MDRwatchdog
Home › Trust Services Criteria
MDRwatchdog Compliance

The Trust Services Criteria, explained

SOC 2 is built on the AICPA's Trust Services Criteria - five categories that define what a SOC 2 report can cover. Security is always included; the other four are optional depending on what your business does and what your buyers need. Choosing the right scope keeps your audit focused and affordable.

Book a 15-minute review →

Security (the Common Criteria) is mandatory and forms the backbone of every SOC 2: access controls, monitoring, change management, risk management, and incident response. If you only include one category, it's this one - and for many companies it's enough.

The optional four: Availability (your system is up and recoverable as committed), Processing Integrity (processing is complete, accurate, and timely), Confidentiality (confidential data is protected), and Privacy (personal information is handled per your notice and criteria). Each adds controls, evidence, and cost.

Choosing scope: add only what your buyers actually require. A SaaS platform with uptime SLAs might add Availability; a company handling sensitive customer data might add Confidentiality. Adding all five 'to be thorough' inflates cost without helping close deals.

MDRwatchdog maps continuous monitoring to whichever criteria you scope, marks what's evidenced, and flags what needs attention - so you can right-size your SOC 2 to what buyers demand. Readiness and evidence; the report is issued by a licensed CPA firm. Not legal advice.

Frequently asked questions

What are the five Trust Services Criteria?

Security (always required), plus optionally Availability, Processing Integrity, Confidentiality, and Privacy. Security forms the Common Criteria backbone of every SOC 2 report.

Which criteria do I need?

Security is mandatory. Add others only if your buyers require them - Availability for uptime commitments, Confidentiality for sensitive data, and so on. Adding all five inflates cost unnecessarily.

Does adding criteria increase cost?

Yes. Each additional criterion adds controls, evidence, and audit scope. Scope to what your buyers actually need.

MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).