RoutineMetric

AICPA SOC 2 Scoping & Trust Services Criteria (TSC) Evaluator

Assess your organization's SOC 2 audit readiness. Define your system profile and customer SLA commitments to discover which Trust Services Criteria (TSC) apply to your upcoming audit, complete a GAP-assessment, and export a printable scoping memo.

1. System & Business Profile

Business models automatically trigger related Trust Criteria according to standard AICPA audit frameworks.

We guarantee specific uptime thresholds (e.g. 99.9%+) to our clients.

We sign custom NDAs or have strict clauses protecting client IP/proprietary records.

We promise error-free transactional, payroll, financial billing, or critical processing.

We collect and process consumer records subject to privacy acts (GDPR, CCPA).

2. Determined SOC 2 Audit Scope

Based on your business model and agreements, your auditor will expect the following criteria to be audited. Security is the mandatory baseline, and others are included based on contractual commitments:

Security (Common Criteria)MandatoryProtection against unauthorized access, use, or modification of systems and data. Mandatory for all SOC 2 audits.
IN SCOPE
AvailabilityEnsuring systems and services are operational, reliable, and available as committed in customer agreements and service SLAs.
IN SCOPE
ConfidentialityProtection of data designated as confidential by contracts, NDAs, or proprietary policies from unauthorized disclosure.
IN SCOPE
Processing IntegrityEnsuring system processing is complete, valid, accurate, timely, and authorized to prevent calculation or data corruption errors.
EXCLUDED
PrivacyProtection of personally identifiable information (PII) in accordance with regulatory mandates (GDPR, CCPA) and AICPA principles.
EXCLUDED
Dynamic Scope Status3 of 5 Trust Criteria Scoped
Selecting correct criteria upfront prevents over-auditing, saving up to $15,000+ in auditor fees.

3. Trust Criteria GAP Assessment

Security (Common Criteria)

Score: 0%
SEC-1AICPA Code: CC6.1, CC6.2, CC6.3Access Control

Are logical access controls (Multi-Factor Authentication, Single Sign-On, and Role-Based Access Control) enforced for all systems, employees, and cloud databases?

SEC-2AICPA Code: CC3.1, CC3.2Risk Assessment

Does the organization perform annual risk assessments, document mitigation strategies, and manage a formal threat register?

SEC-3AICPA Code: CC8.1Change Management

Are all infrastructure, server configuration, and software changes peer-reviewed, documented, and fully tested in staging prior to production deploy?

SEC-4AICPA Code: CC7.3, CC7.4Incident Response & Logging

Is there a documented Incident Response Plan tested annually, with system and application access logs continuously monitored via SIEM?

Confidentiality

Score: 0%
CON-1AICPA Code: C1.1Data Classification & Safeguards

Is sensitive client data clearly classified, with storage isolated from general data and access granted strictly under the principle of least privilege?

CON-2AICPA Code: C1.2Encryption Standards

Is customer data encrypted both in transit (TLS 1.3 with high-strength cipher suites) and at rest (AES-256 with robust key rotation)?

CON-3AICPA Code: C1.3Secure Destruction & Disposal

Are procedures for secure, audited data erasure and hardware sanitization established, ensuring total data disposal at contract termination?

Availability

Score: 0%
AVL-1AICPA Code: A1.1Capacity Management

Are system performance, latency, memory, and database capacity metrics continuously monitored, with proactive automated alerts for resource depletion?

AVL-2AICPA Code: A1.2Disaster Recovery & Backups

Are production databases and critical files backed up on a daily basis, stored offsite/cross-region in an encrypted state, and tested annually for full recovery?

AVL-3AICPA Code: A1.3Business Continuity & Failovers

Are high availability configurations, multi-zone hosting, and clear Business Continuity Plans (BCP) established and verified through tabletop exercises?

Readiness Scorecard

Overall Audit Readiness0%

Low readiness. Complete foundational Security Common Criteria controls to avoid a qualified opinion.

Readiness by Criterion
Security (Common Criteria)0%
Confidentiality0%
Availability0%
Pending Action Items (10)
SEC-1: Access ControlNeeds implementation support.
SEC-2: Risk AssessmentNeeds implementation support.
SEC-3: Change ManagementNeeds implementation support.
SEC-4: Incident Response & LoggingNeeds implementation support.
CON-1: Data Classification & SafeguardsNeeds implementation support.
CON-2: Encryption StandardsNeeds implementation support.
CON-3: Secure Destruction & DisposalNeeds implementation support.
AVL-1: Capacity ManagementNeeds implementation support.
AVL-2: Disaster Recovery & BackupsNeeds implementation support.
AVL-3: Business Continuity & FailoversNeeds implementation support.
Advertisement
Bottom Banner Ad (728x90)

The Executive Guide to AICPA SOC 2 Scoping and Trust Services Criteria (TSC)

AICPA SOC 2 (System and Organization Controls 2) is the standard-bearer for B2B cybersecurity audits in North America. For modern SaaS providers, data processing institutions, and managed IT organizations, presenting a clean SOC 2 Type II audit report is frequently a non-negotiable prerequisite to signing mid-market and enterprise accounts.

Unlike rigid compliance checkmarks, SOC 2 is highly customizable. It is designed around five core Trust Services Criteria (TSC). Correctly scoping which criteria are mandatory for your service organization prevents "scope creep," which can inflate your CPA audit fees, overwhelm internal engineers, and result in long delayed compliance roadmaps.

1. Understanding the Five Trust Services Criteria

The AICPA framework includes the following criteria, with Security serving as the mandatory foundation:

  • Security (Common Criteria): Focuses on network protection, physical controls, logical access limits (MFA, SSO), vulnerability discovery, incident response, and change authorization. Every SOC 2 report must audit the Security criteria.
  • Availability: Examines whether systems are operational and available to meet commitments in service level agreements (SLAs). Key elements include disaster recovery testing, offsite redundant backups, data replication, and auto-scaling capacity monitoring.
  • Confidentiality: Governs data classified as confidential by contracts, customer agreements, or regulatory categories. Focuses heavily on end-to-end data encryption (AES-256), secure key rotations, structured data classification policies, and certified hardware sanitization.
  • Processing Integrity: Validates whether applications process inputs completely, accurately, and within authorized guidelines. Essential for fintechs, billing gateways, and data processing nodes that must prevent transaction duplication or database mismatch errors.
  • Privacy: Evaluates personal information (PII) collection, usage, retention, and deletion practices against the AICPA's strict Privacy principles. Critical for companies dealing directly with consumer health records or managing European/California user profiles.

2. SOC 2 Type I vs. SOC 2 Type II Reports

Organizations typically proceed through two distinct certification phases:

  • SOC 2 Type I: Audits the design of your controls at a specific point in time. It proves that you have documented policies, MFA is active, and server monitoring is operational on the day the auditor evaluates the system. Excellent for initial marketing needs.
  • SOC 2 Type II: Audits both the design and operational effectiveness of your controls over a continuous observation window (typically 3, 6, or 12 months). The auditor collects systematic samples to verify that policies were continuously active and never bypassed.

3. How to Remediate Gaps Before the Audit Starts

CPA firms perform independent, adversarial audits. If they find systematic exceptions (e.g. key developers committing code without peer approval or databases stored without encryption), they may issue a "qualified opinion" or adverse report, which damages your commercial reputation.

Prior to scheduling the audit, run a complete gap assessment using the tool above. Remediate any controls marked as "Not Implemented" by setting up modern tooling: use infrastructure-as-code to enforce server setups, secure cloud access with Single Sign-On, draft a complete incident response document, and run automated recovery drills on your production database backups.

Advertisement