- SOC 2 (System and Organization Controls 2) is an AICPA attestation report on a service organization's controls, issued by an independent CPA firm.
- The Trust Services Criteria cover five categories. Security is required in every SOC 2; Availability, Processing Integrity, Confidentiality and Privacy are added based on scope.
- Type 1 evaluates control design at a point in time. Type 2 also tests whether controls operated effectively over a review period.
- Organizations pursuing SOC 2 usually have statutory, regulatory and contractual obligations beyond the TSC, so a SOC 2-only control set leaves gaps.
- The SCF maps one set of controls to the TSC and 200+ other laws, regulations and frameworks, so SCF-based documentation supports SOC 2 and those obligations together.
What Are the SOC 2 Trust Services Criteria (TSC)?
The Trust Services Criteria are the criteria a CPA firm uses to evaluate a service organization's controls in a SOC 2 examination. They are set by the AICPA's Assurance Services Executive Committee (ASEC). As of 2026, the current version is the 2017 Trust Services Criteria (With Revised Points of Focus, 2022). The criteria describe outcomes your controls must achieve, not how to implement them, which is why you need an underlying framework and documentation to show how you meet them.
Your first step is agreeing on scope with the CPA firm you select. In our experience, most organizations do not include every category. Security is required in every SOC 2, and the other four are added based on the services you provide and the commitments you make to customers:
- Security: information and systems are protected against unauthorized access, disclosure and damage (the Common Criteria, CC1 to CC9);
- Availability: systems are available for operation and use as committed or agreed;
- Processing Integrity: system processing is complete, valid, accurate, timely and authorized;
- Confidentiality: information designated as confidential is protected as committed or agreed; and
- Privacy: personal information is collected, used, retained, disclosed and disposed of in line with the organization's objectives.
In addition to the 17 principles of the COSO 2013 Internal Control framework (CC1 to CC5), the Common Criteria include supplemental criteria for:
- Logical and physical access controls (CC6);
- System operations (CC7);
- Change management (CC8); and
- Risk mitigation (CC9).
For a closer look at each category, see the SCF's SOC 2 Trust Services Criteria guidance.
Why SOC 2 Is Rarely Your Only Compliance Obligation
A SOC 2 report tells customers that a CPA firm evaluated your controls against the TSC categories you scoped. It is not a determination that you comply with any law or with every term in your contracts. Companies that pursue SOC 2 are usually service providers that store or process customer data, so they commonly face other obligations at the same time:
Statutory Obligations
Privacy and data protection laws such as the EU GDPR, the CCPA/CPRA and other US state privacy laws, plus sector laws such as HIPAA or GLBA when you handle that type of data.
Regulatory Obligations
Requirements tied to the markets you sell into, such as NIST SP 800-171 and CMMC for defense contractors, FedRAMP for cloud services sold to federal agencies, or financial and healthcare regulator expectations.
Contractual Obligations
Customer agreements, data processing agreements, business associate agreements and security addendums that require specific controls, frameworks such as ISO 27001 or PCI DSS, or breach notification timelines.
Customer Due Diligence
Security questionnaires and third-party risk reviews that ask how you meet the frameworks your customers use, which are often not the TSC.
If your controls and documentation are built around the TSC alone, every new law, contract clause or customer framework becomes another gap analysis and another set of documents to maintain. A metaframework approach lets one control set answer to all of them.
Why We Recommend the SCF for SOC 2 Type 1 & Type 2
The Secure Controls Framework (SCF) is a free metaframework: a single catalog of 1,500+ cybersecurity and data privacy controls across 34 domains, mapped to 200+ laws, regulations and frameworks, including the AICPA TSC. ComplianceForge is an SCF Licensed Content Provider (LCP), and our SCF-based documentation follows the SCF's control structure.
In our experience, SCF-based documentation is the most efficient and flexible way to address the TSC when SOC 2 is one of several obligations, for these reasons:
One Control Set, Many Obligations
Each SCF control is mapped to the TSC criteria and to the other frameworks it supports, so one policy, standard or procedure can serve as evidence for SOC 2, ISO 27001, NIST CSF and the laws in your scope.
Scope Changes Without Rework
Adding Availability or Privacy to your SOC 2 scope, or taking on a new regulation or customer contract, means selecting additional SCF controls that are already mapped, not rewriting your program.
Documented, Defensible Mappings
SCF crosswalks use NIST IR 8477 Set Theory Relationship Mapping (STRM), which documents how each SCF control relates to a TSC criterion. That gives your team and your auditor a clear basis for coverage decisions.
Built For Type 2 Evidence
A Type 2 tests whether controls operated over time. SCF-based procedures define who performs each control and how, giving you repeatable activities that produce evidence across the review period.
For a Type 1, the CPA firm evaluates whether controls are suitably designed and implemented as of a specific date, so your policies, standards and procedures need to exist and match how you operate. For a Type 2, the firm also tests operating effectiveness over a review period, so you need records showing those procedures were followed throughout that period.
What Cybersecurity Framework Is Best For SOC 2?
Picking a cybersecurity framework is more of a business decision than a technical one, and it should be driven by the statutory, regulatory and contractual obligations in your scope. ISO 27001/27002, NIST SP 800-53 (moderate or high baselines) and the SCF can each be used to address the TSC. The difference is how much else they cover, and how much rework you face when your obligations change.
