How many controls are in SOC 2?
None. SOC 2 defines criteria and leaves the controls to you. There are 61 criteria, and a Security scoped report is measured against 33 of them.
How many controls are in SOC 2? None. That is the real answer rather than a technicality, and it is the thing worth knowing before you budget any of this. SOC 2 defines criteria, which are the benchmarks your controls get evaluated against, and it leaves the controls themselves to you.1
The number people are usually reaching for is the criteria count. That is 61 across all five Trust Services Categories, of which 33 are the common criteria, and a Security scoped report is measured against those 33 alone. The full enumeration is below, family by family.
If you have read that the number is 64, that figure is real and belongs to a different document. 64 is the criteria count of the 2016 standard, TSP section 100A, which the 2017 criteria replaced. Both are worked through below.
The count is harder to find than it should be, for a reason worth stating up front: the standard never totals itself. It presents the criteria in sections and leaves the addition to the reader. Every published figure in this space, including this one, is somebody counting. So here is the count with its working shown, which is the only form of this answer that is worth anything.
The 61 criteria, family by family
| Family | Criteria | Identifiers |
|---|---|---|
| CC1 Control environment | 5 | CC1.1 to CC1.5 |
| CC2 Communication and information | 3 | CC2.1 to CC2.3 |
| CC3 Risk assessment | 4 | CC3.1 to CC3.4 |
| CC4 Monitoring of controls | 2 | CC4.1 to CC4.2 |
| CC5 Control activities | 3 | CC5.1 to CC5.3 |
| CC6 Logical and physical access | 8 | CC6.1 to CC6.8 |
| CC7 System operations | 5 | CC7.1 to CC7.5 |
| CC8 Change management | 1 | CC8.1 |
| CC9 Risk mitigation | 2 | CC9.1 to CC9.2 |
| Common criteria | 33 | Every SOC 2 report covers these |
| A1 Availability | 3 | A1.1 to A1.3 |
| C1 Confidentiality | 2 | C1.1 to C1.2 |
| PI1 Processing integrity | 5 | PI1.1 to PI1.5 |
| P1 Notice and communication of objectives | 1 | P1.1 |
| P2 Choice and consent | 1 | P2.1 |
| P3 Collection | 2 | P3.1 to P3.2 |
| P4 Use, retention and disposal | 3 | P4.1 to P4.3 |
| P5 Access | 2 | P5.1 to P5.2 |
| P6 Disclosure and notification | 7 | P6.1 to P6.7 |
| P7 Quality | 1 | P7.1 |
| P8 Monitoring and enforcement | 1 | P8.1 |
| Privacy subtotal | 18 | P1.1 to P8.1 |
| Total | 61 | All five categories |
Counted from TSP Section 100, the 2017 Trust Services Criteria with revised points of focus dated 2022.1 The 2017 original issue and the March 2020 edition carry the same 61 identifiers. The 2022 revision changed points of focus, not criteria, so anyone citing a criteria count that changed in 2022 has counted something else.
The privacy section carries eight headings numbered P1.0 through P8.0, which look exactly like criteria identifiers and are not. Counting those as criteria gives 69. There is no A1.0, C1.0 or PI1.0, so the trap only exists in privacy, and it is the single most common way a careful person still gets this wrong.
Where 64 comes from
64 is not invented. It is the criteria count of the standard that the current one replaced. The 2016 Trust Services Principles and Criteria, TSP section 100A, contained 64 criteria, and it was superseded by the 2017 Trust Services Criteria.
The two documents sit next to each other, which is what makes this checkable rather than a matter of opinion. AICPA published them in a single bundle: TSP section 100 with its 61 criteria, and TSP section 100A immediately after it with 64. Counting each half separately produces both numbers from one file.
| Category | 2016, TSP 100A | 2017, TSP 100 |
|---|---|---|
| Common criteria | 27 | 33 |
| Availability | 3 | 3 |
| Confidentiality | 8 | 2 |
| Processing integrity | 6 | 5 |
| Privacy | 20 | 18 |
| Total | 64 | 61 |
The interesting column is Confidentiality. It went from eight standalone criteria to two, because the 2017 restructure folded most of that work into the common criteria, which grew from 27 to 33 in the same move. The total fell even though the coverage did not shrink. That is the whole story of the missing three.
Criteria are not controls, and the standard will not count those
The most common version of this question is how many controls SOC 2 has. It has none. The criteria are benchmarks, and the controls that meet them are yours to design, which the standard says in as many words: the criteria are intended to be used for evaluation and reporting regardless of the specific controls management implements.1
This is not pedantry, because it changes what you build. Two companies can both satisfy the same 33 common criteria with control counts that differ by a factor of three, and neither is more compliant than the other. Any vendor quoting a control count is quoting the size of their own library. How many SOC 2 policies you need is the same question one layer down, and it has the same answer.
Points of focus are the illustrative considerations printed under each criterion. There are several hundred of them, and they are explicitly not requirements: the standard states that using the criteria does not require an assessment of whether each point of focus is addressed.3 Treating them as a checklist is how a Security scoped project turns into a year of work it never needed.
Which of the 61 apply to you
Almost certainly 33. Security is mandatory in every SOC 2, and the other four categories are scoped in only when a contract or a buyer requires them.2 A first report that covers the common criteria and nothing else is the normal shape, not a reduced one.
The 18 privacy criteria are the ones to be most careful about. They are the largest optional block, they carry the most evidence, and they are the category buyers ask for least often. The scoping tool works out which categories your contracts actually put in scope, and the criteria guide covers what each one asks for.
Every figure here was counted from the AICPA document rather than taken from another summary, and cross checked against three editions of it. A count that came from counting is worth more than a count that came from a page that got it from a page. Polara G.R.C. scopes Security only, so the 33 common criteria are the set it works against. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
How many criteria are in SOC 2?
Why do so many pages say 64?
How many criteria does a Security only SOC 2 cover?
How many controls are in SOC 2?
Are points of focus required?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.