Which Trust Services Criteria should I include?

Security is mandatory. The other four categories are a choice, and most first reports should not make it.

Which Trust Services Criteria should I include? For a first report, usually one. Security. It is mandatory in every SOC 2,1 and it covers what buyers are actually worried about. The other four are optional, and you add one because a signed contract already commits you to it.

Answer the four questions below as your contracts read today, not as your roadmap reads. The tool names the categories that follow, and why.

Scope is the first real decision in a SOC 2 and the one founders get wrong most often. It sets how many controls you design, how much evidence you produce every month, and how long the examination runs. A wider scope is not a stronger report. It is a longer one.

Does a signed customer contract commit you to uptime, an SLA credit, or a recovery time?
Does a contract designate data you hold as confidential, with a duty to return or destroy it?
Do you process transactions or records on a customer’s behalf, where a wrong output is their problem?
Do you handle personal information under your own privacy notice, rather than only as your customer’s processor?
1of five categories in scope
0added because a contract says so
Security
Mandatory. Every SOC 2 report includes it, so this is never a choice. It covers access control, change management, monitoring, and incident response, and it is what buyers mean when they say SOC 2.

That is the whole answer for most first reports: Security, and nothing else. It is also what Polara G.R.C. scopes, so this is the case we can take end to end.

What each optional category commits you to

The only real choice is which of the other four you take on. Each one is a promise. Add it and an auditor tests whether you kept it.

CategoryThe promise you are making
AvailabilityYour service will be there, and you can bring it back when it is not
ConfidentialityDesignated data stays restricted for exactly as long as the contract says
Processing IntegrityRecords leave your system right, on time, and only when someone authorized them
PrivacyPersonal information is handled the way your published notice says it is

Turn one on above and the tool names the work that comes with it. None of it is exotic. There is just more of it, produced every month for someone else to test, and that is what a longer engagement is.

Why scope moves the price, and why ours does not

An examination is priced on work, and scope is the work. Almost everywhere that makes scope the biggest driver of what an examination costs. Two companies the same size, one scoped to Security and one scoped to all five categories, are not buying the same thing and will not be quoted the same number.

Ours does not move, because the scope does not move. A Security scoped Type 1 through Polara G.R.C. is $4,000 one time, with the Type 1 examination and the independent partner auditor fee included. Fixed scope is what buys the fixed price. What SOC 2 actually costs takes that invoice apart line by line. If you want the calendar instead of the invoice, how long SOC 2 takes covers the observation window and the external items that set your floor.

The mistake almost everyone makes

Founders add categories nobody asked for. It reads as thorough. It is the most reliable way to make a first SOC 2 slower and more expensive than it needed to be, and the buyer who triggered the whole project will not read past the cover page to notice.

Ask the buyer. Their security questionnaire or the contract itself will name what they need, and in most business software deals that name is Security. If they do want Availability, the commitment is usually already sitting in the agreement you signed. Scope to what is written down. Revisit it next year if a real customer makes you. The category definitions, criterion by criterion, are in the Trust Services Criteria guide.2

Scope is not permanent

A later report can be wider than your first, with a customer behind it. Not through us: Polara G.R.C. scopes Security only, and no engagement changes that. Adding a category nobody needed is waste either way.

Who signs off on the scope

You set it in the engagement letter and the independent partner auditor confirms it is workable.3 Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

Which Trust Services Criteria are required?
Only Security. It is the common criteria set that every SOC 2 report contains. Availability, Confidentiality, Processing Integrity and Privacy are optional, and you add one because a contract or a buyer requires it.
Do I need Availability or Confidentiality for my first SOC 2?
Usually not. Add Availability if a signed contract commits you to uptime or a recovery time. Add Confidentiality if a contract designates data you hold as confidential and puts return or destruction duties on you. Otherwise Security alone answers what most buyers ask for.
Does adding a category make the report stronger?
It makes it wider, not stronger. Every category adds controls to design, evidence to produce each month and hours for the auditor to test. A category nobody asked for is work with no buyer behind it.
Can I add a category to my next report?
Scope is set for each examination, so a later report can be wider than the first. Not through Polara G.R.C. though: we scope Security only, and that is fixed rather than a setting. A wider scope means engaging a firm that runs it directly.
Who decides the final scope?
You and the firm agree it in the engagement letter. Through Polara G.R.C. the answer is narrower: we scope Security only, so the tool tells you what a wider contract implies rather than something we would deliver. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Trust Services Criteria AICPA. The criteria overview and the current version in force. Checked 1 August 2026.
  3. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty