Trust Services Criteria (TSC) For SOC 2® Certification
Note - System and Organization Controls (SOC®) is a registered trademark via the AICPA Trust Services Criteria (TSC). This page is educational guidance to answer Frequently Asked Questions (FAQ) pertaining to TSC/SOC 2 compliance efforts.
Since documentation artifacts (e.g., policies, standards, procedures, etc.) are expectations for demonstrating a cybersecurity program exists, a common question we receive is about "What products do I need for SOC 2 certification?" That is a bit of a loaded question, since there are a few missing pieces of information that need to be clarified before we can answer what ComplianceForge product will work best for your your specific needs.
It is important to note that ComplianceForge does not offer "SOC®-specific policies & standards" since we build our documentation to align with a single cybersecurity framework (e.g., NIST CSF, ISO 27001/2, NIST SP 800-53 and the Secure Controls Framework (SCF)). However, with the framework crosswalk mapping, it is possible to use the selected cybersecurity framework to ensure the necessary policies, standards, procedures, etc. address necessary TSC requirements.
The auditor you choose for a SOC 2 will be required to follow specific professional standards established by AICPA and it involves an assessment against AICPA’s Trust Services Criteria (TSC). The good news is the TSC maps to most common cybersecurity frameworks (e.g., ISO 27002, NIST 800-53, etc.).
Since Certified Public Accountant (CPA) firms are the only entities permitted to perform a SOC 2 certification, your first step must be to discuss what is in scope for the assessment with the CPA firm you’ve selected. The reason for this is certain control areas might not be applicable to your organization. From what we've experienced, most companies do not voluntarily choose to be assessed against all of the TSC controls. This is a management decision for your organization to define, in conjunction with the firm you select for your assessment services. In addition to covering the 17 Committee of Sponsoring Organizations (COSO) principles, the TSC covers dozens of cybersecurity and privacy controls associated with designing, implementing and operating security-related controls that cover these high-level categories:
Security
Availability
Processing Integrity
Confidentiality
Privacy
The “supplemental criteria” of the TSC also covers these categories of security controls:
Logical and physical access controls
System operations
Change management
Risk mitigation
What Cybersecurity Framework Is Best For My Needs?
Picking a cybersecurity framework is more of a business decision than a technical one. Additionally, each cybersecurity framework has its benefits and drawbacks, which means that they are not all equal. Picking the best framework is based on your statutory, regulatory and contractual needs. Generally, ISO 27001/2, NIST SP 800-53 (moderate or high baselines) or the SCF are the most appropriate frameworks to build a cybersecurity program when you need to address TSC requirements.
For enterprise-class environments with more complex compliance requirements, the Digital Security Program (DSP) might be the best choice for underlying policies and standards. For less complex compliance environment or smaller companies, ISO 27001/2 or NIST 800-53 version of the Cybersecurity & Data Protection Program (CDPP) can be adequate to address the need for policies and standards.
When you break down what is required to comply with the individual TSC requirements, you will see how these ComplianceForge products can be leveraged to address specific compliance needs:
ComplianceForge Product
Supports The Following TSC Requirement(s)
Cybersecurity & Data Protection Program (CDPP) or Digital Security Program (DSP)
Please note that if you want a customized bundle, we are happy to create one for you. Just contact us with your needs and we will generate a quote for you.
Secure Controls Framework (SCF) "Premium Content" - Expertise-Class Policies, Control Objectives, Standards, Guidelines, Controls & Metrics.
Product Walkthrough Video
This short product walkthrough video is designed to give a brief overview about...
NIST 800-53 Rev5 Policy Template LOW & MODERATE BASELINE
Product Walkthrough Video
This short product walkthrough video is designed to give a brief overview about what the CDPP is to help answer common questions we receive...
ComplianceForge ISO 27001 & 27002 Compliance Documentation Templates
Cybersecurity & Data Protection Program (CDPP) Bundle #1B - ISO 27002:2022 (20% discount)
This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing NIST SP 800-53 R5...
Cybersecurity & Data Protection Program (CDPP) Bundle #1C - NIST SP 800-53 R5 Low & Moderate Baselines (20% discount)
This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing...
ComplianceForge ISO 27001 & 27002 Compliance Documentation Templates
Cybersecurity & Data Protection Program (CDPP) Bundle #3 ISO 27002:2022 (35% discount)
This is a bundle that includes the following eleven (11) ComplianceForge products that are focused on operationalizing ISO...
Cybersecurity & Data Protection Program (CDPP) Bundle #4a (40% discount)
This is a bundle that includes the following fourteen (14) ComplianceForge products that are focused on operationalizing NIST SP 800-53 R5 (low & moderate...
Digital Security Plan (DSP) Bundle #1 - SCF-Aligned Policies, Standards & Procedures (25% Discount)
This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing the Secure Controls Framework...
Digital Security Plan (DSP) Bundle #2 - ENHANCED DIGITAL SECURITY (35% Discount)
This is a bundle that includes the following seven (7) ComplianceForge products that are focused on operationalizing the Secure Controls Framework (SCF):
Digital...
Digital Security Plan (DSP) Bundle #3 - ROBUST DIGITAL SECURITY (45% Discount)
This is a bundle that includes the following thirteen (13) ComplianceForge products that are focused on operationalizing the Secure Controls Framework (SCF):
Digital...