understand, contain, remediate and communicate them.
The entity identifies, develops and implements activities to recover from identified security incidents.
The entity authorises, designs, develops or acquires, configures, documents, tests, approves and implements changes to infrastructure, data, software and procedures to meet its objectives.
The entity identifies, selects and develops risk mitigation activities for risks arising from potential business disruptions.
The entity assesses and manages risks associated with vendors and business partners, including due diligence before engagement and ongoing monitoring.
The entity maintains, monitors and evaluates current processing capacity and use of system components to manage capacity demand and enable the implementation of additional capacity.
The entity authorises, designs, develops, implements, operates, approves, maintains and monitors environmental protections, software, data backup processes and recovery infrastructure.
The entity tests recovery plan procedures supporting system recovery to meet its availability objectives.
The entity identifies and maintains confidential information to meet its objectives related to confidentiality.
The entity disposes of confidential information to meet its objectives related to confidentiality.
The entity obtains or generates, uses and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications.
The entity provides notice to data subjects about its privacy practices to meet its objectives related to privacy, including the purposes for collection, use, retention and disclosure of personal information.
The entity limits the use of personal information to the purposes identified in its notice and consistent with the consent received, retains it only as long as necessary, and disposes of it securely.