SOC 2 Trust Services Categories: Which Should You Choose?
Choose SOC 2 Trust Services Categories from your service, customer requests, commitments, risks, and evidence. Know when Security alone is enough to propose.

For a SOC 2 report, plan to address the Security Common Criteria. Add Availability, Processing Integrity, Confidentiality, or Privacy when the service you provide, what you promise customers, and what report users need make that category relevant. Do not choose all five by default or assume Security alone answers every buyer. Write down the reason for each proposed category and review the set with a qualified CPA firm before relying on an evidence period.
What are the five SOC 2 Trust Services Categories?
The AICPA’s Trust Services Criteria provide criteria for evaluating controls related to Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Common Criteria form the Security baseline. The other categories add criteria for a report that includes them. The criteria are benchmarks for controls, not a fixed list of software settings that every company must copy.
- Security: How does the scoped system guard against unauthorized access or use and other security risks? This is the baseline for a SOC 2 report.
- Availability: Is the system available for operation and use as committed or agreed? Look at uptime, recovery, or service-access commitments that a report user wants examined.
- Processing Integrity: Does the system process information completely, accurately, on time, and as authorized? Consider whether customers rely on the service’s processing results.
- Confidentiality: How does the system protect information designated as confidential? Check the commitments, handling rules, and disposal duties.
- Privacy: How does the system handle personal information under its privacy commitments? Check collection, use, retention, disclosure, and other practices the report user needs examined.
These are prompts for a scope decision, not automatic inclusion rules. A support-ticket system may contain personal information without a customer asking for the Privacy category. A service may promise strong uptime without a buyer requiring Availability in the first report. The obligations and risks still exist even when a category is outside the report. Management must handle them; the category choice defines what this CPA examination will address.
How should a startup choose the categories?
Start with the actual service boundary, then make a short decision record. Do this before adopting a template’s preselected categories.
- Ask the report user. Record the buyer’s exact request, including any named categories. A questionnaire that only says “SOC 2” does not answer this question.
- Read your commitments. Check contracts, service descriptions, privacy notices, data-handling terms, uptime promises, and system requirements. Separate what the company promises from what a template suggests.
- Map the service and information. Name the product, workflows, data types, providers, and people in scope. Identify where processing results, confidential information, or personal information matter to the report.
- Test each proposed category. For every criterion in a category, identify the controls and source evidence the team can support. Do not add a category only because its label sounds reassuring.
- Record the decision. Keep the category, reason, report user, relevant commitment, owner, planned controls, evidence sources, and open gaps in one reviewable record. Take that record to the CPA firm.
For a founder-led team, this connects the sales question to engineering work. If a buyer needs Availability, the team can name the service promise, recovery design, monitoring source, test records, and responsible owner before it commits to a report date. The SOC 2 requirements guide shows how the chosen criteria fit with the system description, controls, evidence, and examination.
Security, Confidentiality, and Privacy are not the same choice
These names overlap in ordinary speech, so read the report question carefully. Security’s Common Criteria address the control environment and protection of systems and information. Confidentiality adds criteria for information the organization has designated as confidential. Privacy adds criteria for personal information and the way it is collected, used, retained, disclosed, and handled under privacy commitments. The AICPA’s Trust Services Criteria define the criteria; use the actual document with your CPA firm to confirm the planned scope.
For example, a code-hosting service may hold customer source code under a confidentiality agreement and also have account-holder contact details. Those facts alone do not prescribe the report categories. Ask what users of this report want assurance about, what the company has promised, and whether the team can support the corresponding criteria. Do not tell a buyer that a Security-only report examined Privacy just because the team also has a privacy notice.
What changes when you add a category?
Adding a category changes the criteria the CPA firm will examine. It may require more controls, owners, source systems, operating records, and testing, although some existing controls may support several criteria. The cost and timing depend on the real gaps, not the category count alone. Use the SOC 2 controls guide to map criteria to how the company actually works.
If management proposes a category after a Type 2 period has begun, check whether the relevant controls operated and evidence exists from the proposed start date. Do not backfill missing history or call management’s candidate dates the CPA-agreed period. Ask the CPA firm whether the category can be included in the intended report and how any gap affects the engagement. The Type 1 versus Type 2 guide explains the date-versus-period difference.
The AICPA’s Description Criteria govern management’s description of the system. They are separate from the Trust Services Categories. Keep the description’s criteria in view even when the report selects only Security. If management includes an optional category but considers one of its criteria not relevant in limited circumstances, record the reason in the description and confirm the treatment with the CPA firm. Do not silently delete the criterion from the plan.
You can keep the decision, criterion mapping, controls, and evidence references in FileGRC’s Git-native GRC workspace. JSON holds structured records, Markdown holds long-form work, and Git supplies the change history. Starter records are proposals, not compliance claims. Your source systems operate the controls and produce evidence; the independent CPA firm performs the examination and decides whether evidence is sufficient.
Run your SOC 2 program as files in Git.
Keep policies, controls, work, and evidence indexes in a repository your team and agents can inspect. Add optional hosted email and Slack reminders to keep work moving.
Frequently asked questions
Which SOC 2 Trust Services Category is required?
Security and its Common Criteria form the baseline for a SOC 2 report. Management may add Availability, Processing Integrity, Confidentiality, or Privacy when the scoped service, commitments, risks, and report users make them relevant. Confirm the planned set with the CPA firm.
Does a startup need all five SOC 2 categories?
No universal rule requires all five categories for every startup. Ask what the report user needs, describe the actual service and commitments, then choose the applicable categories with the CPA firm. Adding a category requires support for its criteria, controls, and evidence.
Does handling personal information require the Privacy category in SOC 2?
Handling personal information makes privacy practices and legal duties important, but it does not by itself settle which categories the intended SOC 2 report will include. Evaluate the report user's request, service commitments, data use, risks, and Privacy criteria with the CPA firm.
What is the difference between Confidentiality and Privacy in SOC 2?
Confidentiality concerns information designated as confidential and how it is protected and disposed of. Privacy concerns personal information and its collection, use, retention, disclosure, and related commitments. A service can have both kinds of information; select categories from the actual scope and report need.
Can I add a SOC 2 category after a Type 2 period starts?
A later category choice can change the controls and evidence the examination needs. Do not assume an earlier period supports a category that the team did not plan or operate. Record the change and ask the CPA firm how it affects scope, period coverage, testing, and report wording.
Can FileGRC choose SOC 2 categories for my company?
No. FileGRC can organize management's criteria, scope, controls, work, and evidence as JSON and Markdown records with Git history. Management chooses the proposed report scope, while the CPA firm agrees on the engagement and evaluates evidence.