Educational drafts — ProofWindow helps founders prepare a first SOC 2. Not legal or audit advice. Not a GRC product.

PW-SOC2-007 SOC 2 readiness spoke

Common Criteria only vs Availability / Confidentiality

TL;DR. Most first reports cover Security (Common Criteria) only. Add Availability if uptime SLAs and resilience are buyer-visible; add Confidentiality when handling sensitive customer data is central to the deal. Extra categories mean more controls, evidence, and cost.

By ProofWindow Editorial Published Last reviewed REVIEW-20260905

Security (Common Criteria) first

Security is the baseline category and includes the Common Criteria. Most seed Type 1 reports start here. It covers control environment, communication, risk, monitoring, and logical/physical access themes relevant to your system.

When to add Availability or Confidentiality

Adding categories expands testing and evidence. Start narrow unless a named deal requires otherwise—and document that requirement.

Questions founders ask

Is Security the same as Common Criteria?

Security uses the Common Criteria as its foundation in the TSC model.

Do we need Privacy too?

Only if in scope for your commitments; it is a separate category with more work.

Can we add Availability later?

Yes in a later period/report—plan evidence now if you expect to.