Glossary

Trust Services Criteria

The Trust Services Criteria are the AICPA’s evaluation categories for SOC 2 examinations: security, availability, processing integrity, confidentiality, and privacy. Security — the common criteria — is mandatory in every SOC 2; the other four are optional additions chosen based on what your customers need assured.

Choosing your criteria

Most first reports scope security alone or security plus availability, because those answer the questions enterprise buyers actually ask. Each added category expands the audit’s control set and cost, so the practical rule is: add a criterion when contracts or questionnaires demand it, not preemptively.

Related Terms

Bridge Letter — A bridge letter covers the gap between your last SOC 2 report period and today, letting customers rely on your report between annual audits.

Observation Window — The observation window is the period a SOC 2 Type II report covers — typically 3 to 12 months — during which controls must demonstrably operate.

SOC 3 — A SOC 3 is the public, general-use version of a SOC 2 Type II report — same audit, no confidential detail, freely publishable on your website.

SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.