Security required
The common criteria: protecting systems and data against unauthorized access, covering access controls, change management, monitoring, and risk management.
Availability
Systems are available for operation and use as committed — uptime, performance monitoring, disaster recovery, and incident handling.
Processing Integrity
Processing is complete, valid, accurate, timely, and authorized — critical for transaction and data-processing platforms.
Confidentiality
Information designated confidential is protected throughout its lifecycle — encryption, access restriction, and secure disposal.
Privacy
Personal information is collected, used, retained, disclosed, and disposed of in line with your privacy notice and AICPA privacy principles.
Evidence, continuously
Across every criterion, a Type II demands ongoing evidence — logs, tickets, reviews, and configs — collected throughout the audit period, not the night before.