Definition
Trust Services Criteria
The Trust Services Criteria are the AICPA control benchmarks that a SOC 2 or SOC 3 examination measures a service organization against. They span five categories: security, availability, processing integrity, confidentiality, and privacy. Every engagement includes security, often called the common criteria, while the other four are optional and chosen to match what a company actually promises its customers. The criteria borrow the seventeen COSO principles and add points of focus that describe what strong controls look like. Your auditor maps each of your controls to these criteria and then tests whether they hold up.
Related services
Keep exploring
← Back to the full glossary