How many controls does SOC 2 require?
- SOC 2 contains no list of controls. It contains 61 criteria, which are statements about what has to be true of your system. You write the controls.
- Security only, which is what most first reports cover, is 33 of those 61. Privacy alone is another 18.
- Our own published library lists 89 controls and 369 test steps, and every one of the 61 criteria is covered by something in it. A different firm could cover the same ground with 50 controls or with 150 and both could be right.
- If someone tells you SOC 2 requires a specific number of controls, they are describing their template, not the rulebook.
The standard counts criteria, not controls
Founders ask me this in the first ten minutes of almost every call. How many controls do we need. They have usually seen a number somewhere, 64 or 80 or 120, and they want to know which one is right.
None of them. The SOC 2 rulebook does not contain a list of controls, and it never has.
What it contains is criteria. The AICPA, the body that writes the standard, publishes the trust services criteria: a set of statements about what has to be true of your system. Criteria describe outcomes. Controls are the things you actually do to make those outcomes true, and you write them.
That distinction is the whole answer. Your auditor tests whether your controls meet the criteria. Nobody checks your controls against a master list, because there is no master list.
Your scope decides how many of the 61 apply
| Category | Criteria | Applies when |
|---|---|---|
| Security, the common criteria | 33 | Always. Every SOC 2 includes it. |
| Availability | 3 | You make uptime commitments |
| Confidentiality | 2 | You promise to protect specific information |
| Processing Integrity | 5 | You process transactions on someone's behalf |
| Privacy | 18 | You handle personal information under a privacy notice |
| Total | 61 |
Most first SOC 2 reports cover Security only. That is 33 criteria, and it is the right starting scope for almost every small company I speak to.
Adding a category is not a small decision. Privacy on its own is another 18 criteria, more than half again the work of a Security-only report. It is also the category people add most often because a customer said the word, without either side checking what it commits them to.
A working control library lands in the eighties
So if there is no list, what does a real one look like.
Ours lists 89 controls and 369 test steps, published in full. Every one of the 61 criteria is covered by something in it, and you can read every control and every test without talking to us.
That number is not a target. A control that reads "access is reviewed quarterly" and a control that reads "access to production is reviewed quarterly by the engineering lead and recorded in the ticket" are the same control at different resolutions. Split one into three and your count goes up while nothing about your security changes.
What matters is coverage. Every criterion in your scope has to be addressed by something. The count is bookkeeping.
Points of focus are guidance, and people read them as a checklist
Underneath each criterion the AICPA lists points of focus. These are examples of what an organization might do to meet it. The standard says plainly that they are guidance and that you are not required to address every one.
I raise this because points of focus are where inflated control counts come from. There are a few hundred of them across the framework. Treat each as a requirement and you generate a library nobody can maintain, most of it describing things that do not apply to a company of five people.
They are prompts. They are genuinely useful read that way.
Three things actually decide your number
Your scope. Security only, or Security plus something else. This moves the number more than anything.
Your stack. A company running one cloud account and one identity provider needs fewer controls than one running three clouds, because there are fewer places for the same criterion to land.
Your appetite for detail. Some firms write few broad controls, some write many narrow ones. Narrow controls are easier to test and easier to fail. Broad ones are harder to evidence.
None of those is something you can look up. If a provider hands you a fixed control list and cannot explain which parts do not apply to you, that is worth asking about before you sign anything.
Frequently asked questions
How many controls does SOC 2 have?
How many controls do I need for a Security-only SOC 2?
What are the five trust services criteria categories?
Does the AICPA publish a required SOC 2 control list?
Why do different SOC 2 control lists have different numbers?
Keep reading
Do you need an evidence collection tool?
Nothing in the standards requires one. Evidence is records your systems already produce, and the auditor should be the one collecting them.
How much evidence does a SOC 2 audit need?
About twenty sources, and one export often answers several criteria at once. What auditors ask for, and what does not count.
How many samples does an auditor actually test?
No standard sets a number. How often the control runs does. The table firms work from, and why which items get picked matters more.
How long does a SOC 2 audit take?
Three clocks run and only one is your auditor's. Where the time actually goes, and the part nothing can speed up.
Sources
- Trust Services Criteria are evaluated at the criterion level; points of focus are illustrative, not requirements (2017 TSC with revised points of focus, 2022).
- AT-C section 205 sets the performance and reporting requirements for examination engagements such as SOC 2; it does not prescribe a required number of controls, a required volume of evidence, or a required sample size.
- SOC 2 is an examination performed by CPAs under the AICPA attestation standards, governed by AT-C 205, not a certification.
- The Chiaro control library, the criteria it maps to, and every test step are published in full.