We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SOC 2 Trust Services Criteria · Required in every report

SOC 2 Security (Common Criteria) (CC1–CC9)

The mandatory category — every SOC 2 examination includes the Common Criteria, whatever else is in scope. CC1–CC5 inherit the COSO internal-control framework; CC6–CC9 carry the technical weight: access, operations, change management and vendor risk. This is ~80% of a typical SOC 2 effort.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit

The criteria that decide your examination

CC1.x
Control environment

Integrity, board oversight, structure, competence and accountability — the COSO layer auditors verify through governance artefacts, org charts and HR practices.

CC2.x
Communication and information

Internal and external communication of security commitments and responsibilities — policies published, customers informed, incidents communicated.

CC3.x
Risk assessment

Objectives specified, risks identified and analysed (including fraud risk), significant change considered — a living risk register, not an annual PDF.

CC4.x
Monitoring activities

Ongoing and separate evaluations of controls, with deficiencies communicated and tracked to closure.

CC5.x
Control activities

Controls selected and deployed to mitigate risks, including over technology — the bridge from risk register to actual safeguards.

CC6.1–6.8
Logical and physical access

The largest block: access provisioning/deprovisioning, authentication, least privilege, physical access, media disposal, and protection against outside access and malware.

CC7.1–7.5
System operations

Vulnerability monitoring, anomaly detection, incident evaluation, response and recovery — with evidence the loop has actually run.

CC8.1
Change management

Infrastructure, data and software changes authorised, designed, tested, approved and implemented — sampled end to end across the period.

CC9.1–9.2
Risk mitigation and vendors

Business-disruption risk mitigation and vendor/business-partner risk management — assessments, agreements, monitoring.

Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).

Where examinations produce exceptions

Point-in-time thinking for a period report

Type II covers an observation window (commonly 6–12 months). A control implemented in month 5 of a 6-month window produces exceptions for months 1–4 — sequencing readiness matters.

Deprovisioning gaps found by sampling

The classic CC6.2/6.3 exception: leavers with active accounts days or weeks after exit. Auditors reconcile HR lists against IdP logs across the whole period.

Change tickets that skip approval or testing

CC8.1 samples changes across the period; emergency changes without retrospective approval are the most common exception in engineering-led teams.

Vendor list without risk treatment

CC9.2 needs vendor risk assessments, security terms and periodic review — a spreadsheet of names satisfies nobody.

Evidence auditors sample

  • Governance artefacts: org chart, board/security-committee minutes, policy approvals
  • Access lifecycle samples: joiner/mover/leaver tickets reconciled to IdP records
  • Vulnerability and monitoring evidence with triage and closure (CC7)
  • Change samples across the period: request → test → approval → deploy (CC8.1)
  • Incident records incl. evaluation, response, communication (CC7.3–7.5)
  • Vendor register with assessments, agreements and review records (CC9.2)

Security (Common Criteria) FAQ

Is the Security category mandatory in SOC 2?

Yes — the Common Criteria (Security) are included in every SOC 2 examination; Availability, Processing Integrity, Confidentiality and Privacy are added based on the commitments you make to customers.

What is the difference between Type I and Type II?

Type I opines on design of controls at a point in time; Type II adds operating effectiveness over a period (commonly 6–12 months). Enterprise customers almost always ask for Type II.

Who can issue a SOC 2 report?

Only a licensed CPA firm can issue the attestation. A readiness partner like CyberSigma prepares you — gap assessment, remediation, evidence — and coordinates the audit with the CPA firm.

Availability (A1)

Security (Common Criteria) in your SOC 2 scope

We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.