SOC 2 · 61 criteria · Client-side

SOC 2 Criteria Reference

Search all 61 Trust Services Criteria with descriptions, common audit evidence, and ISO 27001 mapping. Covers Security (CC1–CC9), Availability, Confidentiality, Processing Integrity, and Privacy. Built for teams prepping SOC 2 Type 1 and Type 2 audits.

All 61 SOC 2 Trust Services Criteria

Open any criterion for its intent, the audit evidence assessors expect, and its ISO 27001:2022 mapping.

Control Environment (5)

CC1.1 Integrity and ethical values CC1.2 Board independence and oversight CC1.3 Organizational structure and reporting lines CC1.4 Commitment to competence CC1.5 Accountability for internal control

Communication and Information (3)

CC2.1 Relevant, quality information CC2.2 Internal communication CC2.3 External communication

Risk Assessment (4)

CC3.1 Objectives for risk assessment CC3.2 Risk identification and analysis CC3.3 Fraud risk assessment CC3.4 Assessing significant change

Monitoring Activities (2)

CC4.1 Ongoing and separate evaluations CC4.2 Evaluating and communicating deficiencies

Control Activities (3)

CC5.1 Control activities mitigating risk CC5.2 General controls over technology CC5.3 Policies and procedures

Logical and Physical Access Controls (8)

CC6.1 Logical access security architecture CC6.2 Provisioning and deprovisioning CC6.3 Role-based access and least privilege CC6.4 Physical access restriction CC6.5 Secure disposal CC6.6 Protection against external threats CC6.7 Protection of data in transmission and movement CC6.8 Prevention and detection of malicious software

System Operations (5)

CC7.1 Vulnerability and configuration monitoring CC7.2 Anomaly and security event monitoring CC7.3 Security event evaluation CC7.4 Incident response execution CC7.5 Incident recovery

Change Management (1)

CC8.1 Change management

Risk Mitigation (2)

CC9.1 Business disruption risk mitigation CC9.2 Vendor and business partner risk

Availability (3)

A1.1 Capacity management A1.2 Environmental protections, backup and recovery infrastructure A1.3 Recovery plan testing

Confidentiality (2)

C1.1 Identification and protection of confidential information C1.2 Disposal of confidential information

Processing Integrity (5)

PI1.1 Processing objectives and specifications PI1.2 Input completeness and accuracy PI1.3 Processing completeness, accuracy and timeliness PI1.4 Output completeness, accuracy and distribution PI1.5 Storage of inputs, items in processing and outputs

Privacy (18)

P1.1 Privacy notice P2.1 Choice and consent P3.1 Collection limited to identified purposes P3.2 Explicit consent for sensitive information P4.1 Use limited to identified purposes P4.2 Retention of personal information P4.3 Secure disposal of personal information P5.1 Access to personal information P5.2 Correction of personal information P6.1 Disclosure with consent P6.2 Recording authorized disclosures P6.3 Recording unauthorized disclosures P6.4 Third-party privacy commitments P6.5 Third-party breach notification obligations P6.6 Breach notification to data subjects P6.7 Accounting of disclosures P7.1 Data quality P8.1 Privacy inquiries, complaints and disputes

Frequently asked questions

How many SOC 2 Trust Services Criteria are there?

The AICPA 2017 Trust Services Criteria (revised 2022) define 61 criteria: 33 Common Criteria (CC1–CC9) that make up the Security category, plus Availability (3), Confidentiality (2), Processing Integrity (5) and Privacy (18). Every SOC 2 report includes Security; the other categories are added based on the services you provide.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses the design of your controls at a point in time. A Type 2 report also tests operating effectiveness over a review period (typically 3–12 months), so auditors sample evidence across the whole window. The criteria are identical — this tool lists typical evidence auditors request for each.

Is this SOC 2 tool free and private?

Yes. The criteria reference is 100% free and runs entirely in your browser — no account, no sign-up, and nothing is sent to a server. You can also map SOC 2 to ISO 27001 and NIST CSF 2.0 with the Control Mapper.

Does SOC 2 map to ISO 27001?

There is significant overlap: most SOC 2 Common Criteria have equivalent ISO 27001:2022 Annex A controls, so evidence collected for one often satisfies the other. Each criterion page in this tool shows its ISO 27001 mapping, and the Control Mapper provides the full three-framework crosswalk.