When SOC 2 is one of several obligations, ComplianceForge recommends the SCF-based Security, Compliance & Resilience Program (SCRP) for policies and standards, paired with the SCF-based Cybersecurity Standardized Operating Procedures (CSOP). If your customers specifically require ISO 27001 or NIST SP 800-53, the ISO 27002 or NIST 800-53 version of the Cybersecurity & Data Protection Program (CDPP) can be adequate for policies and standards. If you manage compliance in a GRC platform, see our premium GRC content.

For a side-by-side comparison, see NIST 800-53 vs ISO 27002 vs NIST CSF vs SCF.
ComplianceForge Products Mapped to SOC 2 TSC Requirements
When you break down what each TSC criterion requires, these ComplianceForge products address specific documentation needs. Criteria references are to the 2017 TSC.
| ComplianceForge Product | Supports The Following TSC Requirement(s) |
|---|---|
| Cybersecurity & Data Protection Program (CDPP) or Security, Compliance & Resilience Program (SCRP) | CC1.2, CC5.3 |
| Cybersecurity Supply Chain Risk Management Strategy & Implementation Plan (C-SCRM SIP) | CC3.3, CC3.4, CC4.2, CC9.1, CC9.2 |
| Cybersecurity Risk Management Program (RMP) | A1.2, CC3.1, CC3.2, CC4.2, CC5.1, CC5.2, CC7.2, CC7.3, CC7.4, CC9.2, PI1.1 |
| Cybersecurity Risk Assessment Template (CRA) | - |
| Vulnerability & Patch Management Program (VPMP) | CC4.2, CC7.1 |
| Integrated Incident Response Program (IIRP) | CC2.3, CC7.3, CC7.4, P6.3, P6.6, P6.7 |
| Secure Engineering & Data Privacy (SEDP) Program | C1.2, CC2.3, CC6.5, Privacy Section |
| Cybersecurity Standardized Operating Procedures (CSOP) | CC2.2, CC5.1, CC5.3 |
| Continuity of Operations Plan (COOP) | A1.2, A1.3, CC7.5, CC9.1 |
| Secure Baseline Configurations (SBC) | CC7.1, CC8.1 |
| Information Assurance Program (IAP) | CC4.1, CC4.2 |
SOC 2 Trust Services Criteria: Common Questions
What are the SOC 2 Trust Services Criteria?
The Trust Services Criteria (TSC) are the AICPA criteria a CPA firm uses to evaluate controls in a SOC 2 examination. They cover five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security, made up of the Common Criteria (CC1 to CC9), is required in every SOC 2. The other categories are added based on your services and customer commitments.
Is SOC 2 a certification?
No. A SOC 2 is an attestation report, not a certification. An independent CPA firm examines your system and controls against the TSC under AICPA attestation standards and issues an opinion. People often search for "SOC 2 certification," but there is no SOC 2 certificate or certifying body.
What is the difference between SOC 2 Type 1 and Type 2?
A SOC 2 Type 1 report evaluates whether controls are suitably designed and implemented as of a specific date. A Type 2 report also tests whether those controls operated effectively throughout a review period, so it requires evidence collected over time. Many organizations start with a Type 1, then move to a Type 2.
What policies do I need for SOC 2?
The TSC does not list required policies. Auditors expect documented policies, standards and procedures that cover the criteria in scope, such as governance, risk assessment, access control, system operations, change management, incident response, vendor management and business continuity. The Common Criteria (CC1 to CC9) are a practical checklist for what your documentation must address.
What is the best framework for SOC 2 compliance?
No single framework is required. The TSC can be addressed with ISO 27001/27002, NIST SP 800-53 or the SCF. ComplianceForge recommends the Secure Controls Framework (SCF) when SOC 2 is one of several obligations, because its 1,500+ controls across 34 domains are mapped to the TSC and 200+ other laws, regulations and frameworks, so the same documentation supports all of them.
Can I use the same controls for SOC 2 and ISO 27001?
Yes. Many TSC criteria overlap with ISO 27001 controls, and the AICPA publishes its own mapping of the TSC to ISO 27001. Building on the SCF lets you manage that overlap in one control set with documented mappings to both. A SOC 2 report and an ISO 27001 certificate are still separate engagements.
Does a SOC 2 report prove compliance with GDPR or CCPA?
No. The SOC 2 Privacy category evaluates controls against the TSC and your privacy commitments, but a SOC 2 report is not a determination of compliance with the GDPR, CCPA/CPRA or other privacy laws. Those laws have their own requirements, which is why mapping your controls to each applicable law, as the SCF does, matters.
Who performs a SOC 2 audit?
SOC 2 examinations are performed by independent CPA firms following AICPA attestation standards. Before the examination starts, agree on scope with your CPA firm: which TSC categories apply, which systems and locations are in scope and, for a Type 2, the length of the review period.
Does ComplianceForge sell SOC 2 policy templates?
ComplianceForge does not sell "SOC 2-only" templates. Our editable policies, standards and procedures are built on a single framework. The SCF-based SCRP and CSOP follow the SCF, which maps to the TSC, so you get coverage for SOC 2 and for the other laws and frameworks in your scope from the same documentation.
Frequently-Asked Questions
Here are answers to common questions about SOC 2 and the Trust Services Criteria:
