Compliance Colleague · Answers · SOC 2

If our SOC 2 covers only Availability, do the common criteria still apply?

Standard: SOC 2 · Answered by Compliance Colleague on September 30, 2026

Question as asked: If our SOC 2 examination covers only the Availability category, do the common criteria still apply?

Yes — the common criteria always apply, in every SOC 2 examination, regardless of which Trust Services category is in scope.

Per the TSC structure (TSC paras .14–.15), Security is the common criteria (CC1–CC9) standing alone. Availability, Confidentiality, Processing Integrity and Privacy are each built on top of the common criteria — they add category-specific criteria (for Availability, A1.1–A1.3) but never replace or exclude CC1–CC9.

An Availability-only examination (i.e., Availability without Security) is uncommon but permitted. In that scenario the common criteria are still tested, but they are evaluated as they relate to the availability objectives rather than as a general security opinion. For example:

  • CC6 (logical and physical access) is assessed for how access controls protect the system's capacity to meet availability commitments;
  • CC7 (system operations) is assessed for how monitoring, incident response and recovery affect availability;
  • CC8.1 (change management) is assessed for how changes could disrupt availability;
  • CC9.1 (business disruption risk) ties directly into the A1 criteria on capacity, environmental protections/backup, and recovery testing.

So the correct statement is: the common criteria are always part of the criteria set; only their evaluation lens narrows to the reported-on category. It would be incorrect to say Security is "always included" as a separate opinion, or that the common criteria are waived when Availability alone is in scope — CC1–CC9 (33 criteria) plus A1.1–A1.3 (3 criteria) together make up the full criteria set for an Availability-only report (36 criteria total).

Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.

This is one answer from Compliance Colleague, which answers questions like this against 30+ security, privacy and AI governance standards, with the clause cited, and reviews your policies against them. Ask your own question free, no card required →

More answers