Which Trust Services Criteria should I include?
Security is mandatory. The other four categories are a choice, and most first reports should not make it.
Which Trust Services Criteria should I include? For a first report, usually one. Security. It is mandatory in every SOC 2,1 and it covers what buyers are actually worried about. The other four are optional, and you add one because a signed contract already commits you to it.
Answer the four questions below as your contracts read today, not as your roadmap reads. The tool names the categories that follow, and why.
Scope is the first real decision in a SOC 2 and the one founders get wrong most often. It sets how many controls you design, how much evidence you produce every month, and how long the examination runs. A wider scope is not a stronger report. It is a longer one.
- Security
- Mandatory. Every SOC 2 report includes it, so this is never a choice. It covers access control, change management, monitoring, and incident response, and it is what buyers mean when they say SOC 2.
That is the whole answer for most first reports: Security, and nothing else. It is also what Polara G.R.C. scopes, so this is the case we can take end to end.
What each optional category commits you to
The only real choice is which of the other four you take on. Each one is a promise. Add it and an auditor tests whether you kept it.
| Category | The promise you are making |
|---|---|
| Availability | Your service will be there, and you can bring it back when it is not |
| Confidentiality | Designated data stays restricted for exactly as long as the contract says |
| Processing Integrity | Records leave your system right, on time, and only when someone authorized them |
| Privacy | Personal information is handled the way your published notice says it is |
Turn one on above and the tool names the work that comes with it. None of it is exotic. There is just more of it, produced every month for someone else to test, and that is what a longer engagement is.
Why scope moves the price, and why ours does not
An examination is priced on work, and scope is the work. Almost everywhere that makes scope the biggest driver of what an examination costs. Two companies the same size, one scoped to Security and one scoped to all five categories, are not buying the same thing and will not be quoted the same number.
Ours does not move, because the scope does not move. A Security scoped Type 1 through Polara G.R.C. is $4,000 one time, with the Type 1 examination and the independent partner auditor fee included. Fixed scope is what buys the fixed price. What SOC 2 actually costs takes that invoice apart line by line. If you want the calendar instead of the invoice, how long SOC 2 takes covers the observation window and the external items that set your floor.
The mistake almost everyone makes
Founders add categories nobody asked for. It reads as thorough. It is the most reliable way to make a first SOC 2 slower and more expensive than it needed to be, and the buyer who triggered the whole project will not read past the cover page to notice.
Ask the buyer. Their security questionnaire or the contract itself will name what they need, and in most business software deals that name is Security. If they do want Availability, the commitment is usually already sitting in the agreement you signed. Scope to what is written down. Revisit it next year if a real customer makes you. The category definitions, criterion by criterion, are in the Trust Services Criteria guide.2
A later report can be wider than your first, with a customer behind it. Not through us: Polara G.R.C. scopes Security only, and no engagement changes that. Adding a category nobody needed is waste either way.
You set it in the engagement letter and the independent partner auditor confirms it is workable.3 Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
Which Trust Services Criteria are required?
Do I need Availability or Confidentiality for my first SOC 2?
Does adding a category make the report stronger?
Can I add a category to my next report?
Who decides the final scope?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.