How many controls are in SOC 2?

None. SOC 2 defines criteria and leaves the controls to you. There are 61 criteria, and a Security scoped report is measured against 33 of them.

How many controls are in SOC 2? None. That is the real answer rather than a technicality, and it is the thing worth knowing before you budget any of this. SOC 2 defines criteria, which are the benchmarks your controls get evaluated against, and it leaves the controls themselves to you.1

The number people are usually reaching for is the criteria count. That is 61 across all five Trust Services Categories, of which 33 are the common criteria, and a Security scoped report is measured against those 33 alone. The full enumeration is below, family by family.

If you have read that the number is 64, that figure is real and belongs to a different document. 64 is the criteria count of the 2016 standard, TSP section 100A, which the 2017 criteria replaced. Both are worked through below.

The count is harder to find than it should be, for a reason worth stating up front: the standard never totals itself. It presents the criteria in sections and leaves the addition to the reader. Every published figure in this space, including this one, is somebody counting. So here is the count with its working shown, which is the only form of this answer that is worth anything.

The 61 criteria, family by family

FamilyCriteriaIdentifiers
CC1 Control environment5CC1.1 to CC1.5
CC2 Communication and information3CC2.1 to CC2.3
CC3 Risk assessment4CC3.1 to CC3.4
CC4 Monitoring of controls2CC4.1 to CC4.2
CC5 Control activities3CC5.1 to CC5.3
CC6 Logical and physical access8CC6.1 to CC6.8
CC7 System operations5CC7.1 to CC7.5
CC8 Change management1CC8.1
CC9 Risk mitigation2CC9.1 to CC9.2
Common criteria33Every SOC 2 report covers these
A1 Availability3A1.1 to A1.3
C1 Confidentiality2C1.1 to C1.2
PI1 Processing integrity5PI1.1 to PI1.5
P1 Notice and communication of objectives1P1.1
P2 Choice and consent1P2.1
P3 Collection2P3.1 to P3.2
P4 Use, retention and disposal3P4.1 to P4.3
P5 Access2P5.1 to P5.2
P6 Disclosure and notification7P6.1 to P6.7
P7 Quality1P7.1
P8 Monitoring and enforcement1P8.1
Privacy subtotal18P1.1 to P8.1
Total61All five categories

Counted from TSP Section 100, the 2017 Trust Services Criteria with revised points of focus dated 2022.1 The 2017 original issue and the March 2020 edition carry the same 61 identifiers. The 2022 revision changed points of focus, not criteria, so anyone citing a criteria count that changed in 2022 has counted something else.

Privacy is where miscounts happen

The privacy section carries eight headings numbered P1.0 through P8.0, which look exactly like criteria identifiers and are not. Counting those as criteria gives 69. There is no A1.0, C1.0 or PI1.0, so the trap only exists in privacy, and it is the single most common way a careful person still gets this wrong.

Where 64 comes from

64 is not invented. It is the criteria count of the standard that the current one replaced. The 2016 Trust Services Principles and Criteria, TSP section 100A, contained 64 criteria, and it was superseded by the 2017 Trust Services Criteria.

The two documents sit next to each other, which is what makes this checkable rather than a matter of opinion. AICPA published them in a single bundle: TSP section 100 with its 61 criteria, and TSP section 100A immediately after it with 64. Counting each half separately produces both numbers from one file.

Category2016, TSP 100A2017, TSP 100
Common criteria2733
Availability33
Confidentiality82
Processing integrity65
Privacy2018
Total6461

The interesting column is Confidentiality. It went from eight standalone criteria to two, because the 2017 restructure folded most of that work into the common criteria, which grew from 27 to 33 in the same move. The total fell even though the coverage did not shrink. That is the whole story of the missing three.

Criteria are not controls, and the standard will not count those

The most common version of this question is how many controls SOC 2 has. It has none. The criteria are benchmarks, and the controls that meet them are yours to design, which the standard says in as many words: the criteria are intended to be used for evaluation and reporting regardless of the specific controls management implements.1

This is not pedantry, because it changes what you build. Two companies can both satisfy the same 33 common criteria with control counts that differ by a factor of three, and neither is more compliant than the other. Any vendor quoting a control count is quoting the size of their own library. How many SOC 2 policies you need is the same question one layer down, and it has the same answer.

A third number worth separating

Points of focus are the illustrative considerations printed under each criterion. There are several hundred of them, and they are explicitly not requirements: the standard states that using the criteria does not require an assessment of whether each point of focus is addressed.3 Treating them as a checklist is how a Security scoped project turns into a year of work it never needed.

Which of the 61 apply to you

Almost certainly 33. Security is mandatory in every SOC 2, and the other four categories are scoped in only when a contract or a buyer requires them.2 A first report that covers the common criteria and nothing else is the normal shape, not a reduced one.

The 18 privacy criteria are the ones to be most careful about. They are the largest optional block, they carry the most evidence, and they are the category buyers ask for least often. The scoping tool works out which categories your contracts actually put in scope, and the criteria guide covers what each one asks for.

How this page was counted

Every figure here was counted from the AICPA document rather than taken from another summary, and cross checked against three editions of it. A count that came from counting is worth more than a count that came from a page that got it from a page. Polara G.R.C. scopes Security only, so the 33 common criteria are the set it works against. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

How many criteria are in SOC 2?
Sixty one across all five Trust Services Categories. Thirty three of those are the common criteria, which every SOC 2 report covers. The remaining twenty eight belong to Availability, Confidentiality, Processing Integrity and Privacy, and apply only when you put that category in scope.
Why do so many pages say 64?
Because 64 is a real count, of the wrong document. The 2016 standard, TSP section 100A, contained 64 criteria. The 2017 Trust Services Criteria replaced it and contain 61. The reduction came mostly from Confidentiality, which went from eight standalone criteria to two once the rest were folded into the common criteria.
How many criteria does a Security only SOC 2 cover?
Thirty three. That is the common criteria set, CC1.1 through CC9.2. The other twenty eight criteria are only evaluated if you scoped Availability, Confidentiality, Processing Integrity or Privacy.
How many controls are in SOC 2?
The standard does not say, and that is deliberate rather than an oversight. SOC 2 defines criteria, which are the benchmarks your controls are evaluated against, and leaves the controls themselves to you. Two companies meeting the same 33 common criteria can have very different numbers of controls.
Are points of focus required?
No. Points of focus are illustrative considerations attached to each criterion, and the standard states that using the criteria does not require assessing whether each point of focus is addressed. They are useful for designing controls and they are not a checklist you have to complete.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty