← Framework library

SOC 2 (Trust Services Criteria)

The Trust Services Criteria underpinning a SOC 2 examination. The Common Criteria (CC1–CC9) are mandatory for every report; Availability, Confidentiality, Processing Integrity and Privacy are optional categories a service organisation may add.

AICPA · 2017 TSC, revised 2022 · United States (used globally by SaaS vendors) · Official source

SOC 2 is an attestation against criteria, not a certification against a fixed control list. Auditors expect the organisation to describe its own controls and then demonstrate they operate. Requirement text below is paraphrased; cite the AICPA source for audit work.
41 of 41 controls
CC1.1 Commitment to integrity and ethical values medium

The entity demonstrates a commitment to integrity and ethical values through a code of conduct, communicated to all personnel and enforced through defined consequences.

CC1 — Control Environment policy-governancetraining
CC1.2 Board independence and oversight medium

The board of directors, or an equivalent governing body, operates independently of management and exercises oversight of the design and operation of internal control.

CC1 — Control Environment board-oversightpolicy-governance
CC1.3 Organisational structure and reporting lines low

Management establishes structures, reporting lines and appropriate authorities and responsibilities in pursuit of the entity's objectives.

CC1 — Control Environment roles-responsibilitiespolicy-governance
CC1.4 Competence of personnel medium

The entity demonstrates a commitment to attract, develop and retain competent individuals, including security awareness training and role-specific competence.

CC1 — Control Environment traininghr-screening
CC1.5 Accountability for control responsibilities low

The entity holds individuals accountable for their internal control responsibilities, including through performance measures and corrective action.

CC1 — Control Environment roles-responsibilities
CC2.1 Quality information for internal control low

The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

CC2 — Communication and Information loggingrecords
CC2.2 Internal communication of responsibilities medium

The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support its functioning.

CC2 — Communication and Information policy-governancetraining
CC2.3 External communication low

The entity communicates with external parties regarding matters affecting the functioning of internal control, including commitments made to customers.

CC2 — Communication and Information vendor-managementprivacy-notice
CC3.1 Objectives and risk identification high

The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives.

CC3 — Risk Assessment risk-assessment
CC3.2 Risk analysis and response high

The entity identifies risks to the achievement of its objectives, analyses them as a basis for determining how they should be managed, and selects risk responses.

CC3 — Risk Assessment risk-assessment
CC3.3 Fraud risk medium

The entity considers the potential for fraud in assessing risks to the achievement of objectives.

CC3 — Risk Assessment risk-assessment
CC3.4 Assessment of significant change medium

The entity identifies and assesses changes that could significantly affect the system of internal control.

CC3 — Risk Assessment change-managementrisk-assessment
CC4.1 Ongoing and separate evaluations medium

The entity selects, develops and performs ongoing and separate evaluations to ascertain whether the components of internal control are present and functioning.

CC4 — Monitoring auditmonitoring
CC4.2 Communication of deficiencies medium

The entity evaluates and communicates internal control deficiencies in a timely manner to those responsible for taking corrective action.

CC4 — Monitoring auditpolicy-governance
CC5.1 Selection and development of control activities medium

The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

CC5 — Control Activities policy-governance
CC5.2 Technology general controls high

The entity selects and develops general control activities over technology to support the achievement of objectives.

CC5 — Control Activities config-managementchange-managementaccess-control
CC5.3 Deployment through policies and procedures medium

The entity deploys control activities through policies that establish what is expected and procedures that put those policies into action.

CC5 — Control Activities policy-governance
CC6.1 Logical access provisioning and restriction critical

The entity implements logical access security software, infrastructure and architectures over protected information assets to protect them from security events. Access is restricted to authorised users and is granted on the principle of least privilege.

CC6 — Logical and Physical Access access-controlauthenticationencryption-at-rest
CC6.2 Registration and authorisation of new users high

Prior to issuing system credentials, the entity registers and authorises new internal and external users, and removes access when it is no longer required.

CC6 — Logical and Physical Access access-controlonboarding
CC6.3 Access modification and removal critical

The entity authorises, modifies or removes access to data and systems based on roles, responsibilities or the system design, and removes access promptly on termination or role change.

