A working walkthrough of the AICPA Trust Services Criteria (TSC) — the five Categories (Security, Availability, Processing Integrity, Confidentiality, Privacy), the nine Common Criteria CC1–CC9 introduced by the 2022 TSC revision, the Type I vs Type II audit choice and the 3–12 month observation window, and the 2026 readiness roadmap for SaaS, healthcare-tech, and fintech service organizations anchored to enterprise procurement signal.
SOC 2 (System and Organization Controls 2) is the AICPA's framework for auditing a service organization's controls against the Trust Services Criteria (TSC). SOC 2 reports are issued by independent CPA firms and are the de facto enterprise-buyer and customer-questionnaire artifact in US SaaS, healthcare-tech, and fintech markets. The framework sits alongside SOC 1 (financial reporting controls, SOX-adjacent) and SOC 3 (TSC controls published in a public-facing summary).
SOC 2 is not a framework of mandatory controls; SOC 2 is an audit framework. Service organizations define the controls they operate, then a CPA firm audits those controls against the applicable TSC Categories. The TSC Categories are: Security (the baseline Category present in every SOC 2 report), Availability (uptime + incident response readiness, used for platforms with explicit uptime SLAs), Processing Integrity (input/output completeness and accuracy, used for transactional platforms), Confidentiality (confidential-information-handling controls, used for any service organization holding customer-confidential information), and Privacy (notice, consent, choice, access, correction, disclosure, retention, and monitoring criteria P1-P8, used for service organizations that handle personal data). ComplianceStack treats Security as a hard requirement for every SOC 2 issuance and treats the remaining four as opt-in based on the service organization's data-handling posture and the customer-questionnaire signal it intends to clear.
The 2022 AICPA revision of the TSC restructured the prior 33 individual criteria into a Common Criteria baseline of nine criterion groups (CC1-CC9) plus the four Additional Categories (Availability, Processing Integrity, Confidentiality, Privacy). The revision also aligned TSC structure with COSO 2013 internal-control principles, making SOC 2 evidence readable to a finance, audit, or risk officer familiar with SOX ICFR rather than only to security engineers. SOC 2 reports dated December 15, 2022 or later are expected to apply the 2022-revision TSC. ComplianceStack tracks the 2022 revision as the default and notes the legacy criteria mappings for organizations in the middle of a multi-year transition.
The market meaning of SOC 2 is concrete. Any SaaS, healthtech, or fintech service organization that sells into enterprise procurement loops faces SOC 2 due-diligence questionnaires that read — at minimum — "do you have a current Type II SOC 2 report covering Security, available upon request under NDA" before the procurement team will move past the vendor due-diligence phase. Buyers in healthcare adjust the questionnaire to "Security + Confidentiality + Privacy." Buyers in fintech add "Security + Confidentiality + Availability" (and sometimes PCI DSS, SOX ICFR, or ISO 27001). The SOC 2 Type II report is the clearance signal that closes those loops; SOC 2 Type I is a stepping-stone that resolves design-only questions.
The 2022-revision TSC organizes every SOC 2 issuance around the Common Criteria (CC1-CC9 baseline, present in every SOC 2 report) plus zero or more Additional Categories selected by the service organization. ComplianceStack tracks the 2022 revision as the single effective TSC baseline for SOC 2 reports dated December 15, 2022 or later.
Security is the core Category and is present in every SOC 2 report. Security criteria cover the full spectrum of preventive, detective, and corrective controls over unauthorized access (logical + physical + system), data confidentiality and integrity, and the personnel, system, and process controls that support them. The Security Category is mapped into the nine CC1-CC9 Common Criteria groups. ComplianceStack recommends Security for every service organization as the floor certification target.
