How many controls are in SOC 2, and what actually gets counted

SOC 2 counts criteria, not controls. Here is the full tally, the source of the stale 64, and why the control number is yours to keep small.

How many controls are in SOC 2? Zero. The standard never lists controls. It lists criteria, the outcomes an auditor measures you against, and you decide which controls get you there.1 The criteria count is 61. Of those, 33 are common criteria, and a report scoped to Security alone is measured on those 33 and nothing more.

That difference matters for your costs more than for your trivia. A control count is a design choice, and every control you add is something to run, evidence and pay someone to test. Below is the full criteria tally, the story behind the outdated 64, and a practical way to keep your own control list short.

Three numbers that get mixed up

Search results blur three different things into one figure. Pull them apart and the question gets easy. Only one of the three is a requirement, and it is not the one people usually quote.

Criteria
The benchmarks in the AICPA document. There are 61. These are what the auditor evaluates, and the only fixed count in the standard.
Points of focus
Examples printed under each criterion, several hundred in total. The standard says you do not have to assess each one.3 Useful as prompts. Not a checklist.
Controls
What your company actually does, such as reviewing access or approving code changes. The standard deliberately leaves the number to you.

The standard says it plainly. The criteria are meant to be used for evaluation regardless of which specific controls management puts in place.1 So when a vendor says SOC 2 has a certain number of controls, it is telling you the size of its own library.

The full count of the 61 criteria

The AICPA document never adds itself up. It lays the criteria out by section and leaves the sum to the reader, which is why published counts disagree. Here is the addition with every family shown, so you can check it line by line.

FamilyCountIdentifiers
CC1 Control environment5CC1.1 to CC1.5
CC2 Communication and information3CC2.1 to CC2.3
CC3 Risk assessment4CC3.1 to CC3.4
CC4 Monitoring of controls2CC4.1 to CC4.2
CC5 Control activities3CC5.1 to CC5.3
CC6 Logical and physical access8CC6.1 to CC6.8
CC7 System operations5CC7.1 to CC7.5
CC8 Change management1CC8.1
CC9 Risk mitigation2CC9.1 to CC9.2
Common criteria33In every SOC 2
A1 Availability3A1.1 to A1.3
C1 Confidentiality2C1.1 to C1.2
PI1 Processing integrity5PI1.1 to PI1.5
P1 Notice and communication of objectives1P1.1
P2 Choice and consent1P2.1
P3 Collection2P3.1 to P3.2
P4 Use, retention and disposal3P4.1 to P4.3
P5 Access2P5.1 to P5.2
P6 Disclosure and notification7P6.1 to P6.7
P7 Quality1P7.1
P8 Monitoring and enforcement1P8.1
Privacy subtotal18P1.1 to P8.1
All categories61Security, Availability, Confidentiality, Processing Integrity, Privacy

Source: TSP Section 100, the 2017 Trust Services Criteria with the 2022 revised points of focus.1 The original 2017 issue and the March 2020 edition carry the same 61 identifiers. The 2022 revision only touched points of focus. If a page says the criteria count changed in 2022, it counted something else.

Watch the privacy headings

Privacy has eight section headings numbered P1.0 to P8.0. They look like criteria. They are not. Count them in and you get 69. No other category has a .0 heading, so this is the one place where a careful counter still slips.

Why older pages say 64

The 64 is real. It just belongs to the previous standard. The 2016 Trust Services Principles and Criteria, TSP section 100A, had 64 criteria, and the 2017 version replaced it. AICPA published both in one file, one after the other, so counting each half of the same file gives you both figures.

Category2016 (TSP 100A)2017 (TSP 100)
Common criteria2733
Availability33
Confidentiality82
Processing integrity65
Privacy2018
Total6461

Look at Confidentiality. It dropped from eight standalone criteria to two, because the 2017 rewrite moved that material into the common criteria, which grew from 27 to 33. Coverage stayed the same. The total simply went down by three.

Your control count is a cost decision

Since the standard sets no control number, the size of your control set is up to you. That is good news for a small team. Every control has a running cost: someone performs it, someone saves the evidence, and the auditor samples it. Two companies can satisfy the same 33 common criteria with control lists that differ threefold, and neither one is more compliant.

Large platforms tend to ship big control libraries, and their pricing reflects a bigger product. Here is what one marketplace reports buyers actually paid:

  • Vendr reports a median annual contract value of $20,000 for Vanta, based on purchases completed through its marketplace. Source, checked 2026-07-30.
  • Vendr reports a median annual contract value of $24,601 for Drata, based on purchases completed through its marketplace. Source, checked 2026-07-30.
  • Vendr reports a median annual contract value of $20,000 for Secureframe, based on purchases completed through its marketplace. Source, checked 2026-07-30.

You do not need that to map controls to 33 criteria. You can do the mapping yourself. Start from the criteria, write one control per real activity you already perform, and only add a control when a criterion is left uncovered. Resist copying a points of focus list into your control set. That is how a Security project quietly becomes a year of work. How many SOC 2 policies you need applies the same logic to documents.

Which criteria your first report covers

Nearly always the 33 common criteria. Security is required in every SOC 2, and the other four categories only come in when a contract or buyer asks for them.2 A first report on Security alone is the normal shape. It is not a lesser report.

Be most careful with the 18 privacy criteria. They are the biggest optional block and carry the most evidence, so adding them without a buyer asking is an expensive guess. The scoping tool checks which categories your contracts really require, and the criteria guide explains what each one asks for. We scope Security only, so the 33 common criteria are the set our software works against.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Your next step

Want to know how far your current setup is from the 33 common criteria? The free readiness assessment takes about 15 minutes. You get a readiness assessment, score, gap list and one AI sample policy, with no card needed. If the gap list looks manageable, the pricing page shows the monthly and yearly plans side by side, and how audits are priced.

Questions

How many Trust Services Criteria are there?
Sixty one, spread over five categories. Thirty three are common criteria and appear in every SOC 2. The other twenty eight belong to Availability, Confidentiality, Processing Integrity and Privacy, and they only apply if you put that category in scope.
Where does the number 64 come from?
From the 2016 standard, TSP section 100A, which had 64 criteria. The 2017 Trust Services Criteria replaced it with 61. Most of the drop is in Confidentiality, which shrank from eight criteria to two when its content moved into the common criteria.
How many criteria apply to a Security only report?
Thirty three, the common criteria from CC1.1 to CC9.2. The remaining twenty eight are evaluated only when you scope in one of the other four categories.
So how many controls does SOC 2 require?
It does not set a number. The criteria describe what has to be true, and you design the controls that make it true. Two companies can meet the same 33 common criteria with very different control counts and both be fine.
Do I have to address every point of focus?
No. Points of focus are examples listed under each criterion to help you think about design. The standard says using the criteria does not require checking off each one, so treat them as prompts rather than a to do list.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.