We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

AICPA Trust Services Criteria · 5 categories

SOC 2, criterion by criterion

One deep guide per category: what each criterion demands, the exceptions auditors actually write, and the evidence they sample across a Type II period. Reports are issued by licensed CPA firms — we get you ready and coordinate the examination.

CC1–CC9 · Required
Security (Common Criteria)

The mandatory category — every SOC 2 examination includes the Common Criteria, whatever else is in scope. CC1–

A1 · Optional
Availability

Three criteria with heavy operational implications: capacity, environmental protections and backup, and tested

PI1 · Optional
Processing Integrity

The category for systems whose value IS the correctness of processing — payments, payroll, billing, data pipel

C1 · Optional
Confidentiality

Two criteria, deceptively simple: identify and protect confidential information, then dispose of it provably.

P1–P8 · Optional
Privacy

The largest optional category: eight criteria tracking personal information from notice to enforcement. Scoped

Start with the free self-assessment, or go straight to SOC 2 services.