Every SOC 2 scoping conversation eventually lands on the same question. Which SOC 2 Trust Services Criteria actually belong in your audit? Security is not optional, so that part is easy. The other four, Availability, Confidentiality, Processing Integrity, and Privacy, are where founders overspend without realizing it. Each one you add is not a feature you're turning on. It's a line item, and it extends your audit fieldwork.

This isn't a rundown of what the five criteria mean. That full breakdown, along with attestation vs. certification, Type I vs. Type II, and the rest of the SOC 2 basics, lives on our complete SOC 2 guide for SaaS startups. This article looks at what it costs to add a criterion, what it buys you, and when the extra scope is worth it.

Security Is Required. Everything Else Is a Pricing Decision

The AICPA's Trust Services Criteria define five categories an auditor can test against: Security, Availability, Confidentiality, Processing Integrity, and Privacy. Security is mandatory in every SOC 2 report. It covers the Common Criteria, the baseline controls around access, change management, monitoring, and incident response that every audit tests regardless of scope.

The other four are optional, and that's the part most vendors gloss over. Each one you add means more control objectives to design, more evidence to collect, and more hours your auditor spends testing. A leaner scope isn't a shortcut. For a first-year SOC 2 program, it's usually the right call.

How to Choose SOC 2 Trust Services Criteria for Your First Audit

Most first-time SOC 2 candidates default to Security-only, and the reason is simple. It's what enterprise buyers actually ask for. Security questionnaires and vendor risk assessments are built around the Common Criteria. Adding a criterion nobody requested doesn't strengthen your report. It just adds audit time your sales team is waiting on.

Before you scope anything beyond Security, work through a few concrete questions:

  • What do your actual prospects ask for? Pull the last five security questionnaires or vendor risk assessments you've received. If none of them mention uptime SLAs, data classification, or transaction accuracy, you don't have evidence yet that a broader scope moves deals.
  • Does your contract promise something Security alone doesn't cover? An SLA guaranteeing 99.9% uptime is an Availability claim. If you're already contractually on the hook for it, the criterion just formalizes what you've already committed to.
  • What does your product actually do with data? A platform that processes payroll runs or billing calculations has a Processing Integrity story to tell. A read-only analytics dashboard usually doesn't.
  • Do you handle data under an NDA or contractual confidentiality clause that goes beyond your general security posture? That's a signal for Confidentiality, not Privacy, which is a separate criterion built around personal information handling.

If none of those questions turn up a clear buyer requirement, start with Security alone. You can always expand scope in a later observation period once the demand is real instead of hypothetical.

What Each Additional Trust Services Criterion Actually Costs You

This is the part that matters for budgeting, and it's usually where the SOC 2 Trust Services Criteria cost conversation gets skipped over. Every criterion beyond Security adds its own control objectives, which means new policies to write, new evidence to gather monthly or quarterly, and new testing procedures your auditor has to run. None of that is free, and none of it happens in the background while Security testing proceeds unaffected.

  • Availability adds controls around capacity planning, backup and recovery testing, and incident response tied specifically to uptime. If you already monitor these things for operational reasons, the incremental cost is mostly documentation and formalizing what you track. If you don't, it's new tooling and new process, on top of new audit hours.
  • Confidentiality requires you to define what counts as confidential, document how it's classified, and show controls around its handling, transmission, and disposal. The audit work here is manageable if your data classification is already clean. It gets expensive fast if it isn't, because the auditor's first ask will be a data inventory you don't yet have.
  • Processing Integrity is the most control-heavy of the four. It requires demonstrating that data processing is complete, accurate, timely, and authorized, which usually means new logging, new reconciliation checks, and new evidence trails around whatever transactions your system performs. This one adds real audit fieldwork, not just paperwork.
  • Privacy is scoped separately from the other four and maps closely to how you collect, use, retain, and dispose of personal information. If you're already handling this under a framework like GDPR or CCPA, some of the groundwork exists. If you're not, this is the criterion most likely to require net-new policy work before an auditor will even start testing.

Picture a twelve-person expense-management SaaS company that gets asked about Processing Integrity by a single enterprise prospect midway through its observation period. Adding it late means retrofitting reconciliation logs the auditor now has to test after the fact, which is exactly the scramble a written scope decision avoids. Price the criterion before the prospect asks, not after.

Stack two or three of these onto a first-year audit and the effect compounds. Readiness work grows, evidence collection grows, and your auditor's fieldwork hours grow with it. A typical first-year SOC 2 program runs roughly $30,000 to $100,000 in cash plus internal time, and criteria count is one of the primary levers that number moves on, alongside observation length and how much of the readiness work you do yourself versus outsource.

Scope Creep Costs You Twice

The cost of an extra criterion doesn't show up once. It shows up in your CPA audit fee, and it shows up again in your timeline. CPA audit fees for a startup-focused Type I typically run $10,000 to $15,000 with a boutique firm, and Type II fees climb from there as observation length and criteria count increase. Every criterion you add gives the auditor more to test, which means more fieldwork hours billed at their rate.

