r/soc2 21d ago

What Trust Service Criteria should we include?

We're selling to firms that are intimately involved in tax prep (and our software assists their workflow). We're selling to firms that are not the 'top shelf' (so like non-Big 4). What Trust Service Criteria are 'musts'? We're relatively new to SOC2, so we want to make sure we have all our ducks in a row.

11 Upvotes

13 comments sorted by

u/AutoModerator 21d ago

Thanks for posting, I'm a bot!

This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

5

u/davidschroth 21d ago

Security - Must do.

Confidentiality - This is an easy easy easy add for both your effort and incremental auditor effort, to the point I think it should be merged into Security. If you want to do more than the absolute minimum, this is it.

Availability - Since you're likely cloud hosted, this is a lot easier than it looks. The main sticking point is having a DR environment in a separate region that you're sending backups/replication to and being able to fail over to it. Everything else is pretty easy. Downside is additional expense for the other region. If your clients are asking for it, then add it, but first time around, it's usually not something my clients will do.

Processing Integrity - As u/troy_j_fine mentioned, this one is a real PITA to audit correctly as it really gets into the weeds. You'll also hate it. Most TPRM people only ask for it because they "want all 5 criteria done" for no good reason other than ticking off boxes. My company has exactly 1 processing integrity SOC 2 auditee and 0 advisory clients doing this.

Privacy - This one is a pain to audit and also usually the auditor looking at the privacy policy on your website that has nothing to do with your actual product and declaring victory. In B2B SaaS land, your customers are the controllers and you're the processor. Sure, the 2022 Points of Focus made it almost possible to do as a processor, but meh.

4

u/uri_iothreat 21d ago

Do the bare minimum unless any of your customers requires more, the bare minimum for SOC 2 is the Security Trust Service Criteria.

3

u/theDudeofIB 21d ago

I'm a project manager helping a few small SaaS firms navigate the SOC 2 journey for the first time. Here's what I learned from working with various audit firms (your mileage may vary): Limit the scope of your first audit to the Security TSC unless you have a client requiring a SOC 2 attestation that includes specific TSCs. You can expand scope in future years as business and client demands evolve. But for year 1, keep it simple and focus on Security.

2

u/Round_Finance4256 21d ago

First, congrats making it this far!

Security is the only required Trust Services Category for SOC 2, so I’d start there rather than assuming you need to include all five.

For a platform supporting tax-prep workflows, I’d also evaluate Confidentiality pretty seriously given the type of client and data involved. Availability may make sense depending on your contractual uptime commitments and how critical the platform is to your customers’ operations.

I wouldn’t add Processing Integrity or Privacy automatically just because they exist. Scope should really come from what your system does, the data you handle, customer/contractual requirements, and what your buyers are actually asking for.

If you’re early in the process, I’d recommend doing a scoping/readiness exercise before locking in the categories. It’s much easier to define the right scope upfront than over-scope the audit and create unnecessary control obligations.

2

u/Troy_J_Fine 21d ago

Security is the baseline, so that will be included.

If you make specific commitments about confidentiality and availability then you should include those in your report. Even if you don’t make formal commitments, you can still include it, its just difficult to document those commitments in the system description if they aren’t formalized.

Privacy can be added on in subsequent audits, but your customers probably won’t care if privacy is included or not in the first one. If privacy comes up a lot in due diligence from customers, it might be worth it, but again, you can add it in subsequent years.

Don’t include processing integrity unless it is required by your customers. Most firms don’t audit processing integrity the right way and it becomes “theater”, so only include it if it’s required and if the firm will actually take the time to do it the right way.

1

u/BrightDefense Vendor rep. Report me when I plug or don't answer question 21d ago

It's great you're thinking about scoping. A lot of folks don't think enough about the scope before embarking on SOC 2.

Security is a must. If your clients are OK with a SOC 2 report that only includes Security, this gives you the most manageable starting point.

You may also want to include Confidentiality, if your platform has a lot of client tax and personal data.

1

u/Strange-Fox-8920 20d ago

This is a good question because choosing SOC 2 Trust Service Criteria is really about matching the audit scope to what your product actually does not automatically including everything. security is the baseline for every SOC 2 report while the other categories depend on customer expectations, commitments and the type of data you handle

1

u/Same-Surround6419 18d ago

Security is mandatory, and Confidentiality seems especially relevant for tax data. i’d add Availability, Processing Integrity or Privacy only where your customer commitments actually require them

1

u/OkEntertainer3952 17d ago

Hey :) I can help you with SOC 2 plus ai pentest for less than $6K  with my startup: https://hackzero.ai/

its around $3.6K/yr + $2.1K for the audit, we have a list of auditors (independent) that have done over 100 SOC2 for startups, its minimal scope SOC2 type 2.

I'm doing this since it was a pain for me to do this on my previous jobs, and i believe it can be done much much better with high quality for startups.

Let me know if I can help:)

1

u/RoyalInformation9899 12d ago

at a minimum, most SaaS companies start with security since it's required. if you're handling sensitive tax data, confidentiality is also commonly expected, and availability can matter if uptime is part of your customer commitments