CC6 — Logical and Physical Access access-controloffboardingaccess-review
CC6.4 Physical access to facilities medium

The entity restricts physical access to facilities and protected information assets to authorised personnel.

CC6 — Logical and Physical Access physical-security
CC6.5 Disposal of physical and logical assets medium

The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished.

CC6 — Logical and Physical Access media-disposaldata-deletion
CC6.6 Boundary protection high

The entity implements logical access security measures to protect against threats from sources outside its system boundaries.

CC6 — Logical and Physical Access network-securityencryption-in-transit
CC6.7 Restriction of information transmission, movement and removal critical

The entity restricts the transmission, movement and removal of information to authorised users and processes, and protects it during transmission, movement and removal.

CC6 — Logical and Physical Access encryption-in-transitencryption-at-restdlp
CC6.8 Prevention and detection of unauthorised software high

The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software.

CC6 — Logical and Physical Access malwareendpoint
CC7.1 Detection of configuration changes and vulnerabilities high

The entity uses detection and monitoring procedures to identify changes to configurations that introduce new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.

CC7 — System Operations vulnerability-managementconfig-management
CC7.2 Monitoring for anomalies high

The entity monitors system components and the operation of those components for anomalies indicative of malicious acts, natural disasters and errors, and analyses them to determine whether they represent security events.

CC7 — System Operations loggingmonitoringsiem
CC7.3 Evaluation of security events high

The entity evaluates security events to determine whether they could or have resulted in a failure to meet objectives, and if so, takes action to prevent or address such failures.

CC7 — System Operations incident-response
CC7.4 Incident response programme critical

The entity responds to identified security incidents by executing a defined incident response programme to understand, contain, remediate and communicate them.

CC7 — System Operations incident-responsebreach-notification
CC7.5 Recovery from identified incidents high

The entity identifies, develops and implements activities to recover from identified security incidents.

CC7 — System Operations incident-responserecovery
CC8.1 Authorised change management high

The entity authorises, designs, develops or acquires, configures, documents, tests, approves and implements changes to infrastructure, data, software and procedures to meet its objectives.

CC8 — Change Management change-managementsdlc
CC9.1 Risk mitigation for business disruption medium

The entity identifies, selects and develops risk mitigation activities for risks arising from potential business disruptions.

CC9 — Risk Mitigation business-continuityrecoverybackup
CC9.2 Vendor and business partner risk management high

The entity assesses and manages risks associated with vendors and business partners, including due diligence before engagement and ongoing monitoring.

CC9 — Risk Mitigation vendor-managementthird-party
A1.1 Capacity management medium

The entity maintains, monitors and evaluates current processing capacity and use of system components to manage capacity demand and enable the implementation of additional capacity.

A1 — Availability capacityavailabilitymonitoring
A1.2 Backup, recovery and environmental protection high

The entity authorises, designs, develops, implements, operates, approves, maintains and monitors environmental protections, software, data backup processes and recovery infrastructure.

A1 — Availability backuprecoverydr-testing
A1.3 Recovery plan testing medium

The entity tests recovery plan procedures supporting system recovery to meet its availability objectives.

A1 — Availability dr-testingbusiness-continuity
C1.1 Identification and protection of confidential information high

The entity identifies and maintains confidential information to meet its objectives related to confidentiality.

C1 — Confidentiality data-classificationconfidentiality
C1.2 Disposal of confidential information medium

The entity disposes of confidential information to meet its objectives related to confidentiality.

C1 — Confidentiality data-deletiondata-retention
PI1.1 Quality information about processing objectives and specifications medium

The entity obtains or generates, uses and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications.

PI1 — Processing Integrity integrity
P1.1 Notice and communication of privacy commitments high

The entity provides notice to data subjects about its privacy practices to meet its objectives related to privacy, including the purposes for collection, use, retention and disclosure of personal information.

P1 — Privacy privacy-noticelawful-basis
P4.1 Use, retention and disposal of personal information (P4.1–P4.3) high

The entity limits the use of personal information to the purposes identified in its notice and consistent with the consent received, retains it only as long as necessary, and disposes of it securely.

P4 — Privacy data-retentiondata-minimisationdata-deletion