How many controls are in SOC 2, and what actually gets counted
SOC 2 counts criteria, not controls. Here is the full tally, the source of the stale 64, and why the control number is yours to keep small.
How many controls are in SOC 2? Zero. The standard never lists controls. It lists criteria, the outcomes an auditor measures you against, and you decide which controls get you there.1 The criteria count is 61. Of those, 33 are common criteria, and a report scoped to Security alone is measured on those 33 and nothing more.
That difference matters for your costs more than for your trivia. A control count is a design choice, and every control you add is something to run, evidence and pay someone to test. Below is the full criteria tally, the story behind the outdated 64, and a practical way to keep your own control list short.
Three numbers that get mixed up
Search results blur three different things into one figure. Pull them apart and the question gets easy. Only one of the three is a requirement, and it is not the one people usually quote.
- Criteria
- The benchmarks in the AICPA document. There are 61. These are what the auditor evaluates, and the only fixed count in the standard.
- Points of focus
- Examples printed under each criterion, several hundred in total. The standard says you do not have to assess each one.3 Useful as prompts. Not a checklist.
- Controls
- What your company actually does, such as reviewing access or approving code changes. The standard deliberately leaves the number to you.
The standard says it plainly. The criteria are meant to be used for evaluation regardless of which specific controls management puts in place.1 So when a vendor says SOC 2 has a certain number of controls, it is telling you the size of its own library.
The full count of the 61 criteria
The AICPA document never adds itself up. It lays the criteria out by section and leaves the sum to the reader, which is why published counts disagree. Here is the addition with every family shown, so you can check it line by line.
| Family | Count | Identifiers |
|---|---|---|
| CC1 Control environment | 5 | CC1.1 to CC1.5 |
| CC2 Communication and information | 3 | CC2.1 to CC2.3 |
| CC3 Risk assessment | 4 | CC3.1 to CC3.4 |
| CC4 Monitoring of controls | 2 | CC4.1 to CC4.2 |
| CC5 Control activities | 3 | CC5.1 to CC5.3 |
| CC6 Logical and physical access | 8 | CC6.1 to CC6.8 |
| CC7 System operations | 5 | CC7.1 to CC7.5 |
| CC8 Change management | 1 | CC8.1 |
| CC9 Risk mitigation | 2 | CC9.1 to CC9.2 |
| Common criteria | 33 | In every SOC 2 |
| A1 Availability | 3 | A1.1 to A1.3 |
| C1 Confidentiality | 2 | C1.1 to C1.2 |
| PI1 Processing integrity | 5 | PI1.1 to PI1.5 |
| P1 Notice and communication of objectives | 1 | P1.1 |
| P2 Choice and consent | 1 | P2.1 |
| P3 Collection | 2 | P3.1 to P3.2 |
| P4 Use, retention and disposal | 3 | P4.1 to P4.3 |
| P5 Access | 2 | P5.1 to P5.2 |
| P6 Disclosure and notification | 7 | P6.1 to P6.7 |
| P7 Quality | 1 | P7.1 |
| P8 Monitoring and enforcement | 1 | P8.1 |
| Privacy subtotal | 18 | P1.1 to P8.1 |
| All categories | 61 | Security, Availability, Confidentiality, Processing Integrity, Privacy |
Source: TSP Section 100, the 2017 Trust Services Criteria with the 2022 revised points of focus.1 The original 2017 issue and the March 2020 edition carry the same 61 identifiers. The 2022 revision only touched points of focus. If a page says the criteria count changed in 2022, it counted something else.
Watch the privacy headings
Privacy has eight section headings numbered P1.0 to P8.0. They look like criteria. They are not. Count them in and you get 69. No other category has a .0 heading, so this is the one place where a careful counter still slips.
Why older pages say 64
The 64 is real. It just belongs to the previous standard. The 2016 Trust Services Principles and Criteria, TSP section 100A, had 64 criteria, and the 2017 version replaced it. AICPA published both in one file, one after the other, so counting each half of the same file gives you both figures.
| Category | 2016 (TSP 100A) | 2017 (TSP 100) |
|---|---|---|
| Common criteria | 27 | 33 |
| Availability | 3 | 3 |
| Confidentiality | 8 | 2 |
| Processing integrity | 6 | 5 |
| Privacy | 20 | 18 |
| Total | 64 | 61 |
Look at Confidentiality. It dropped from eight standalone criteria to two, because the 2017 rewrite moved that material into the common criteria, which grew from 27 to 33. Coverage stayed the same. The total simply went down by three.
Your control count is a cost decision
Since the standard sets no control number, the size of your control set is up to you. That is good news for a small team. Every control has a running cost: someone performs it, someone saves the evidence, and the auditor samples it. Two companies can satisfy the same 33 common criteria with control lists that differ threefold, and neither one is more compliant.
Large platforms tend to ship big control libraries, and their pricing reflects a bigger product. Here is what one marketplace reports buyers actually paid:
- Vendr reports a median annual contract value of $20,000 for Vanta, based on purchases completed through its marketplace. Source, checked 2026-07-30.
- Vendr reports a median annual contract value of $24,601 for Drata, based on purchases completed through its marketplace. Source, checked 2026-07-30.
- Vendr reports a median annual contract value of $20,000 for Secureframe, based on purchases completed through its marketplace. Source, checked 2026-07-30.
You do not need that to map controls to 33 criteria. You can do the mapping yourself. Start from the criteria, write one control per real activity you already perform, and only add a control when a criterion is left uncovered. Resist copying a points of focus list into your control set. That is how a Security project quietly becomes a year of work. How many SOC 2 policies you need applies the same logic to documents.
Which criteria your first report covers
Nearly always the 33 common criteria. Security is required in every SOC 2, and the other four categories only come in when a contract or buyer asks for them.2 A first report on Security alone is the normal shape. It is not a lesser report.
Be most careful with the 18 privacy criteria. They are the biggest optional block and carry the most evidence, so adding them without a buyer asking is an expensive guess. The scoping tool checks which categories your contracts really require, and the criteria guide explains what each one asks for. We scope Security only, so the 33 common criteria are the set our software works against.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Your next step
Want to know how far your current setup is from the 33 common criteria? The free readiness assessment takes about 15 minutes. You get a readiness assessment, score, gap list and one AI sample policy, with no card needed. If the gap list looks manageable, the pricing page shows the monthly and yearly plans side by side, and how audits are priced.
Questions
How many Trust Services Criteria are there?
Where does the number 64 come from?
How many criteria apply to a Security only report?
So how many controls does SOC 2 require?
Do I have to address every point of focus?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.