Audit and compliance
Trust Services Criteria
Also called: TSC, AICPA TSC, trust service principles
The Trust Services Criteria are the AICPA's control criteria used in SOC 2 engagements, organized into five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security is required in every SOC 2; the others are included only if the organization selects them.
Security is also called the common criteria, numbered CC1 through CC9. CC4.1 covers evaluations to confirm controls are present and functioning, and CC7.1 covers detecting vulnerabilities, which is where penetration testing evidence usually lands.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.