Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

SOC 2 Trust Services Criteria (TSC): Policies, Procedures & SCF Mapping

Organizations pursuing a SOC 2 Type 1 or Type 2 report rarely answer to the AICPA Trust Services Criteria (TSC) alone. Customer contracts, privacy laws and industry regulations usually come with it. That is why ComplianceForge recommends building your cybersecurity program on the Secure Controls Framework (SCF): one set of controls, mapped to the TSC and 200+ other laws, regulations and frameworks, documented in policies, standards and procedures your auditor can test.

  • A SOC 2 is an attestation, not a certification. An independent CPA firm examines your controls against the TSC under AICPA attestation standards and issues a report with its opinion.
  • ComplianceForge does not sell "SOC 2-only" templates. Our documentation is built on a single framework. With the SCF, that framework's crosswalk to the TSC shows where each criterion is addressed.

ComplianceForge has policies, standards, procedures and other documentation that covers all applicable TSC requirements that can help a company successfully pass a SOC 2 audit.

Key Takeaways: SOC 2 Trust Services Criteria (TSC)
  • SOC 2 (System and Organization Controls 2) is an AICPA attestation report on a service organization's controls, issued by an independent CPA firm.
  • The Trust Services Criteria cover five categories. Security is required in every SOC 2; Availability, Processing Integrity, Confidentiality and Privacy are added based on scope.
  • Type 1 evaluates control design at a point in time. Type 2 also tests whether controls operated effectively over a review period.
  • Organizations pursuing SOC 2 usually have statutory, regulatory and contractual obligations beyond the TSC, so a SOC 2-only control set leaves gaps.
  • The SCF maps one set of controls to the TSC and 200+ other laws, regulations and frameworks, so SCF-based documentation supports SOC 2 and those obligations together.
Overview

What Are the SOC 2 Trust Services Criteria (TSC)?

The Trust Services Criteria are the criteria a CPA firm uses to evaluate a service organization's controls in a SOC 2 examination. They are set by the AICPA's Assurance Services Executive Committee (ASEC). As of 2026, the current version is the 2017 Trust Services Criteria (With Revised Points of Focus, 2022). The criteria describe outcomes your controls must achieve, not how to implement them, which is why you need an underlying framework and documentation to show how you meet them.

Your first step is agreeing on scope with the CPA firm you select. In our experience, most organizations do not include every category. Security is required in every SOC 2, and the other four are added based on the services you provide and the commitments you make to customers:

  • Security: information and systems are protected against unauthorized access, disclosure and damage (the Common Criteria, CC1 to CC9);
  • Availability: systems are available for operation and use as committed or agreed;
  • Processing Integrity: system processing is complete, valid, accurate, timely and authorized;
  • Confidentiality: information designated as confidential is protected as committed or agreed; and
  • Privacy: personal information is collected, used, retained, disclosed and disposed of in line with the organization's objectives.

In addition to the 17 principles of the COSO 2013 Internal Control framework (CC1 to CC5), the Common Criteria include supplemental criteria for:

  • Logical and physical access controls (CC6);
  • System operations (CC7);
  • Change management (CC8); and
  • Risk mitigation (CC9).

For a closer look at each category, see the SCF's SOC 2 Trust Services Criteria guidance.

Beyond SOC 2

Why SOC 2 Is Rarely Your Only Compliance Obligation

A SOC 2 report tells customers that a CPA firm evaluated your controls against the TSC categories you scoped. It is not a determination that you comply with any law or with every term in your contracts. Companies that pursue SOC 2 are usually service providers that store or process customer data, so they commonly face other obligations at the same time:

Statutory Obligations

Privacy and data protection laws such as the EU GDPR, the CCPA/CPRA and other US state privacy laws, plus sector laws such as HIPAA or GLBA when you handle that type of data.

Regulatory Obligations

Requirements tied to the markets you sell into, such as NIST SP 800-171 and CMMC for defense contractors, FedRAMP for cloud services sold to federal agencies, or financial and healthcare regulator expectations.

Contractual Obligations

Customer agreements, data processing agreements, business associate agreements and security addendums that require specific controls, frameworks such as ISO 27001 or PCI DSS, or breach notification timelines.

Customer Due Diligence

Security questionnaires and third-party risk reviews that ask how you meet the frameworks your customers use, which are often not the TSC.

The Cost Of A SOC 2-Only Approach

If your controls and documentation are built around the TSC alone, every new law, contract clause or customer framework becomes another gap analysis and another set of documents to maintain. A metaframework approach lets one control set answer to all of them.

