What are the Trust Services Criteria (TSC)?
The trust services criteria (TSC) are the control objectives a SOC 2 report is measured against, published by the AICPA. There are five categories: security, availability, processing integrity, confidentiality, and privacy. Security is required in every SOC 2 report, and the others are optional.
What the buyer is really asking
Buyers want to know which of the five SOC 2 trust services criteria your report covers: security, availability, processing integrity, confidentiality, and privacy. Security is always in scope. List any others and say how you monitor the controls between audits.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you define and monitor trust services criteria?”
- “Which trust services criteria does your SOC 2 cover?”
- “Is availability in scope for your SOC 2 report?”
Evidence to have ready
- The scope section of your SOC 2 report
- Continuous control monitoring output, if you use a compliance platform
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.