What are the SOC 2 Trust Service Criteria pillars and audit types?
Last updated: September 10, 2025
Context
Organizations pursuing SOC 2 compliance need to understand the different Trust Service Criteria (TSC) pillars and the differences between Type 1 and Type 2 audits to properly scope their compliance efforts.
Answer
SOC 2 has five Trust Service Criteria (TSC) pillars:
Security (mandatory) - This is the foundational pillar required for all SOC 2 audits
Privacy - Covers how personal information is collected, used, retained, and disclosed
Confidentiality - Addresses protection of sensitive information
Availability - Focuses on system availability for operation and use
Processing Integrity - Ensures system processing is complete, valid, accurate, and timely (Note: This pillar is optional and may not be applicable for all organizations)
The key differences between SOC 2 audit types are:
Type 1 - Evaluates the design and implementation of controls at a specific point in time
Type 2 - Assesses both the design and operating effectiveness of controls over a period of time (typically 3-12 months)
Type 2 audits are generally considered more comprehensive as they demonstrate sustained compliance over time rather than just at a single point. The audit period length can affect both the thoroughness of the assessment and the time required to complete the certification process.
I'm still not certain what TSC or Type to go after!
That's alright - Reach out to us and we'll offer some guidance based on your goals and timeline.