← Glossary·Frameworks

Trust Services Criteria (TSC)

Also known as: AICPA TSC · TSC 2017
SOC 2

The five AICPA criteria categories underpinning SOC 2: Security, Availability, Confidentiality, Processing Integrity, Privacy.

The Trust Services Criteria (2017, revised 2022) are the AICPA's control criteria used to evaluate suitability of design and operating effectiveness in SOC 2 engagements. The Security (Common Criteria, CC1–CC9) category is mandatory; the other four (A, C, PI, P) are optional and chosen based on customer commitments.

Why it matters
Choosing the right TSC categories upfront is critical — adding Privacy mid-engagement can triple audit cost and timeline.

Related terms

SOC 2
AICPA attestation report on a service organisation's controls across five Trust Services Criteria.
Common Criteria (CC1–CC9)
The nine Common Criteria categories that make up the Security TSC in SOC 2 — control environment through change management.
SOC 2 Type I vs Type II
Type I = design of controls at a point in time. Type II = design + operating effectiveness over a period (typically 3–12 months).

Does your program actually cover Trust Services Criteria (TSC)?

Run a free ComplianceIQ audit against SOC 2 and we'll surface every gap on this — and the other controls auditors flag — with the exact clause references to fix.

Free SOC 2 auditBack to glossary