Trust Services Criteria — Availability
Current AICPA Trust Services CriteriaWho it applies to
- Entities and teams responsible for controls supporting the availability trust-services criterion
- Entities and teams responsible for backup, recovery and continuity capability
- Entities and teams responsible for vendor and sub-service-organisation management
- Entities and teams responsible for evidence of operating effectiveness over time
SOC 2 is an attestation framework, not a regulation with one operative date. Timing is defined by the service organisation’s examination period and customer assurance commitments.