2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
Chapter 3: SOC Engagements & AttestationLesson 3.3

3.3 Evaluating the Trust Services Criteria (Security, Availability, Privacy)

Master the structure of AICPA TSP Section 100 Trust Services Criteria, analyzing the mandatory Common Criteria (Security, CC1-CC9) and the optional Availability, Processing Integrity, Confidentiality, and Privacy criteria.

🎯 Essential Technical Takeaways

  • Security (Common Criteria CC1-CC9) is mandatory in every SOC 2 report and aligns with the 17 COSO internal control principles.
  • Availability criteria (A1.1-A1.3) focus on environmental controls, power redundancy, capacity management, and BCP/DR testing.
  • Processing Integrity criteria (PI1.1-PI1.5) evaluate whether system operations are complete, valid, accurate, timely, and authorized.
  • Privacy criteria (P1-P8) evaluate personal information (PII) against the AICPA Generally Accepted Privacy Principles (GAPP).

SOC 2 and SOC 3 examinations are evaluated against the AICPA Trust Services Criteria (TSP Section 100). The criteria are organized into five distinct categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The 'Security' category—designated as the 'Common Criteria' (CC series)—is mandatory in every SOC 2 examination because unauthorized access inherently threatens the integrity and operation of all other criteria. The CC series incorporates the 17 COSO internal control principles (CC1 through CC5) and supplements them with logical access, physical security, change management, and risk mitigation criteria (CC6 through CC9).

The other four criteria are optional modular add-ons selected based on user commitments: (1) Availability: evaluates whether systems are operational and accessible for committed use, focusing on environmental controls (fire suppression, UPS, diesel generators, redundant HVAC), capacity management, and disaster recovery testing; (2) Processing Integrity: evaluates whether transaction processing is complete, valid, accurate, timely, and authorized, focusing on input validation and automated batch balancing; (3) Confidentiality: evaluates whether information designated as confidential (trade secrets, intellectual property, contract terms) is protected from unauthorized disclosure; and (4) Privacy: evaluates whether personal information (PII) is handled in accordance with the entity's privacy notice and the AICPA Generally Accepted Privacy Principles (GAPP).

When auditing these criteria, the service auditor evaluates both preventative and detective controls, inspecting system configurations, automated log reviews, firewall rulesets, and managerial approvals to determine whether controls operated effectively without exception throughout the testing window.

⚠️ CPA Evolution Exam Traps & Control Pitfalls

  • Attempting to issue a SOC 2 report that excludes the Security (Common Criteria) category.
  • Confusing the Confidentiality criterion (protecting corporate business secrets) with the Privacy criterion (protecting individual PII).
  • Treating environmental power and cooling safeguards as part of Processing Integrity rather than Availability.

Interactive Knowledge Checkpoint

Knowledge Checkpoint • Section 3.3

A software service provider commissions an independent CPA firm to perform a SOC 2 examination covering only the 'Availability' and 'Confidentiality' categories. When the engagement partner reviews the scope, which Trust Services Category must be included in every SOC 2 examination as a mandatory baseline?