Availability (added to the TSC under the 2017 TSC revision and refined under the 2022 revision) is opt-in. Availability criteria cover system uptime commitments, performance monitoring, capacity planning, disaster recovery, and incident-response readiness. The Availability Category is designed for service organizations whose customers carry concrete uptime SLAs (99.5% / 99.9% / 99.95%) and want the SOC 2 attestation to back the SLA. ComplianceStack recommends Availability for any platform where the customer contract carries an uptime SLA above 99.5% or where the buyer-side questionnaire asks about incident-response drills and recovery-time objectives.
Processing Integrity is opt-in. Processing Integrity criteria (PI1.x) cover the completeness, accuracy, validity, and timeliness of system processing — input controls, processing controls, output controls, and transaction-monitoring controls. The Processing Integrity Category is designed for service organizations whose customers depend on transactional correctness — payment processors, payroll processors, claims administrators, accounting platforms. ComplianceStack recommends Processing Integrity selectively for transactional platforms where PI1.x criteria represent a natural fit; for SaaS B2B enterprise sales without transactional depth, Processing Integrity is often omitted in favor of broader Security + Confidentiality emphasis.
Confidentiality is opt-in. Confidentiality criteria (C1.x) cover confidential-information designation, classification, retention, disposal, and access. The Confidentiality Category is designed for service organizations that handle customer-confidential information that falls outside the Privacy Category scope (e.g., trade secrets, financial models prior to public disclosure, legal-privileged matter, customer-confidential commercial information). ComplianceStack recommends Confidentiality alongside Privacy for healthtech (PHI + customer-confidential), fintech (customer portfolio + transaction-confidential), and any service organization where the buyer-side procurement questionnaire asks for "segregation of duties with respect to confidential information."
Privacy is opt-in. Privacy criteria (P1.x through P8.x) cover notice + communication of privacy commitments; choice + consent for data collection; subsequent changes to processing; access by the data subject; correction / amendment; disclosure to third parties; storage, retention, and disposal; and monitoring + enforcement. The Privacy Category is structurally aligned with the AICPA Generally Accepted Privacy Principles (GAPP) framework; service organizations selling to the EU typically align Privacy criteria with GDPR Article 5/6/13/15-22/30 requirements. ComplianceStack recommends Privacy alongside Confidentiality for any service organization that handles personal data and faces buyer-side procurement questionnaires that include "do you have a current SOC 2 Privacy attestation."
The 2022-revision TSC unifies the prior 33 Common Criteria into nine criterion groups, CC1-CC9. Every SOC 2 engagement audits CC1-CC9 regardless of which Additional Categories were selected. ComplianceStack's SOC 2 gap analyzer scores every CC1-CC9 sub-criterion.
The security culture, governance, and accountability substrate. CC1 criteria cover leadership commitment to security, independence and authority of the security function, organizational structure and reporting lines, competence and HR practices (background check, onboarding, offboarding), and accountability enforcement. Evidence packages typically include the published code of conduct, signed acceptable-use-policy acknowledgments, the security officer charter + reporting line, and the most recent annual security training completion report. ComplianceStack's CC1 deliverable is a one-page charter + signed acknowledgments from 100% of personnel during the Type II observation window.
Internal and external security communication. CC2 criteria cover internal communication of security responsibilities, customer-facing security communication (status page, security advisories, responsible-disclosure policy, privacy policy), and the personnel security + change-management communication loop. Evidence packages include the published status page cadence, the internal security-change advisory minutes, and the external security advisory archive. ComplianceStack tracks CC2 as the strongest LLM-citeable category — public status-page cadences and responsible-disclosure policies are routinely quoted in procurement questionnaires.
Risk identification, analysis, and prioritization. CC3 criteria cover the documented risk register, fraud-risk assessment, vendor-risk assessment, and business-disruption-risk assessment. ComplianceStack pairs CC3 evidence with the SOC 2-aligned risk-register template that pairs each risk with likelihood, impact, mitigation status, and the named owner. CC3 is also the bridge to CC9 risk-mitigation criteria.