Why The SCF

Why We Recommend the SCF for SOC 2 Type 1 & Type 2

The Secure Controls Framework (SCF) is a free metaframework: a single catalog of 1,500+ cybersecurity and data privacy controls across 34 domains, mapped to 200+ laws, regulations and frameworks, including the AICPA TSC. ComplianceForge is an SCF Licensed Content Provider (LCP), and our SCF-based documentation follows the SCF's control structure.

In our experience, SCF-based documentation is the most efficient and flexible way to address the TSC when SOC 2 is one of several obligations, for these reasons:

One Control Set, Many Obligations

Each SCF control is mapped to the TSC criteria and to the other frameworks it supports, so one policy, standard or procedure can serve as evidence for SOC 2, ISO 27001, NIST CSF and the laws in your scope.

Scope Changes Without Rework

Adding Availability or Privacy to your SOC 2 scope, or taking on a new regulation or customer contract, means selecting additional SCF controls that are already mapped, not rewriting your program.

Documented, Defensible Mappings

SCF crosswalks use NIST IR 8477 Set Theory Relationship Mapping (STRM), which documents how each SCF control relates to a TSC criterion. That gives your team and your auditor a clear basis for coverage decisions.

Built For Type 2 Evidence

A Type 2 tests whether controls operated over time. SCF-based procedures define who performs each control and how, giving you repeatable activities that produce evidence across the review period.

SOC 2 Type 1 vs Type 2: What Changes For Documentation

For a Type 1, the CPA firm evaluates whether controls are suitably designed and implemented as of a specific date, so your policies, standards and procedures need to exist and match how you operate. For a Type 2, the firm also tests operating effectiveness over a review period, so you need records showing those procedures were followed throughout that period.

Framework Selection

What Cybersecurity Framework Is Best For SOC 2?

Picking a cybersecurity framework is more of a business decision than a technical one, and it should be driven by the statutory, regulatory and contractual obligations in your scope. ISO 27001/27002, NIST SP 800-53 (moderate or high baselines) and the SCF can each be used to address the TSC. The difference is how much else they cover, and how much rework you face when your obligations change.

When SOC 2 is one of several obligations, ComplianceForge recommends the SCF-based Security, Compliance & Resilience Program (SCRP) for policies and standards, paired with the SCF-based Cybersecurity Standardized Operating Procedures (CSOP). If your customers specifically require ISO 27001 or NIST SP 800-53, the ISO 27002 or NIST 800-53 version of the Cybersecurity & Data Protection Program (CDPP) can be adequate for policies and standards. If you manage compliance in a GRC platform, see our premium GRC content.

Spectrum Cybersecurity Framework Policies Standards Procedures

For a side-by-side comparison, see NIST 800-53 vs ISO 27002 vs NIST CSF vs SCF.

What Products Are Applicable?

ComplianceForge Products Mapped to SOC 2 TSC Requirements

When you break down what each TSC criterion requires, these ComplianceForge products address specific documentation needs. Criteria references are to the 2017 TSC.

ComplianceForge ProductSupports The Following TSC Requirement(s)
Cybersecurity & Data Protection Program (CDPP) or Security, Compliance & Resilience Program (SCRP)CC1.2, CC5.3
Cybersecurity Supply Chain Risk Management Strategy & Implementation Plan (C-SCRM SIP)CC3.3, CC3.4, CC4.2, CC9.1, CC9.2
Cybersecurity Risk Management Program (RMP)A1.2, CC3.1, CC3.2, CC4.2, CC5.1, CC5.2, CC7.2, CC7.3, CC7.4, CC9.2, PI1.1
Cybersecurity Risk Assessment Template (CRA)-
Vulnerability & Patch Management Program (VPMP)CC4.2, CC7.1
Integrated Incident Response Program (IIRP)CC2.3, CC7.3, CC7.4, P6.3, P6.6, P6.7
Secure Engineering & Data Privacy (SEDP) ProgramC1.2, CC2.3, CC6.5, Privacy Section
Cybersecurity Standardized Operating Procedures (CSOP)CC2.2, CC5.1, CC5.3
Continuity of Operations Plan (COOP)A1.2, A1.3, CC7.5, CC9.1
Secure Baseline Configurations (SBC)CC7.1, CC8.1
Information Assurance Program (IAP)CC4.1, CC4.2
Frequently Asked Questions

SOC 2 Trust Services Criteria: Common Questions

What are the SOC 2 Trust Services Criteria?

The Trust Services Criteria (TSC) are the AICPA criteria a CPA firm uses to evaluate controls in a SOC 2 examination. They cover five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security, made up of the Common Criteria (CC1 to CC9), is required in every SOC 2. The other categories are added based on your services and customer commitments.

Is SOC 2 a certification?

