Which Trust Services Criteria should I include? Four questions decide

Security is always in scope. Anything else needs a contract behind it, and this tool tells you which.

Which Trust Services Criteria should I include? Security, always. It is required in every SOC 2 report1 and covers what buyers care about. The other four categories are optional. Add one only when a contract you already signed commits you to it.

Answer the four questions based on the contracts you have today, not the ones you hope to sign. The tool lists the categories that follow and explains each.

Have you signed a customer contract that promises uptime, service credits, or a recovery time?
Does a contract mark some of the data you hold as confidential and require you to return or destroy it?
Do you process transactions or records for customers, where a wrong result lands on them?
Do you collect personal information under your own privacy notice, not only as a processor for customers?
1of five categories in scope
0added because a contract requires it
Security
Always included, in every SOC 2. It covers access, change management, monitoring and incident response, and it is what a buyer means by asking for a SOC 2.

Security and nothing else. That is a complete scope for a first report, and it is exactly what cybersoftware covers, from readiness through the Type 1 report.

Why every added category costs money

An audit is priced on the work, and scope is the work. Each extra category brings more controls to design, more evidence to collect every month, and more hours of testing. Two companies of the same size, one scoped to Security and one to all five, are buying different things and will get different quotes.

The cost does not stop at the first report. A category you add this year is one you are expected to keep, so it comes back at every renewal with its own controls and evidence. For a small team with no security hire, that is hours taken from the product every month.

A fixed scope keeps the audit smaller. A Security scoped Type 1 with the independent partner auditor goes through our preferred pricing program, and you see the price in your account before you book. The software does most of the work, so the auditor only has to verify evidence that arrives prepared. We negotiate the fee on your behalf. How much SOC 2 costs breaks the full bill down, and how long SOC 2 takes covers the calendar.

The promise behind each optional category

Adding a category is making a promise that an auditor will then test. Here is the promise in one line each, so you can check it against what your contracts actually say.

CategoryYou are promising
AvailabilityThe service stays up, and you can restore it when it goes down
ConfidentialityMarked data stays restricted for as long as the contract says
Processing IntegrityOutputs are correct, on time and authorized
PrivacyPersonal information is handled as your notice says

Scope to what is written down

Adding categories nobody asked for can feel thorough. It mainly makes a first SOC 2 slower and more expensive, and the buyer who started the project may never read past the cover. Ask that buyer. Their questionnaire or contract names what they need. If Availability matters to them, the uptime clause is probably already in the agreement you signed. Scope to the paper, and revisit next year if a real customer asks. Full definitions of each category are in the Trust Services Criteria guide.1

Next step

Scope is set in the engagement letter, and the independent partner auditor confirms it can be done.2 To see how ready you are for a Security scoped report, take the free readiness assessment (about 15 minutes) or compare plans on pricing. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

Which Trust Services Criteria are mandatory?
Security only. It is the common criteria set, and every SOC 2 report includes it. Availability, Confidentiality, Processing Integrity and Privacy are optional and get added when a contract or buyer calls for them.
Should my first SOC 2 include Availability or Confidentiality?
Only if a signed contract points there. Uptime or recovery time commitments suggest Availability. A contract that marks data as confidential and requires you to return or destroy it suggests Confidentiality. Without those, Security on its own answers the question buyers are asking.
Is a report with more categories a better report?
It is a bigger report, not a better one. Each category adds controls to build, evidence to collect every month and testing hours for the auditor, and all of that costs money. A category no customer asked for is spending with no return.
Can I widen the scope later?
Yes, scope is set per examination, so a later report can cover more. That wider report would come from a firm that runs it directly, because cybersoftware scopes Security only and does not change that per customer.
Who sets the final scope?
You and the CPA firm, in the engagement letter. Through cybersoftware the scope is Security, so this tool shows what a wider contract would imply rather than something we deliver. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.