Skip to content
AICPA SOC 2

SOC 2 Trust Service Criteria Checklist

Interactive SOC 2 readiness checklist. Security (CC series) is mandatory; Availability and Confidentiality are standard additions for SaaS. Track Type II audit readiness.

Security

Mandatory

Availability

Addl.

Processing Integrity

Addl.

Confidentiality

Addl.

Privacy

Addl.

0%0/51 controls implemented
CC1 — Control Environment: 0/5
CC2 — Communication and Information: 0/3
CC3 — Risk Assessment: 0/4
CC4 — Monitoring Activities: 0/2
CC5 — Control Activities: 0/3
CC6 — Logical and Physical Access Controls: 0/8
CC7 — System Operations: 0/5
CC8 — Change Management: 0/1
CC9 — Risk Mitigation: 0/2
A — Availability: 0/3
C — Confidentiality: 0/2
PI — Processing Integrity: 0/5
P — Privacy: 0/8

Frequently Asked Questions

What is SOC 2?

An attestation report, based on the AICPA's Trust Services Criteria, that evaluates a service organisation's controls relevant to security, availability, processing integrity, confidentiality and/or privacy.

What's the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are suitably designed at a single point in time; Type II assesses whether those controls operated effectively over an observation period, typically 3 to 12 months.

Is Security the only mandatory Trust Services Criteria?

Yes — the Security (Common Criteria) category is required in every SOC 2 report; Availability, Processing Integrity, Confidentiality and Privacy are optional, selected based on customer commitments.

Does SOC 2 apply outside the US?

It's an AICPA (US) standard, but it's widely requested internationally by enterprise customers, especially of SaaS and cloud providers, regardless of where the vendor is based.