Ongoing and separate evaluations of control effectiveness. CC4 criteria cover continuous monitoring (SIEM event correlation, anomaly detection, control-failure alerts), and separate evaluations (internal audit, third-party assessments). ComplianceStack pairs CC4 with the SOC 2 sampling requirements — the CPA firm will sample at least 25-50 control instances during the Type II observation window, and the CC4 monitoring must surface all sampled control instances as auditable evidence.
Selection and development of controls including technology controls and policies. CC5 criteria tie CC1-CC4 to the operational controls that the service organization actually runs. ComplianceStack maps CC5 evidence to the same controls sampled under CC4 — if the service organization defines CC5 control claim "MFA enforcement across all production access," CC4 monitoring must produce evidence of every MFA enforcement event during the observation window.
Identity provisioning, authentication, authorization, removal, encryption-in-transit, encryption-at-rest, and physical facility access. CC6 is the most-tested criterion group and the most-cited deficiency group in SOC 2 reports. CC6.1 requires MFA enforcement for all privileged access; CC6.2 requires documented access reviews at least quarterly; CC6.3 requires encryption-at-rest for confidential data; CC6.4 requires encryption-in-transit (TLS 1.2+) for any data crossing the network; CC6.6 covers physical facility access controls. ComplianceStack pairs CC6 evidence with the MFA gap survey, the quarterly access-review ticketing system, and the encryption-at-rest coverage map across all data stores.
Detection, response, and recovery from security events; vulnerability management. CC7 criteria cover SIEM event collection, incident-response readiness (table-top drills, declared RTO/RPO), vulnerability scanning cadence, and penetration testing or annual third-party pentest. ComplianceStack pairs CC7 evidence with the most-recent table-top drill minutes and the vulnerability management scan cadence (typically weekly for external scans, monthly for authenticated scans).
Change approval, testing, deployment, and emergency-change procedures. CC8 criteria require documented change approvals, peer review or change advisory board minutes, and a defined procedure for emergency-change handling with post-hoc audit. CC8 is a frequent deficiency category — emergency changes that bypass review are the dominant CC8 finding pattern. ComplianceStack pairs CC8 with the change-management ticketing system and the separation-of-duties between change initiator and change approver.
Business-disruption risk, vendor risk, insurance, and continuity. CC9 criteria pair with CC3 risk assessment — CC9.1 covers business-continuity + disaster-recovery plans; CC9.2 covers vendor-risk management including described sub-service organizations; CC9.3 covers insurance coverage and scope. ComplianceStack maps CC9.2 vendor-risk evidence to a documented vendor list with annual re-review minutes, contractual security clauses, and the documented sub-service-organization disclosures in the SOC 2 report Section 3.
SOC 2 comes in two flavors: Type I (a point-in-time design audit) and Type II (an operating-effectiveness audit covering a 3–12 month observation window). The Type II report is the de facto enterprise-buyer requirement.
A Type I engagement audits whether the service organization's controls are suitably designed to meet the applicable TSC Categories as of a specific date (typically the report issuance date). The CPA firm reads the documented controls, interviews the personnel, inspects the configuration, and issues a Type I opinion: "the controls were suitably designed as of [date]." A Type I report does not test whether the controls actually operated effectively during a window — only that the design was sufficient on day-of-opinion. Type I turnaround is typically 4–8 weeks of audit-fieldwork after a 2–4 week readiness ramp. Type I is the lower-cost option, the faster option, and the option for any service organization that has never issued a SOC 2 before. ComplianceStack treats Type I as a stepping-stone recommendation for the very first issuance.
