SOC 2 Trust Services Criteria: how each one changes your audit cost.
What the Trust Services Criteria are
The Trust Services Criteria (TSC) are the AICPA control framework a SOC 2 report is evaluated against, codified as TSP Section 100. The current version is the 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, with revised points of focus issued in 2022. The criteria themselves did not change in that revision; only the underlying points of focus were updated to reflect current business and technology practice. There is no separate 2024 or 2026 edition: a SOC 2 audit in 2026 is still performed against the 2017 criteria with the 2022 revised points of focus (AICPA, TSP Section 100).
Five categories exist. Security is mandatory and is the only category every SOC 2 report must include; it is the set the AICPA labels the common criteria. Availability, Processing Integrity, Confidentiality, and Privacy are optional categories you scope in based on customer and contractual need. The rest of this page models what each optional category adds to audit cost.
Per-criterion cost section
Security (mandatory). The baseline. Common Criteria controls cover access management, change management, risk assessment, system operations, and communication. Every SOC 2 report includes Security. There is no SOC 2 without it.
Confidentiality. Adds controls around classification of confidential information, retention and disposal, and protection during transmission. The most commonly added of the four, because B2B contracts routinely carry confidentiality obligations that these controls map onto directly. Usually the cheapest to add, since most teams are already doing a version of the work.
Availability. Adds controls around system monitoring, capacity planning, incident response for availability events, and backup and restoration. Customer-driven where uptime SLAs are contractual. If you already run a credible on-call and monitoring practice, the readiness work is mostly writing down what you do.
Processing Integrity. Adds controls around data input completeness and accuracy, processing accuracy, and quality assurance procedures. Mostly relevant to transaction-processing platforms: payments, billing, data pipelines. Rarely worth adding speculatively, because it is specific enough that customers who need it will say so.
Privacy. Adds controls around notice, choice and consent, collection, retention, disclosure, access, quality, and monitoring of personal information. This is the heavy one, and the weight falls on readiness rather than the audit: data inventories, processor relationships and DSAR handling all have to exist before anyone can test them. For a processor already meeting GDPR obligations, much of that groundwork is done, which is why Privacy is far cheaper to add on top of a mature privacy programme than from a standing start.
Minimum-viable scope
For a first-time SOC 2 with no specific customer driver, Security only is sufficient. It produces a complete SOC 2 attestation, costs the least, and leaves room to add criteria in year 2 if customers ask. For B2B SaaS where customer contracts already include confidentiality language, add Confidentiality from the start to avoid a year-2 scope expansion. For platforms with uptime SLAs, add Availability.
Resist the temptation to add criteria you do not yet need. Each one adds cost, readiness time, and ongoing maintenance. Scope can always grow at renewal; it cannot easily shrink once customers expect it.
What scope does to the fee
The mechanism is simple and the magnitude is not published. Each criterion brings its own controls; each control has to be tested; testing is auditor hours; hours are the fee. That chain is structural and you can rely on it. What no firm discloses is how many hours a given criterion adds in a given environment, and there is no register to look it up in.
So the toggle below is a model, not a price list. It applies this site's assumption that each optional criterion adds between 10 and 25 percent to auditor hours, and it widens its range as you add criteria rather than pretending to a precision it does not have. Tick a subset to see the modelled audit fee move.
Adding a criterion adds controls to test, so it adds auditor hours. Nobody publishes how many. This model assumes 10 to 25 percent per criterion and widens the range accordingly, rather than quoting a single percentage it cannot stand behind. The figure moves with the blended rate, set here at the model default of £190 per hour.
Use it for the shape of the decision, not the digits. The useful output is the relative cost of a scope choice you are weighing, and the reminder that the fee is hours, which means scope is the lever you control most directly.
Cross-reference
For the readiness component that scales with each criterion, see the readiness cost page. For the audit-fee tier that scales with the criteria total, see the audit firm fees page. For the scale-up bracket where adding criteria becomes a budget conversation in itself, see the scale-up cost page.