Trust Service Principles (TSP)

AICPA criteria for SOC 2: Security, Availability, Processing Integrity, Confidentiality, Privacy.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

The Trust Service Principles (TSP) are the five criteria established by the American Institute of Certified Public Accountants (AICPA) that form the foundation of SOC 2 reports: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security (also known as the Common Criteria) is mandatory for every SOC 2 engagement, whilst the remaining four principles are selected based on the nature of the services provided. Each principle defines specific control objectives that organisations must meet to demonstrate trustworthy operations.

For organisations seeking SOC 2 certification, understanding which Trust Service Principles apply to their services is a critical first step. The principles provide a clear and auditable framework for demonstrating to customers and stakeholders that appropriate controls are in place. Aligning internal controls with the TSP criteria also streamlines audit preparation and can reduce the time and cost of achieving certification.

U

V

W

Z

Frequently asked questions

What are the Trust Service Principles?
They are the categories a SOC 2 report can cover: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security — the common criteria — is always in scope; the other four are chosen based on what you commit to customers.
Are they called Principles or Criteria?
Criteria is now correct. The AICPA renamed the Trust Services Principles to the Trust Services Criteria (TSC) in 2017. Both terms are still used in practice and refer to the same framework.
Which categories should you include in a SOC 2?
Only those you can genuinely evidence and that your customers ask about. Security is mandatory; Availability suits infrastructure and SaaS commitments, and Confidentiality suits sensitive customer data. Privacy applies where you make commitments about personal information you collect and use yourself — processors of customer data often address it under Confidentiality instead. Adding categories adds audit effort.