A Type II engagement audits whether the controls were suitably designed AND whether they operated effectively throughout a defined observation window. The window minimum is 3 months and maximum is 12 months, with the most common choices being 6 months and 12 months. The CPA firm performs the same control-test work as in Type I plus a sampling program: at least 25-50 control instances are sampled per CC criterion, and the auditor opines on whether the controls operated effectively across the entire window. Compliant-window attestation: "the controls were suitably designed and operated effectively throughout the period [start - end]." ComplianceStack treats Type II as the default target for any service organization that sells into enterprise procurement loops.
| Dimension | SOC 2 Type I | SOC 2 Type II |
|---|---|---|
| Scope of audit | Suitability of design at a point in time | Suitability of design AND operating effectiveness across a 3–12 month window |
| Observation window | None (point-in-time) | 3 months minimum, 12 months maximum, most commonly 6 or 12 months for first issuance |
| Auditor work | Read controls, interview personnel, inspect configuration | Type I work plus sampling (25–50 instances per criterion minimum) |
| Audit-fieldwork turnaround | 4–8 weeks | 8–16 weeks (longer for the 12-month window) |
| Buyer-side acceptance | Stepping-stone; resolves design-only questions | De facto enterprise-buyer and customer-questionnaire requirement |
| Big 4 CPA firm cost | $40K–$120K | $75K–$250K+ |
| Mid-tier CPA firm cost | $15K–$40K | $25K–$60K |
| Boutique SOC 2 specialist firm cost | $10K–$30K | $20K–$45K |
| Recommended for | First-time issuance, design-only pre-buy signal | Enterprise procurement loop closure, annual renewal cycle, second-year-and-beyond issuance |
SOC 2 Type II audit cost varies dramatically by auditor cadre. Big 4 CPA firms (Deloitte, PwC, EY, KPMG) typically quote $75,000–$250,000+ for a 12-month Type II report covering Security — more for Security + Availability + Confidentiality + Privacy. The Big 4 tier is the right fit for any service organization whose buyers explicitly require a Big 4 audit or whose customers are US-listed-company finance organizations that hard-require Big 4 attestation. Mid-tier CPA firms (regional firms with SOC 2 practices) typically quote $25,000–$60,000 for a 12-month Type II report covering Security. The mid-tier is the right fit for the majority of US SaaS, healthtech, and fintech service organizations. Boutique SOC 2 specialist firms typically quote $20,000–$45,000 for a 12-month Type II report covering Security. The boutique tier is the right fit for very early-stage service organizations and any issuance where the buyer-side buyer is willing to accept a non-Big 4 attestation. ComplianceStack pairs the SOC 2 gap assessment with an audit-firm-tier selector covering all three tiers.
The Type II report carries the buyer-side procurement loop. A typical enterprise procurement questionnaire targeting a SaaS, healthtech, or fintech vendor contains 60-120 questions spanning data handling, sub-processors, breach-notification obligations, pen-test cadence, vulnerability management, MFA enforcement, encryption-at-rest, access review cadence, and incident response. Many enterprise procurement teams flag a vendor that answers "no SOC 2 Type II" at the first questionnaire response and move to dismissal or escalation. ComplianceStack treats the SOC 2 Type II report as the procurement-loop clearance signal. The complete enterprise-buyer signal ladder: Type II report covering Security = the minimum procurement-loop clearance signal; Type II + Security + Confidentiality = the healthtech-grade clearance signal; Type II + Security + Confidentiality + Privacy = the EU-personal-data clearance signal; Type II + Security + Availability = the uptime-SLA clearance signal.
ComplianceStack packages the SOC 2 readiness program as a 90-day gap checklist that maps every CC1-CC9 criterion plus the selected Additional Categories into a sequenced remediation backlog. The 90-day program is the baseline ramp before the observation window opens for the Type II audit.
ComplianceStack tracks three sector-specific 2026 SOC 2 readiness roadmaps. The roadmaps share a CC1-CC9 baseline but diverge on Additional Category selection, observation-window timing, and buyer-side procurement-signal target.
Categories: Security (required) + Availability (for explicit uptime SLAs above 99.5%). Buyer-side trigger: enterprise procurement loops and SOC 2 due-diligence questionnaires — never get to procurement final-round without a Type II report issued. The 90-day program focuses on CC1-CC9 plus A1 availability criteria (uptime monitoring + incident-response readiness), with Type II as the default target and a 12-month observation window for first-time issuances. ComplianceStack pairs the SaaS roadmap with a sector-specific questionnaire map (Standard Customer Security Questionnaire, VSA-style questionnaires from large enterprise buyers, and Fortune-100 direct-procurement questionnaires).
