SOC 2 Trust Service Criteria Checklist
Interactive SOC 2 readiness checklist. Security (CC series) is mandatory; Availability and Confidentiality are standard additions for SaaS. Track Type II audit readiness.
Security
Mandatory
Availability
Addl.
Processing Integrity
Addl.
Confidentiality
Addl.
Privacy
Addl.
Related Compliance Frameworks
International ISMS standard — 93 controls across 4 themes. Widely recognised globally.
6-function framework (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) for any organisation size.
18 prioritised controls in 3 implementation groups. Practical cyber hygiene baseline.
12 requirements for entities handling payment card data. Mandatory for merchants and service providers.
India mandatory incident reporting: 6-hour reporting window, 180-day log retention, NTP sync.
Reserve Bank of India Master Directions covering cyber risk, SOC requirements and incident reporting.
Administrative, physical and technical safeguards for electronic Protected Health Information (ePHI).
Frequently Asked Questions
What is SOC 2?
An attestation report, based on the AICPA's Trust Services Criteria, that evaluates a service organisation's controls relevant to security, availability, processing integrity, confidentiality and/or privacy.
What's the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a single point in time; Type II assesses whether those controls operated effectively over an observation period, typically 3 to 12 months.
Is Security the only mandatory Trust Services Criteria?
Yes — the Security (Common Criteria) category is required in every SOC 2 report; Availability, Processing Integrity, Confidentiality and Privacy are optional, selected based on customer commitments.
Does SOC 2 apply outside the US?
It's an AICPA (US) standard, but it's widely requested internationally by enterprise customers, especially of SaaS and cloud providers, regardless of where the vendor is based.