Skip to main content

SOC 2: Milestones and Trust Service Criteria

Two high-impact settings tucked into the SOC 2 framework's overflow menu — your Type 1/Type 2 milestone, and which Trust Service Criteria you're being assessed against.

Written by Upendra Varma

On your SOC 2 framework page (Prove → Compliance → Frameworks → SOC 2), the menu holds two settings that affect your entire SOC 2 program — both worth understanding before you touch them.

Readiness Milestone: Type 1 vs. Type 2

Edit Milestone controls whether you're working toward a Type 1 (point-in-time) or Type 2 (over a monitoring period) report:

The in-app warning is direct about the blast radius: changing the readiness milestone affects the state of all related tasks and timelines. This isn't a cosmetic label — it's what "SOC 2 Type 2 Readiness: X%" on your Tasks page is actually measuring against. Only change it if you're confident it reflects your current audit goal, and check with support first if you're not sure what switching will do to work already in progress.

Trust Service Criteria

Manage Trust Service Criteria controls which of SOC 2's five criteria you're being assessed against:

Security, Availability, and Confidentiality are selected by default. Processing Integrity and Privacy are optional add-ons you can select if they're relevant to your business (e.g. Privacy if you handle significant personal data). As with the milestone, the in-app warning recommends checking with your customer success manager before changing this — it resyncs your framework's requirements, tests, and controls to match.

Did this answer your question?