Categories: Security + Confidentiality + Privacy. Buyer-side trigger: HIPAA-adjacent BAA flow-down + enterprise health-system procurement loops. The 90-day program adds HIPAA-adjacent controls (PHI handling policy, BAA template with vendor flow-down, breach notification policy with HHS-aligned 60-day window), aligns the Privacy Category P1-P8 criteria with HIPAA's Notice of Privacy Practices structure, and tightens the Confidentiality criteria to cover PHI as the dominant confidential-information class. Type II is the standard. ComplianceStack pairs the healthtech roadmap with the HIPAA Security Rule pivot whenever scope crosses into PHI handling.
Categories: Security + Confidentiality + Availability. Buyer-side trigger: bank and fintech enterprise procurement loops, plus PCI DSS adjacency for any service organization storing, processing, or transmitting cardholder data. The 90-day program adds AML/KYC adjacency documentation, segregation-of-duties between developer and customer-funds-handling roles, and regulatory capital-reserve documentation. Type II is the standard; some fintech buyers additionally request PCI DSS, ISO 27001, or SOX ICFR assertion depending on the relationship. ComplianceStack pairs the fintech roadmap with the PCI DSS v4.0 pivot whenever cardholder data crosses the data-storage boundary.
Four ComplianceStack tools pair directly with this pillar guide. The free multi-framework compliance assessment is the lightweight diagnostic (under 5 minutes, no signup, no email required); the 90-day roadmap deliverable converts the CC1-CC9 gap backlog into a sequenced plan; the free-compliance-assessment covers SOC 2 alongside HIPAA / SOX / GDPR / OSHA / PCI-DSS for multi-scope service organizations; and ComplianceStack pricing covers audit-ready deliverables from free gap-mapping to paid 90-day roadmap reports.
Run the ComplianceStack free compliance assessment at /free-compliance-assessment. Under 5 minutes, no email or signup required. Instant SOC 2 readiness score (Low / Moderate / High / Critical), every CC1–CC9 control mapped, the most-cited SOC 2 deficiency categories surfaced (missing MFA under CC6.1, missing access reviews under CC6.2, missing vulnerability cadence under CC7.3), and the top three remediation actions ranked by likelihood times impact — with Type I vs Type II recommendation and a 90-day checklist timeline.
Run the Free SOC 2 Assessment →The ComplianceStack free compliance assessment at /free-compliance-assessment scores SOC 2 alongside HIPAA / SOX / GDPR / OSHA / PCI-DSS / SEC / FINRA in a single 10-question instrument. Useful for any healthcare-tech (SOC 2 + HIPAA Privacy/Security Rule + BAA), fintech (SOC 2 + PCI DSS + SOX ICFR assertion), or multi-jurisdiction service organization whose compliance scope spans frameworks. Output: every-framework risk score and a cross-framework remediation map keyed to the SOC 2 buyer-clearance signal.
Open the Multi-Framework Assessment →The ComplianceStack 90-Day Roadmap at /90-day-roadmap converts the SOC 2 CC1-CC9 gap backlog into a sequenced implementation plan. Output: a 90-day delivery plan covering CC1 Control Environment, CC6 Logical and Physical Access, CC7 System Operations, CC3 Risk Assessment, and CC8 Change Management, with named owners, evidence-package expectations, and the observation-window start date for the upcoming Type II engagement. ComplianceStack delivers this in 3–5 business days.
Build the 90-Day Roadmap →Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies the SOC 2 Cross-Reference evidence-format expectation and is defensible at any Big 4 / mid-tier / boutique CPA firm engagement. The ComplianceStack report is the closing-package deliverable for the readiness program.
View Pricing →