Last updated: July 26, 2026
Getting Ready · Compliance Q&A

Which Trust Services Criteria should I include in my SOC 2?

Security, also called the Common Criteria, is mandatory in every SOC 2. The other four — Availability, Confidentiality, Processing Integrity, and Privacy — are optional. Add only those your customers contractually require.

The full answer

Every SOC 2 report is built on the AICPA's Trust Services Criteria, and Security — also called the Common Criteria — is the only category that is always required. It covers access controls, change management, risk assessment, and incident response, and many small companies scope their first report to Security alone.

The other four criteria are optional, and you add them only when a customer commitment or contract calls for them. Availability suits products that promise uptime SLAs. Confidentiality fits when you handle sensitive business data under NDA. Processing Integrity matters for systems that process transactions accurately, such as payments or payroll. Privacy applies when you collect and manage personal information governed by a privacy notice.

Each criterion you add brings its own controls and evidence, which lengthens preparation and can raise the audit fee. A US SOC 2 audit commonly runs $5,000 to $60,000 or more depending on scope, per published pricing guides from Vanta, Drata, and Secureframe (2024–2026); audits booked through the AuditNex network start at $2,500 and average about $5,000. Adding criteria you do not need inflates that cost without helping you close deals.

A practical approach is to start with Security, then ask your top prospects which criteria their security teams expect. Enterprise buyers frequently want Availability and Confidentiality alongside Security, but rarely all five. You can expand scope in a later reporting period as your commitments grow. Because SOC 2 is an AICPA attestation issued under SSAE No. 18, your auditor will confirm the final scope with you before fieldwork begins.

Go deeper

Short answer not enough? These pages cover the full picture:

Complete SOC 2 guide ›  ·  SOC 2 timeline estimator ›

Get matched with the right auditor

Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.

Get instant pricing →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

Can a two-person startup get SOC 2?

Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.

Do I need a penetration test for SOC 2?

Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.

Does SOC 2 cover remote work and BYOD?

Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.

Does SOC 2 require MFA?

Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.

Does SOC 2 require a vendor management program?

Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.

Does SOC 2 require annual security training?

Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.

All compliance questions ›

Sources: AICPA Trust Services Criteria (2017, revised 2022); AICPA SSAE No. 18 attestation standards; Vanta, Drata, and Secureframe pricing guides (2024–2026). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.