Which Trust Services Criteria should I include? Four questions decide
Security is always in scope. Anything else needs a contract behind it, and this tool tells you which.
Which Trust Services Criteria should I include? Security, always. It is required in every SOC 2 report1 and covers what buyers care about. The other four categories are optional. Add one only when a contract you already signed commits you to it.
Answer the four questions based on the contracts you have today, not the ones you hope to sign. The tool lists the categories that follow and explains each.
- Security
- Always included, in every SOC 2. It covers access, change management, monitoring and incident response, and it is what a buyer means by asking for a SOC 2.
Security and nothing else. That is a complete scope for a first report, and it is exactly what cybersoftware covers, from readiness through the Type 1 report.
Why every added category costs money
An audit is priced on the work, and scope is the work. Each extra category brings more controls to design, more evidence to collect every month, and more hours of testing. Two companies of the same size, one scoped to Security and one to all five, are buying different things and will get different quotes.
The cost does not stop at the first report. A category you add this year is one you are expected to keep, so it comes back at every renewal with its own controls and evidence. For a small team with no security hire, that is hours taken from the product every month.
A fixed scope keeps the audit smaller. A Security scoped Type 1 with the independent partner auditor goes through our preferred pricing program, and you see the price in your account before you book. The software does most of the work, so the auditor only has to verify evidence that arrives prepared. We negotiate the fee on your behalf. How much SOC 2 costs breaks the full bill down, and how long SOC 2 takes covers the calendar.
The promise behind each optional category
Adding a category is making a promise that an auditor will then test. Here is the promise in one line each, so you can check it against what your contracts actually say.
| Category | You are promising |
|---|---|
| Availability | The service stays up, and you can restore it when it goes down |
| Confidentiality | Marked data stays restricted for as long as the contract says |
| Processing Integrity | Outputs are correct, on time and authorized |
| Privacy | Personal information is handled as your notice says |
Scope to what is written down
Adding categories nobody asked for can feel thorough. It mainly makes a first SOC 2 slower and more expensive, and the buyer who started the project may never read past the cover. Ask that buyer. Their questionnaire or contract names what they need. If Availability matters to them, the uptime clause is probably already in the agreement you signed. Scope to the paper, and revisit next year if a real customer asks. Full definitions of each category are in the Trust Services Criteria guide.1
Scope is set in the engagement letter, and the independent partner auditor confirms it can be done.2 To see how ready you are for a Security scoped report, take the free readiness assessment (about 15 minutes) or compare plans on pricing. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
Which Trust Services Criteria are mandatory?
Should my first SOC 2 include Availability or Confidentiality?
Is a report with more categories a better report?
Can I widen the scope later?
Who sets the final scope?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.