Educational guides — ProofWindow publishes educational guides on first SOC 2 readiness. Not legal or audit advice. Not a GRC product.

PW-SOC2-007 SOC 2 readiness spoke

SOC 2 Security-only vs Availability / Confidentiality

TL;DR. Most first reports cover Security (Common Criteria) only. Add Availability if uptime SLAs and resilience are buyer-visible; add Confidentiality when handling sensitive customer data is central to the deal. Extra categories mean more controls, evidence, and cost.

Claim ladder Material statements on this page are labeled Verified, Inferred, or Unknown per editorial standards.

Key terms: Trust Services Criteria, Common Criteria.

By ProofWindow Editorial Published Last reviewed REVIEW-20260905

On this page

Security (Common Criteria) first

Security is the baseline category and includes the Common Criteria. Most seed Type 1 reports start here. It covers control environment, communication, risk, monitoring, and logical/physical access themes relevant to your system.

When to add Availability or Confidentiality

Adding categories expands testing and evidence. Start narrow unless a named deal requires otherwise—and document that requirement.

Questions founders ask

Is Security the same as Common Criteria?

Security uses the Common Criteria as its foundation in the TSC model.

Do we need Privacy too?

Only if in scope for your commitments; it is a separate category with more work.

Can we add Availability later?

Yes in a later period/report—plan evidence now if you expect to.

Sources

  1. primary 2017 Trust Services Criteria (With Revised Points of Focus – 2022) — AICPA & CIMA — Authoritative TSC document (Security/Availability/Processing Integrity/Confidentiality/Privacy).
  2. primary SOC 2 — SOC for Service Organizations: Trust Services Criteria — AICPA & CIMA — Official SOC 2 topic landing; defines SOC 2 as examination of controls relevant to TSC categories.