Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security TSP 100
Cyber Security

TSP 100

← Back to Glossary
By NHI Mgmt Group Updated September 20, 2026 Domain: Cyber Security

TSP 100 is the AICPA guidance document that defines the Trust Services Criteria and their points of focus. It explains how organisations and auditors should interpret each criterion and gives implementation guidance that helps translate the framework into practical controls, evidence, and audit expectations.

What TSP 100 Covers

TSP 100 is not a control framework in itself, but the interpretive guide that explains how the AICPA Trust Services Criteria and their points of focus should be read, evidenced, and applied in practice. For auditors and organisations, its value is in turning the criteria from abstract principles into a shared testing and implementation baseline.

That distinction matters because TSP 100 shapes what counts as a relevant control, what evidence is persuasive, and how exceptions are judged. It is therefore part reference document, part implementation lens, and part audit expectation setter.

How It Relates to Trust Services Criteria

The Trust Services Criteria are the substance; TSP 100 is the interpretive layer that helps organisations understand how those criteria are meant to work in real environments. It clarifies the relationship between each criterion and its points of focus, which is important when a control objective is broad enough to allow different implementation patterns.

That interpretive role is especially useful when teams need to map policies, configurations, monitoring, and evidence to one criterion without treating the criteria as a checklist of isolated statements. In practice, TSP 100 helps align audit language, control design, and operational evidence around the same security intent.

For readers working on third-party assurance or vendor assessments, the closest external reference point is the SOC 2 Trust Services Criteria (AICPA), because TSP 100 exists to explain how those criteria are interpreted and applied.

Why It Matters for Control Design and Audit Evidence

TSP 100 matters because controls are only useful if they can be defended consistently. The guidance helps organisations decide whether a control is genuinely aligned to the criterion, whether the evidence is sufficiently direct, and whether the implementation is strong enough to satisfy an auditor’s expectation without overfitting to a narrow technical reading.

That is why the document is often used during control design, readiness assessments, and audit preparation. It gives teams a way to translate high-level trust requirements into repeatable operational practices, while still leaving room for environment-specific implementation choices.

A practical reading of the criteria is helped by broader control catalogs such as NIST SP 800-53 Rev 5 Security and Privacy Controls, which similarly connect governance intent to concrete control families like access control, audit, and configuration management.

Common Misunderstandings About TSP 100

A common mistake is to treat TSP 100 as if it were the same thing as the Trust Services Criteria. It is not. The criteria define the control expectations, while TSP 100 explains how to interpret those expectations and where the points of focus fit into the overall assessment.

Another misunderstanding is assuming the document prescribes one fixed technical implementation. In reality, it supports more than one way to satisfy a criterion, as long as the control outcome, evidence quality, and audit logic remain consistent with the intent of the guidance.

For teams that need implementation detail rather than interpretive guidance, the OWASP Cheat Sheet Series is a useful complementary reference because it focuses on practitioner-level control execution across areas such as authentication, secrets handling, and session management.

Risk and Threat Considerations

TSP 100 is usually discussed as an audit and governance document, but the risk lies in misreading it as a substitute for actual control design. If organisations rely on a superficial interpretation, they can end up with controls that look compliant on paper while leaving real gaps in evidence, operating discipline, or control coverage.

Failure mechanism: Weak interpretation can produce incomplete mappings between criteria, controls, and evidence, which then lets gaps survive until audit time or, worse, until a real control failure exposes them.

Impact: The result can be failed audits, costly remediation, inconsistent assurance claims, and reduced trust in the organisation’s reported control posture.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 4 — Secure Configuration of Enterprise Assets and SoftwareTSP 100 supports control evidence and implementation interpretation for security criteria.
CIS Control 6 — Access Control ManagementTrust Services Criteria commonly depend on access control outcomes and documented enforcement.
CIS Control 8 — Audit Log ManagementTSP 100 relies on evidence quality, and audit logging is often core evidence for trust criteria.
Recommendation — Align control evidence to secure configuration baselines that auditors can verify. Document and enforce access control decisions with reviewable evidence. Collect and retain audit logs that substantiate control operation and exceptions.
NIST CSF 2.0GV.OC-01 — Organisational ContextTSP 100 helps organisations interpret trust criteria in the context of their control environment.
PR.AA-01 — Identity Management, Authentication, and Access ControlTrust Services Criteria often require demonstrable access governance and authentication controls.
GV.RM-01 — Risk Management StrategyTSP 100 informs how organisations judge whether controls adequately address trust and assurance risk.
Recommendation — Define control context so trust criteria map cleanly to business and assurance needs. Apply access and authentication controls that support audit-ready assurance evidence. Use a risk strategy that ties assurance criteria to measurable control outcomes.

Practitioner Guidance

Why practitioners should care: TSP 100 is most useful when teams need to prove that their controls are not just present, but defensibly aligned to the Trust Services Criteria. It helps reduce ambiguity between policy language, operational execution, and audit evidence.

Practitioner takeaway: Treat TSP 100 as the interpretive bridge between criterion intent and control evidence, and use it to test whether your implementation would still make sense to an auditor reviewing the underlying objective, not just the documentation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org