Track: SOC 2 basics · Lesson 3 of 10
The five SOC 2 trust services categories, explained
Short answer
SOC 2 reports address one or more of five categories: security, availability, processing integrity, confidentiality and privacy. Security is the base of every SOC 2 report. The others are added when customers need them, and each one adds controls to prepare and evidence to collect.
By the SOC 2 Vendor Compare ledger desk · Published 2025-03-18 · Reviewed 2026-09-29 · Editorial assessment
What does security cover?
Security is about protecting information and systems against unauthorized access and use. Its criteria, often called the common criteria, cover governance, risk assessment, access control, change management, monitoring and incident response. Every SOC 2 report includes it.
What do availability and processing integrity cover?
Availability covers whether the system is available for operation and use as committed, for example through capacity planning, backups and recovery. Processing integrity covers whether processing is complete, valid, accurate and timely. Companies that sell uptime commitments often add availability; companies whose product transforms customer data, such as billing or data pipelines, sometimes add processing integrity.
What do confidentiality and privacy cover?
Confidentiality covers information designated as confidential, such as customer business data, from collection to disposal. Privacy covers personal information and how it is collected, used, retained and disclosed. Privacy overlaps with laws such as GDPR and CCPA, which is one reason buyers ask whether a platform maps SOC 2 controls to those frameworks.
How do you choose the scope?
Start with what your customers ask for in security reviews. Adding a category means more controls to design and more evidence to keep, so do not add one only because it sounds complete. Your auditor can advise on scope, and a compliance expert, where the vendor provides one, can help you decide before the audit is booked.
How do platforms handle the categories?
All six vendors on our ledger support SOC 2, and all of them organize controls against the criteria. The difference shows when you add other frameworks: some vendors state cross-mapping or a common control framework, so one control can satisfy several requirements. See Adding ISO 27001 or a second framework after SOC 2 and the framework criterion on the rankings.
What do customers check in the report?
Security reviewers usually read the auditor's opinion, the scope and system description, the list of controls and, in a Type II, any exceptions. They also check the report date and the categories covered. If a customer needs availability commitments covered and your report covers security only, expect follow-up questions. Knowing what your main customers read helps you choose the categories before the audit, not after.