PW-SOC2-007 SOC 2 readiness spoke
Common Criteria only vs Availability / Confidentiality
TL;DR. Most first reports cover Security (Common Criteria) only. Add Availability if uptime SLAs and resilience are buyer-visible; add Confidentiality when handling sensitive customer data is central to the deal. Extra categories mean more controls, evidence, and cost.
Security (Common Criteria) first
Security is the baseline category and includes the Common Criteria. Most seed Type 1 reports start here. It covers control environment, communication, risk, monitoring, and logical/physical access themes relevant to your system.
When to add Availability or Confidentiality
- Availability — customers care about uptime, DR, capacity; you already test restores and track incidents against SLAs.
- Confidentiality — protecting confidential information is a contractual centerpiece beyond general security claims.
Adding categories expands testing and evidence. Start narrow unless a named deal requires otherwise—and document that requirement.
Questions founders ask
Is Security the same as Common Criteria?
Security uses the Common Criteria as its foundation in the TSC model.
Do we need Privacy too?
Only if in scope for your commitments; it is a separate category with more work.
Can we add Availability later?
Yes in a later period/report—plan evidence now if you expect to.