No. A SOC 2 is an attestation report, not a certification. An independent CPA firm examines your system and controls against the TSC under AICPA attestation standards and issues an opinion. People often search for "SOC 2 certification," but there is no SOC 2 certificate or certifying body.

What is the difference between SOC 2 Type 1 and Type 2?

A SOC 2 Type 1 report evaluates whether controls are suitably designed and implemented as of a specific date. A Type 2 report also tests whether those controls operated effectively throughout a review period, so it requires evidence collected over time. Many organizations start with a Type 1, then move to a Type 2.

What policies do I need for SOC 2?

The TSC does not list required policies. Auditors expect documented policies, standards and procedures that cover the criteria in scope, such as governance, risk assessment, access control, system operations, change management, incident response, vendor management and business continuity. The Common Criteria (CC1 to CC9) are a practical checklist for what your documentation must address.

What is the best framework for SOC 2 compliance?

No single framework is required. The TSC can be addressed with ISO 27001/27002, NIST SP 800-53 or the SCF. ComplianceForge recommends the Secure Controls Framework (SCF) when SOC 2 is one of several obligations, because its 1,500+ controls across 34 domains are mapped to the TSC and 200+ other laws, regulations and frameworks, so the same documentation supports all of them.

Can I use the same controls for SOC 2 and ISO 27001?

Yes. Many TSC criteria overlap with ISO 27001 controls, and the AICPA publishes its own mapping of the TSC to ISO 27001. Building on the SCF lets you manage that overlap in one control set with documented mappings to both. A SOC 2 report and an ISO 27001 certificate are still separate engagements.

Does a SOC 2 report prove compliance with GDPR or CCPA?

No. The SOC 2 Privacy category evaluates controls against the TSC and your privacy commitments, but a SOC 2 report is not a determination of compliance with the GDPR, CCPA/CPRA or other privacy laws. Those laws have their own requirements, which is why mapping your controls to each applicable law, as the SCF does, matters.

Who performs a SOC 2 audit?

SOC 2 examinations are performed by independent CPA firms following AICPA attestation standards. Before the examination starts, agree on scope with your CPA firm: which TSC categories apply, which systems and locations are in scope and, for a Type 2, the length of the review period.

Does ComplianceForge sell SOC 2 policy templates?

ComplianceForge does not sell "SOC 2-only" templates. Our editable policies, standards and procedures are built on a single framework. The SCF-based SCRP and CSOP follow the SCF, which maps to the TSC, so you get coverage for SOC 2 and for the other laws and frameworks in your scope from the same documentation.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about SOC 2 and the Trust Services Criteria:

What are the five Trust Services Criteria for SOC 2?
The five Trust Services Criteria categories are Security, Availability, Processing Integrity, Confidentiality and Privacy. Security is required in every SOC 2 examination, and the other four are added based on the services the organization provides and what its customers need. SOC 2 engagements currently use the AICPA's 2017 Trust Services Criteria with revised points of focus from 2022. Scope should be agreed with the CPA firm before the examination begins.
What is the difference between SOC 2 Type 1 and Type 2?
A SOC 2 Type 1 report evaluates whether controls are suitably designed at a specific point in time, while a Type 2 report evaluates whether those controls operated effectively over a period of time. A Type 2 report includes the service auditor's tests of controls and the results, which gives customers more evidence about day-to-day operation. An organization can complete a Type 1 first to confirm its control design before starting the longer Type 2 period.
Is SOC 2 a certification?
No, SOC 2 is an attestation, not a certification. A CPA firm examines a service organization's controls against the AICPA Trust Services Criteria and issues a report that includes its opinion, management's assertion and a description of the system. People often say SOC 2 certified, but the deliverable is the report, which customers and business partners request to assess the risks of relying on the service organization.
Which cybersecurity framework is best for SOC 2?
ISO 27001 / 27002, NIST SP 800-53 at the moderate or high baseline and the Secure Controls Framework (SCF) are usually the strongest choices for addressing SOC 2 requirements. The Trust Services Criteria map to common frameworks, and the AICPA publishes a mapping of the 2017 Trust Services Criteria to NIST 800-53. The choice is mainly a business decision based on your other obligations, such as federal contracts or international customers.
Does ComplianceForge sell SOC 2 policy templates?
No, ComplianceForge doesn't sell SOC 2 specific policies and standards. Instead, our documentation aligns with a single cybersecurity framework, such as NIST CSF, ISO 27001 / 27002, NIST SP 800-53 or the Secure Controls Framework (SCF), and crosswalk mapping shows how our policies and standards address the Trust Services Criteria. For SOC 2, we recommend the Security, Compliance & Resilience Program (SCRP) or the ISO 27002 or NIST 800-53 versions of the Cybersecurity & Data Protection Program (CDPP).