How many controls does SOC 2 require?

TL;DR
  • SOC 2 contains no list of controls. It contains 61 criteria, which are statements about what has to be true of your system. You write the controls.
  • Security only, which is what most first reports cover, is 33 of those 61. Privacy alone is another 18.
  • Our own published library lists 89 controls and 369 test steps, and every one of the 61 criteria is covered by something in it. A different firm could cover the same ground with 50 controls or with 150 and both could be right.
  • If someone tells you SOC 2 requires a specific number of controls, they are describing their template, not the rulebook.

The standard counts criteria, not controls

Founders ask me this in the first ten minutes of almost every call. How many controls do we need. They have usually seen a number somewhere, 64 or 80 or 120, and they want to know which one is right.

None of them. The SOC 2 rulebook does not contain a list of controls, and it never has.

What it contains is criteria. The AICPA, the body that writes the standard, publishes the trust services criteria: a set of statements about what has to be true of your system. Criteria describe outcomes. Controls are the things you actually do to make those outcomes true, and you write them.

That distinction is the whole answer. Your auditor tests whether your controls meet the criteria. Nobody checks your controls against a master list, because there is no master list.

Your scope decides how many of the 61 apply

CategoryCriteriaApplies when
Security, the common criteria33Always. Every SOC 2 includes it.
Availability3You make uptime commitments
Confidentiality2You promise to protect specific information
Processing Integrity5You process transactions on someone's behalf
Privacy18You handle personal information under a privacy notice
Total61

Most first SOC 2 reports cover Security only. That is 33 criteria, and it is the right starting scope for almost every small company I speak to.

Adding a category is not a small decision. Privacy on its own is another 18 criteria, more than half again the work of a Security-only report. It is also the category people add most often because a customer said the word, without either side checking what it commits them to.

A working control library lands in the eighties

So if there is no list, what does a real one look like.

Ours lists 89 controls and 369 test steps, published in full. Every one of the 61 criteria is covered by something in it, and you can read every control and every test without talking to us.

That number is not a target. A control that reads "access is reviewed quarterly" and a control that reads "access to production is reviewed quarterly by the engineering lead and recorded in the ticket" are the same control at different resolutions. Split one into three and your count goes up while nothing about your security changes.

What matters is coverage. Every criterion in your scope has to be addressed by something. The count is bookkeeping.

Points of focus are guidance, and people read them as a checklist

Underneath each criterion the AICPA lists points of focus. These are examples of what an organization might do to meet it. The standard says plainly that they are guidance and that you are not required to address every one.

I raise this because points of focus are where inflated control counts come from. There are a few hundred of them across the framework. Treat each as a requirement and you generate a library nobody can maintain, most of it describing things that do not apply to a company of five people.

They are prompts. They are genuinely useful read that way.

Three things actually decide your number

Your scope. Security only, or Security plus something else. This moves the number more than anything.

Your stack. A company running one cloud account and one identity provider needs fewer controls than one running three clouds, because there are fewer places for the same criterion to land.

Your appetite for detail. Some firms write few broad controls, some write many narrow ones. Narrow controls are easier to test and easier to fail. Broad ones are harder to evidence.

None of those is something you can look up. If a provider hands you a fixed control list and cannot explain which parts do not apply to you, that is worth asking about before you sign anything.

Frequently asked questions

How many controls does SOC 2 have?
SOC 2 has no set number of controls. The AICPA defines 61 trust services criteria, which are statements about what must be true of your system, and you design your own controls to meet the ones in your scope. Published control libraries commonly land anywhere between 50 and 150 for the same 61 criteria, and all of them can be correct.
How many controls do I need for a Security-only SOC 2?
Security only means the 33 common criteria. How many controls cover them is up to you and your auditor. Our published library lists 89 controls and 369 test steps, with every one of the 61 criteria covered by something in it, so a Security-only scope draws on a subset of those. What gets tested is coverage of the criteria, not a control count.
What are the five trust services criteria categories?
Security, Availability, Confidentiality, Processing Integrity, and Privacy. Security is mandatory and contains 33 criteria, called the common criteria. Availability adds 3, Confidentiality 2, Processing Integrity 5, and Privacy 18, for 61 in total. Most first reports cover Security only.
Does the AICPA publish a required SOC 2 control list?
No. The AICPA publishes criteria and points of focus, not controls. Points of focus are explicitly guidance, and the standard states you are not required to address every one. Any control list you are handed is a firm's or a vendor's interpretation of the criteria, not the rulebook itself.
Why do different SOC 2 control lists have different numbers?
Because a control is a unit of description and firms choose different resolutions. One firm writes logical access review as a single control. Another splits it into production access, corporate access, and third-party access. Same coverage, three times the count. Compare what is covered, not how many rows are in the spreadsheet.

Keep reading

Sources
  1. Trust Services Criteria are evaluated at the criterion level; points of focus are illustrative, not requirements (2017 TSC with revised points of focus, 2022).
  2. AT-C section 205 sets the performance and reporting requirements for examination engagements such as SOC 2; it does not prescribe a required number of controls, a required volume of evidence, or a required sample size.
  3. SOC 2 is an examination performed by CPAs under the AICPA attestation standards, governed by AT-C 205, not a certification.
  4. The Chiaro control library, the criteria it maps to, and every test step are published in full.