Learn about SOC 2’s 5 Trust Services Criteria, Security, Availability, Confidentiality, Privacy, Processing Integrity, & which ones apply to different industries, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization.
Table of Contents
What is the Security criterion in SOC 2?
The Security criterion, also called the Common Criteria, is the only mandatory Trust Services Criterion and is included in every SOC 2 examination. It evaluates whether systems and data are protected against unauthorized access, unauthorized disclosure, and damage that could compromise availability, integrity, confidentiality, or privacy. Controls assessed under Security include identity and access management, multi-factor authentication (MFA), endpoint protection, firewall configuration, risk assessment processes, incident response planning, change management, and vendor oversight. Security forms the baseline; all other criteria build on top of it.
What is the Availability criterion in SOC 2?
The Availability criterion evaluates whether an organization’s systems remain operational and accessible to meet agreed-upon service commitments. It examines disaster recovery planning, uptime monitoring, redundancy architecture, capacity planning, and performance against service-level agreements (SLAs). Availability applies to any organization whose clients’ operations are materially affected by system downtime, SaaS platforms, cloud hosting providers, data centers, and organizations with contractual uptime obligations. It is not about achieving perfect uptime, it is about demonstrating that controls are in place to honor availability commitments.
What is the Processing Integrity criterion in SOC 2?
The Processing Integrity criterion evaluates whether system processing is complete, valid, accurate, timely, and authorized. It examines data inputs and outputs, processing quality controls, error detection and correction mechanisms, and whether authorized processing occurs as designed. This criterion applies to financial processing platforms, payroll and tax systems, e-commerce order and payment processing, data analytics platforms, and any service where the accuracy and completeness of data processing has direct downstream consequences for customers. If customers depend on the system to produce the correct result, not just to keep the data safe, Processing Integrity is relevant.
What is the Confidentiality criterion in SOC 2?
The Confidentiality criterion evaluates how an organization protects information designated as confidential, trade secrets, intellectual property, licensed data, client contracts, and proprietary business information. It covers protection during data transmission, while data is at rest, and through to final disposal. Confidentiality addresses business-sensitive information broadly and is distinct from the Privacy criterion, which exclusively addresses personal information. Organizations managing commercially sensitive client data, CRM platforms, legal technology providers, B2B analytics companies, document management systems, typically include this criterion.
What is the Privacy criterion in SOC 2?
The Privacy criterion evaluates how an organization manages the full lifecycle of personal information: collection, use, retention, disclosure, and deletion. It applies to organizations processing personally identifiable information (PII) or protected health information (PHI), healthcare vendors, HR and payroll platforms, financial services firms handling personal account data, and any organization collecting names, addresses, Social Security numbers, medical histories, or financial records. The Privacy criterion aligns substantially with HIPAA’s Privacy Rule, GDPR’s data processing principles, and CCPA’s personal information rights provisions, and explicitly requires controls around data breach detection and disclosure obligations.
What is the difference between the Confidentiality and Privacy criteria in SOC 2?
Confidentiality covers any information an organization or its clients designate as sensitive, trade secrets, contracts, intellectual property, financial data, or proprietary business information. Privacy covers only one category: data relating to identifiable individuals, names, addresses, Social Security numbers, medical records, and financial account details. An organization can have obligations under both simultaneously: Confidentiality applies to clients’ proprietary business data; Privacy applies to the personal information of those clients’ end customers or employees. The distinction matters because Privacy adds obligations specifically around personal data lifecycle management, consent, use limitation, individual rights, and breach disclosure, that Confidentiality does not carry.
Which Trust Services Criteria apply by industry?
Trust Services Criteria selection depends on the type of data handled and the service commitments made to customers. Security is mandatory in every SOC 2 examination regardless of industry; the remaining four criteria are included based on relevance to the organization’s risk environment and customer requirements.
SaaS and cloud technology providers typically include Security, Availability, and Confidentiality. Healthcare vendors and radiology organizations include Security, Confidentiality, Privacy, and Availability. Financial services firms, accounting firms, and payment processors include Security, Confidentiality, Privacy, and Processing Integrity. MSPs and network service providers include Security, Availability, and Confidentiality. Law firms and insurance companies include Security, Confidentiality, and Privacy. Pharmaceutical and clinical research organizations include Security, Confidentiality, Privacy, and Processing Integrity. HR, payroll, and benefits platforms include Security, Privacy, and Processing Integrity. E-commerce and retail organizations include Security, Availability, Confidentiality, and Privacy. Data analytics platforms include Security, Confidentiality, and Processing Integrity. AI-powered SaaS organizations may require all five criteria depending on the data environment and service commitments.
The table below showcases this data in an easier format.
Industry | Recommended TSC Combination |
SaaS / cloud technology | Security + Availability + Confidentiality |
Healthcare vendors / radiology | Security + Confidentiality + Privacy + Availability |
Financial services / accounting / payment processing | Security + Confidentiality + Privacy + Processing Integrity |
MSPs / network service providers | Security + Availability + Confidentiality |
Law firms / insurance companies | Security + Confidentiality + Privacy |
Pharma / clinical research | Security + Confidentiality + Privacy + Processing Integrity |
HR / payroll / benefits platforms | Security + Privacy + Processing Integrity |
E-commerce / retail | Security + Availability + Confidentiality + Privacy |
Data analytics platforms | Security + Confidentiality + Processing Integrity |
AI-powered SaaS | Security + Availability + Confidentiality + Privacy + Processing Integrity |
What are Points of Focus in SOC 2?
Points of Focus are illustrative guidance documents published by the AICPA that accompany each Trust Services Criterion. They provide examples of how organizations can satisfy the intent of a specific criterion, they are not mandatory controls. Auditors reference Points of Focus when evaluating whether an organization’s control design is suitable for its operating environment. Organizations use Points of Focus as design reference points during the planning and implementation phase, working with a readiness partner who understands how auditors apply them within specific industries.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties