If our SOC 2 covers only Availability, do the common criteria still apply?
Question as asked: If our SOC 2 examination covers only the Availability category, do the common criteria still apply?
Yes — the common criteria always apply, in every SOC 2 examination, regardless of which Trust Services category is in scope.
Per the TSC structure (TSC paras .14–.15), Security is the common criteria (CC1–CC9) standing alone. Availability, Confidentiality, Processing Integrity and Privacy are each built on top of the common criteria — they add category-specific criteria (for Availability, A1.1–A1.3) but never replace or exclude CC1–CC9.
An Availability-only examination (i.e., Availability without Security) is uncommon but permitted. In that scenario the common criteria are still tested, but they are evaluated as they relate to the availability objectives rather than as a general security opinion. For example:
- CC6 (logical and physical access) is assessed for how access controls protect the system's capacity to meet availability commitments;
- CC7 (system operations) is assessed for how monitoring, incident response and recovery affect availability;
- CC8.1 (change management) is assessed for how changes could disrupt availability;
- CC9.1 (business disruption risk) ties directly into the A1 criteria on capacity, environmental protections/backup, and recovery testing.
So the correct statement is: the common criteria are always part of the criteria set; only their evaluation lens narrows to the reported-on category. It would be incorrect to say Security is "always included" as a separate opinion, or that the common criteria are waived when Availability alone is in scope — CC1–CC9 (33 criteria) plus A1.1–A1.3 (3 criteria) together make up the full criteria set for an Availability-only report (36 criteria total).
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)