• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
soc reports

Which SOC 2® Trust Services Categories are right for my organization?

June 7, 2022 Posted by Cera Adams SOC Reporting Services

SOC 2® can apply to most service organizations, including companies who provide analytics, business intelligence, managed IT security service providers, and software-as-a-service companies who provide websites, applications, and programs.

A service organization’s management is responsible for selecting the Trust Services Categories to be included within the scope of the SOC 2® examination based on its understanding of the needs of its customers.

There are five Trust Services Criteria options:

  • Security: Systems and data stored by a company are protected against unauthorized access and unauthorized disclosure of information.
  • Availability: Information and systems are available for operation.
  • Confidentiality: Information designated as confidential information is protected.
  • Processing Integrity: System processing is complete, valid, accurate, timely, and authorized. Data remains correct throughout the course of data processing.
  • Privacy: Personal information is collected, used, retained, disclosed, and disposed of in accordance with pre-stated policies.

While all organizations must meet the requirements of the criteria common to all five of the trust services categories, most service organizations will include the security category within the scope of their SOC 2®. The security category addresses whether the system is protected (both physically and logically) against unauthorized access. 

To determine if other categories should be included, a service organization should consider the commitments it makes to its customers.

Some examples for when an organization may consider additional Trust Services Categories:

• A service organization that provides IT infrastructure or data center services to its customers may have certain commitments or SLAs to its customers about system availability; therefore, a SOC 2® examination that addresses the availability category is likely to meet its customer needs.

• A service organization that processes sensitive data like proprietary information, financial reports, passwords, lists of prospective customers, customer databases, or business strategies for its customers may make commitments about maintaining the confidentiality of the information processed, handled, or stored; therefore, a SOC 2® examination that addresses the confidentiality category is likely to meet its customer needs.

• A service organization that provides financial or data-related services such as analytics or wants to provide assurance to its clients that there are no errors in their process of data input, processing procedures, and data output may make commitments about maintaining processing integrity; therefore, a SOC 2® examination that addresses the processing integrity category is likely to meet its customer needs.

• A service organization that handles personnel records, payment card information, or personal health information for its customers may make commitments about maintaining the privacy of the information processed, handled, or stored; therefore, a SOC 2® examination that addresses the privacy category is likely to meet its customer needs.

Although four of the categories are optional, organizations should determine which categories are most relevant based their service commitments and customer needs.

Share
0
Cera Adams, CISA, CRISC

About Cera Adams

Cera joined OCD Tech as an IT Audit Manager in October 2017. She is currently Director, Assurance Services. She has twenty years of experience in IT audit, Information security, and IT risk management, primarily in the health insurance and financial services industries. Cera leads our SOC2 practice.

You also might be interested in

DATA PRIVACY WEEK

DATA PRIVACY WEEK

Jan 23, 2023

OCD Tech joins forces with The National Cybersecurity Alliance and[...]

Employees are Weak Links

Dec 30, 2015

These days, it’s tough to be a bank. Regulatory demands[...]

C3PAO
C3PAO Badge

C3PAO

Apr 30, 2021

OCD Tech, the IT Audit & Security division of O’Connor & Drew P.C., a Braintree MA CPA firm has been selected as a Candidate Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessor Organization.

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next