Search all 61 Trust Services Criteria with descriptions, common audit evidence, and ISO 27001 mapping. Covers Security (CC1–CC9), Availability, Confidentiality, Processing Integrity, and Privacy. Built for teams prepping SOC 2 Type 1 and Type 2 audits.
Open any criterion for its intent, the audit evidence assessors expect, and its ISO 27001:2022 mapping.
The AICPA 2017 Trust Services Criteria (revised 2022) define 61 criteria: 33 Common Criteria (CC1–CC9) that make up the Security category, plus Availability (3), Confidentiality (2), Processing Integrity (5) and Privacy (18). Every SOC 2 report includes Security; the other categories are added based on the services you provide.
A Type 1 report assesses the design of your controls at a point in time. A Type 2 report also tests operating effectiveness over a review period (typically 3–12 months), so auditors sample evidence across the whole window. The criteria are identical — this tool lists typical evidence auditors request for each.
Yes. The criteria reference is 100% free and runs entirely in your browser — no account, no sign-up, and nothing is sent to a server. You can also map SOC 2 to ISO 27001 and NIST CSF 2.0 with the Control Mapper.
There is significant overlap: most SOC 2 Common Criteria have equivalent ISO 27001:2022 Annex A controls, so evidence collected for one often satisfies the other. Each criterion page in this tool shows its ISO 27001 mapping, and the Control Mapper provides the full three-framework crosswalk.