A muted flat illustration of an open office with a glass walled meeting room, a blank whiteboard, shelves of plain binders, and a server rack.

Trust Services Categories are not the Trust Services Criteria

Trust Services Categories and Trust Services Criteria both shorten to TSC. One groups the criteria for scoping. The other is what you are tested against.

Say SOC to a room of engineers, and most of them hear “security operations center”, not a compliance report. It’s frankly just what that industry thinks of when it hears the word. Say it in a room of auditors, and it means something else. In a compliance auditing context, it commonly refers to System and Organization Controls. Same three letters, different conversations.

One person says SOC at a whiteboard while two thought bubbles go different directions, one showing a wall of security monitors and the other a bound audit report.

Now, Trust Services Categories and Trust Services Criteria both shorten to TSC. This is really where the confusion can start, as well as just assuming they both mean the same thing.

Now when somebody on a scoping call asks which TSCs are in scope, and depending on who is in the room, that can mean two different things.

Categories and the Criterion used within the SOC framework (specifically SOC 2 Reports) mean different things as they reside at different layers, and mixing them up changes what you mean. For a SOC 2 Report, the Report can cover 5 different areas that can drastically impact the scope of your report.

The five are categories

The trust services criteria are classified into the following categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Those five are the categories. The criteria are the requirements underneath them, and the arrow runs only in one direction.

Underneath sits one body of criteria. The common criteria, CC1.1 through CC9.2, apply across all five. Security is satisfied by the common criteria alone. Availability, processing integrity, confidentiality, and privacy each add their own criteria.

A diagram with five Trust Services Category chips on top, an arrow labeled classified into running upward, and beneath it the common criteria block spanning all five plus the extra criteria each category adds.

So, “we need all five criteria” is not a fact about the standard. Which categories did the customer ask for? Is the appropriate context. The honest answer is usually security, as it’s considered “standard” in the common criteria areas.  A common category to be issued in the next SOC 2 Report would be confidentiality. Using “Criteria” instead of “Categories” is just, frankly, a common verbiage mistake. The phrase gets handed from a questionnaire to a slide, and by the time it reaches your auditor, it sounds like a requirement.

It is not.

Points of focus are optional

Points of focus are optional angles used to ensure the criteria assess the right things.

The source is blunt. The Trust Services Criteria “do not require an assessment of whether each point of focus is addressed.”

Staring at a readiness checklist with a row per point of focus? Points of focus describe characteristics of a criterion. They are not controls you owe anyone. They may help management and the auditor judge whether controls were well designed and are operating effectively.

May.

On my side of the table, I test controls against the criterion. My focus is on how I check that I asked about the right things. An auditor focuses on how they become comfortable with control wording and the testing of controls in the workpapers; there may be coverage notes and details on the scope indicating whether the points of focus were mapped against control wordings to demonstrate criteria, but this is again at management’s discretion.

A control owner wheels in a hand truck stacked with eleven identical binders labeled CC6.1 while a seated auditor holds up a single finger.

Where the criteria came from

The criteria align with the 17 principles of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) internal control framework. You will see the supplemental criteria described as not aligned with COSO. That has it backward. They supplement COSO principle 12, the one about putting policies into action.

Which categories belong in your report is a separate argument. Confidentiality versus privacy is where most of it comes down to.

Next time somebody says “TSC” on a call, ask which one they mean. A lot of folks will say “trust services criteria” when they mean “category.”

Which criteria come with which categories

Once you pick the Trust Services Categories in your report. The tool shows the criteria that come with them.

Trust Services Categories
Criteria in scope
    Criteria your controls are evaluated against33

    Points of focus are not in this count on purpose. They sit beneath individual criteria and describe characteristics. Using the criteria does not require assessing whether each point of focus is addressed; they are not requirements. I would think of them more as a guide to help understand the intention of the criteria and get you thinking about what the control language should look like.

    A criteria count is not a control count and not a price. One criterion can be met by one control or by several, and a control can address more than one criterion. Scope also depends on your system, your service commitments, and what your contracts and potential customers care about.

    Source: AICPA 2017 trust services criteria, with revised points of focus 2022—more at sageaudits.com.