Trust Services Criteria
Also known as TSC
The five categories a SOC 2 report can cover: security, availability, processing integrity, confidentiality, and privacy.
Security is mandatory and is referred to as the common criteria. The other four are optional and chosen based on what you promise customers, so a report covering security and availability is a different scope from one covering all five.
Reading which categories are in scope is the first thing to check when a vendor sends you their report.
Where this comes up
Trust Services Criteria sits inside our compliance and frameworks work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.