The timeline hit is easy to underestimate. A broader scope means more evidence to collect during your observation period, which means more opportunities for a gap to surface mid-engagement, a missing log, an untested backup, a policy that exists on paper but isn't actually followed. Each gap found during fieldwork means remediation, and remediation means delay.

A common version of this: a Series A company adds Confidentiality mid-engagement because one customer questionnaire mentioned an NDA, then discovers its data classification policy doesn't exist yet. That single gap can add several weeks to fieldwork while the auditor waits on a document nobody had written. A Security-only scope gives your team fewer places for that kind of surprise to hide.

None of this means extra criteria are a bad investment. It means they're a specific, priceable one, and you should only take it on once you know what it's buying.

When Adding a Criterion Beyond Security Actually Pays Off

Scope isn't fixed forever. Plenty of companies start Security-only and add a criterion in year two once the business case is concrete rather than theoretical. A few situations where the math tends to work:

  1. An enterprise deal is explicitly blocked on it. If a procurement team has told you, in writing, that your report needs to cover Availability or Processing Integrity to close, that's a demand signal worth pricing against the deal size.
  2. You've already built the controls for other reasons. If your engineering team runs quarterly disaster recovery tests and tracks uptime against an internal SLA anyway, formalizing that into an Availability criterion costs less because the operational work already exists.
  3. Your product's core function is the thing a criterion covers. A payments platform without Processing Integrity in scope will eventually get asked about it by a buyer's security team. Building it into the audit before that question arrives is cheaper than a rushed mid-cycle addition.
  4. You're renewing cyber insurance and the underwriter is asking specific questions your current scope doesn't answer. Insurance renewals occasionally surface gaps a sales cycle never would.

Notice what's not on that list. Adding a criterion because it seems thorough, or because a competitor's report includes it, isn't a reason at all. Neither of those is a buyer requirement, and neither justifies the added cost.

Learn how CyberSprint's SOC 2 Type II service scopes and prices this decision walks through exactly this tradeoff with a real cost estimate for your specific product and buyer base, rather than a generic range.

A Simple Way to Price Your Scope Before You Commit

Before your kickoff call with an auditor or readiness partner, put a number next to each criterion you're considering. List the specific policy work, tooling, and evidence collection it requires that you don't already have. Then list the deals, renewals, or underwriting questions it would actually unlock. If the second list is thinner than the first, you have your answer.

This exercise takes an afternoon, and it's worth doing before you sign an engagement letter, not after. A scoping conversation that starts with "what does the buyer need" produces a leaner, cheaper, faster audit than one that starts with "what could we include."

Getting the Scope Decision Right the First Time

The founders who get the most value out of their first SOC 2 report are rarely the ones with the broadest scope. They're the ones whose scope maps precisely to what their buyers actually check for. A tight, well-documented Security-only report that closes deals beats a five-criteria report that took twice as long and answers questions nobody asked.

If you're not sure which side of that line your business sits on, that's a fifteen minute conversation, not a research project. Start a conversation with CyberSprint and we'll walk through your actual buyer requirements before you commit to a scope, a cost, or a CPA firm.

Frequently Asked Questions

Do I need to include all five Trust Services Criteria in my SOC 2 audit?

No. Security is the only required criterion. The AICPA's framework lets you scope Availability, Confidentiality, Processing Integrity, and Privacy in or out based on what your buyers and contracts actually require. Most startups start with Security alone.

How much does adding a Trust Services Criterion cost?

It varies by criterion and by how much of the underlying control work already exists in your business. Expect it to add both readiness work, new policies and new evidence collection, and audit fieldwork hours, which raises your CPA fee. There's no fixed add-on price, because the cost depends entirely on how far your current operations are from what the criterion requires.

How long does each additional criterion add to the audit?

Expect additional weeks, not days, particularly for Processing Integrity, which tends to require the most new evidence and testing. The exact impact depends on how mature your existing processes are for that criterion going in.

Can I add a criterion after my first SOC 2 report?

Yes, and it's common. Many companies run a Security-only Type II in year one, then add a criterion in a later observation period once a specific buyer or contractual requirement makes the case concrete.

Who decides which criteria belong in scope?

You do, working from your own buyer requirements and system description. Your auditor doesn't set your scope. They test against whatever scope you and your readiness partner define, so the decision belongs to you before the engagement starts.

Getting SOC 2 scope right the first time is less about the audit and more about knowing your buyers. Get that part right, and the report becomes the credential that opens the next enterprise deal instead of a project that dragged on longer, and cost more, than it needed to.

Not sure which criteria you need?

We help small cloud-native SaaS companies turn compliance into something enterprise buyers actually trust. Let's talk about where you are and what's next.

Start a conversation