Back to Frameworks

SOC 2 (AICPA TSP-100)

International
5 domains
51 controls

AICPA Trust Services Criteria 2017 with 2022 Points of Focus. Used in SOC 2 Type 1 and Type 2 examinations.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Availability

3 controls
Controls in the Availability domain of SOC 2 (AICPA TSP-100)3 controls
CodeTitle
A1.1Capacity Management
A1.2Environmental Protections, Backups, Recovery Infrastructure
A1.3Recovery Plan Testing

Common Criteria

33 controls
Controls in the Common Criteria domain of SOC 2 (AICPA TSP-100)33 controls
CodeTitle
CC1.1Commitment to Integrity and Ethical Values
CC1.2Board Independence and Oversight
CC1.3Management Structures, Reporting Lines, Authorities
CC1.4Commitment to Competence
CC1.5Accountability for Internal Control
CC2.1Information Quality
CC2.2Internal Communication
CC2.3External Communication
CC3.1Objective Clarity
CC3.2Risk Identification and Analysis
CC3.3Fraud Risk Assessment
CC3.4Change Assessment
CC4.1Ongoing and Separate Evaluations
CC4.2Deficiency Communication
CC5.1Control Selection and Development
CC5.2Technology General Controls
CC5.3Policy Deployment
CC6.1Logical Access Security Software and Infrastructure
CC6.2User Registration and Authorization
CC6.3Role-Based Access and Least Privilege
CC6.4Physical Access Restrictions
CC6.5Asset Disposal and Data Destruction
CC6.6Boundary Protection
CC6.7Data Transmission and Movement Controls
CC6.8Unauthorized or Malicious Software Prevention
CC7.1Vulnerability and Configuration Management
CC7.2Security Event Monitoring
CC7.3Security Event Evaluation
CC7.4Incident Response
CC7.5Incident Recovery
CC8.1Change Management
CC9.1Business Disruption Risk Mitigation
CC9.2Vendor and Business Partner Risk Management

Confidentiality

2 controls
Controls in the Confidentiality domain of SOC 2 (AICPA TSP-100)2 controls
CodeTitle
C1.1Identification and Maintenance of Confidential Information
C1.2Disposal of Confidential Information

Privacy

8 controls
Controls in the Privacy domain of SOC 2 (AICPA TSP-100)8 controls
CodeTitle
P1.1Notice to Data Subjects
P2.1Choice and Consent
P3.1Collection Limitation
P4.1Use, Retention, and Disposal of Personal Information
P5.1Access by Data Subjects
P6.1Disclosure and Notification
P7.1Quality of Personal Information
P8.1Monitoring and Enforcement of Privacy

Processing Integrity

5 controls
Controls in the Processing Integrity domain of SOC 2 (AICPA TSP-100)5 controls
CodeTitle
PI1.1Quality Information for Processing
PI1.2Input Completeness and Accuracy
PI1.3Processing Completeness, Accuracy, Timeliness, Authorization
PI1.4Output Completeness, Accuracy, Distribution
PI1.5Storage Integrity of Records and Outputs

Frequently Asked Questions

What is SOC 2 (AICPA TSP-100)?

SOC 2 (AICPA TSP-100) is a compliance framework from International with 5 domains and 51 controls. AICPA Trust Services Criteria 2017 with 2022 Points of Focus. Used in SOC 2 Type 1 and Type 2 examinations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does SOC 2 (AICPA TSP-100) have?

SOC 2 (AICPA TSP-100) has 51 controls organised across 5 domains. The largest domains are Common Criteria (33 controls), Privacy (8 controls), Processing Integrity (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does SOC 2 (AICPA TSP-100) map to?

SOC 2 (AICPA TSP-100) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with SOC 2 (AICPA TSP-100) compliance?

Start your SOC 2 (AICPA TSP-100) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SOC 2 (AICPA TSP-100) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 51 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required