Skip to main content

SOC 2 Trust Services Criteria

The SOC 2 Trust Services Criteria are the criteria a service organization's controls are evaluated against in a SOC 2 examination, published by the AICPA. They apply to the operator of the service, not the software it runs. This page indexes two criteria from the Common Criteria series that bear on software development: system operations and change management.

Requirement groupThemes
CC7 System operationsT6 Automated security verification
T13 Vulnerability handling and disclosure
CC8.1 Change managementT5 Independent review before a change is accepted
T7 Testing and acceptance
T8 Change control and traceability