SOC2Prep

Do you need more than SOC 2 security?

Security alone satisfies most buyers. Each extra category adds real work, and privacy adds the most by a distance, so add one only when a customer names it.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Take security only for a first report unless a customer has named another category in writing. Security is the one mandatory category and it satisfies the large majority of vendor security reviews on its own. Adding availability costs roughly 10 to 15 percent more preparation and $3,000 to $6,000 CAD on the audit fee. Confidentiality is similar. Processing integrity is a step up. Privacy roughly doubles the documentation work and is the one companies regret adding to a first report.

1 Categories that are mandatory

+10 to 15% Effort added by availability or confidentiality

+60 to 100% Documentation effort added by privacy

What does each category actually add?

The four optional trust services categories, effort and audit fee impact
CategoryWhat it testsNew controls you will needAdded audit fee (CAD)
Availability That the system is available as you committed Capacity monitoring, uptime measurement against a stated commitment, recovery objectives, a tested disaster recovery exercise $3,000 to $6,000
Confidentiality That information designated confidential is protected and disposed of Data classification, retention schedule per class, evidenced disposal including from backups, confidentiality commitments in contracts $3,000 to $7,000
Processing integrity That processing is complete, valid, accurate, timely and authorized Input validation controls, exception and error queue review with evidence, output reconciliation, definitions of complete and accurate for your system $5,000 to $12,000
Privacy That personal information is handled per your notice and the AICPA privacy criteria Privacy notice, consent records, choice mechanisms, access and correction handling, retention and disposal of personal information, third-party disclosure records, quality controls $8,000 to $20,000
Security, for comparisonMandatory. The nine common criteria families, CC1 to CC9Included in the base fee

Availability and confidentiality both lean on documents you may already have: a tested restore feeds availability, and a data classification and retention schedule feeds confidentiality. Both are covered from the control side on the business continuity plan and the access control policy pages.

The controls column is the real cost, not the fee column. Each of those controls needs to operate across the whole observation window, which means a category added late is a category whose evidence starts late. The common criteria page covers what security alone already asks for.

When does a buyer genuinely need each one?

Availability
When you sell an uptime commitment in the contract and the buyer's business stops if you stop. Infrastructure and platform vendors, payments, anything embedded in someone's production path. If your SLA is aspirational marketing rather than a contractual credit, availability adds an obligation you have not actually taken on.
Confidentiality
When you hold customer information that is confidential by contract rather than personal by law: source code, legal documents, financial models, unreleased product data. It is the category most often requested by professional services and financial buyers, and it is the cheapest of the four to add well.
Processing integrity
When the output of your system is the product and an error is the harm. Payroll, billing, payments, claims adjudication, anything computing a number somebody relies on. It is rarely useful for a general SaaS application, and vendors that add it speculatively find the criteria hard to evidence because they never defined what accurate means.
Privacy
When a buyer names it, and only then. It is written against the AICPA's own privacy criteria, not against PIPEDA, Law 25 or any US state statute, so it does not discharge a Canadian legal obligation and cannot be substituted for one. Companies add it expecting it to answer privacy questionnaires and find it answers a different question.

Privacy in a SOC 2 is not privacy law

The privacy category tests whether you do what your own privacy notice says. It has nothing to say about whether your notice satisfies PIPEDA's accountability requirement or Quebec Law 25's governance duties, and a Canadian company that adds the privacy category is still non-compliant with both if it has not done that work separately. SOC 2 and Law 25 maps what actually applies.

How to decide

  1. Read what the customer wrote. Most contracts say "SOC 2 Type 2" with no category named, and that means security.
  2. If a category is named, take that one and no others. Adding a second because it seems adjacent is how a three-category first report happens.
  3. Check whether you have a contractual availability commitment. If you do and a buyer relies on it, availability is the most defensible addition.
  4. Check whether your contracts designate customer information as confidential. If they do, confidentiality is largely documentation of things you already promised.
  5. Decide before the observation window opens, never during it. A category added in month two has two months of evidence for a three month window.
  6. If in doubt, ship security only and add a category at the next report. The second report is cheaper to expand than the first is to get right.

The case for adding one in year one

There is a real one, and it is commercial rather than technical. If you sell into a market where two of your competitors already hold a security and availability report, arriving with security only invites a question on every deal, and answering it costs sales time forever. Adding availability at the start costs a few thousand CAD and a disaster recovery test you should be running anyway.

What does not justify adding a category is a general sense of wanting a stronger report. Buyers do not read a four-category report as more secure, they read it as covering different things, and a report with a category you struggled to evidence carries exceptions that a narrower report would not have had.

Which trust services criteria are required for SOC 2?

Only security, the common criteria. Availability, confidentiality, processing integrity and privacy are all optional and are selected by you, not imposed by the auditor.

Can we add a category to an existing report?

Not to a report already issued. You select categories for the next examination period, and the new category's controls need to operate for the whole of that period, which usually means deciding a quarter or more before the window opens.

Does the privacy category satisfy PIPEDA?

No. It tests whether you follow your own privacy notice against the AICPA's criteria. PIPEDA's accountability, consent and breach-record obligations are a separate matter and are not examined. Treat them as two projects that share some evidence.

How much does each category add to the audit fee?

Roughly $3,000 to $7,000 CAD each for availability and confidentiality, $5,000 to $12,000 CAD for processing integrity, and $8,000 to $20,000 CAD for privacy, on top of a security-only fee. Readiness effort rises by a similar proportion, and for privacy it rises more.

Do most Canadian SaaS companies take more than security?

Most first reports are security only. Availability is the most common second category and it usually appears at the second or third report, once an uptime commitment has become contractual. Deciding this is part of scoping.

Get the category decision quoted properly

Tell us which categories a customer named and firms will quote against that scope rather than a default.

Get matched