Deep dives on the five Trust Services Criteria and the COSO-based Common Criteria (CC1–CC9) that anchor every SOC 2. ← Back to SOC 2: The Complete Guide
The five criteria
Criterion | Guide |
|---|---|
Security (required) | |
Availability | |
Processing Integrity | |
Confidentiality | |
Privacy |
The Common Criteria (CC1–CC9, COSO components)
Area | Guide |
|---|---|
CC1 Control Environment | |
CC2 Communication & Information | |
CC3 Risk Assessment | |
CC4 Monitoring Activities | |
CC5 Control Activities |
How the criteria work
Guide | What you'll learn |
|---|---|
The mandatory CC baseline in every report | |
When to add Availability/PI/Confidentiality/Privacy | |
Defining expected outcomes | |
Creating effective controls (Type I focus) | |
Demonstrating consistent performance (Type II) |
Resources: TSC Mapping Template · Control Matrix / RACI
