Security — formally the Common Criteria, numbered CC1 through CC9 — anchors every report; an audit cannot exclude it. The other four are additive: Availability covers uptime commitments and resilience, Processing Integrity covers whether systems process data completely and accurately, Confidentiality covers protection and disposal of sensitive business information, and Privacy covers personal information handled under your privacy notice. The cover of every report states which categories it includes, and experienced readers check that line before anything else.
None of the criteria hand you controls. Each states an outcome — restrict logical access, manage change, monitor for anomalies — and management designs whatever controls achieve it in their environment, guided by the AICPA’s points of focus. This is why two clean reports can contain entirely different control sets, and why the auditor’s real question is fit: do your controls, as designed and operated, satisfy every criterion in scope? How that evaluation runs end to end is covered in our SOC 2 framework guide.
Categories follow contracts. Promise uptime in your MSAs and reviewers will expect Availability in the report; process payments or payroll and Processing Integrity earns its place; handle consumer data directly and Privacy enters the conversation. Every addition widens the audit boundary and the evidence you must sustain, so most first reports ship with Security alone or Security plus Availability, expanding at renewal once the Type 2 rhythm is established.