SOC 2 Security (Common Criteria) (CC1–CC9)
The mandatory category — every SOC 2 examination includes the Common Criteria, whatever else is in scope. CC1–CC5 inherit the COSO internal-control framework; CC6–CC9 carry the technical weight: access, operations, change management and vendor risk. This is ~80% of a typical SOC 2 effort.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit
The criteria that decide your examination
Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).
Where examinations produce exceptions
Type II covers an observation window (commonly 6–12 months). A control implemented in month 5 of a 6-month window produces exceptions for months 1–4 — sequencing readiness matters.
The classic CC6.2/6.3 exception: leavers with active accounts days or weeks after exit. Auditors reconcile HR lists against IdP logs across the whole period.
CC8.1 samples changes across the period; emergency changes without retrospective approval are the most common exception in engineering-led teams.
CC9.2 needs vendor risk assessments, security terms and periodic review — a spreadsheet of names satisfies nobody.
Evidence auditors sample
- Governance artefacts: org chart, board/security-committee minutes, policy approvals
- Access lifecycle samples: joiner/mover/leaver tickets reconciled to IdP records
- Vulnerability and monitoring evidence with triage and closure (CC7)
- Change samples across the period: request → test → approval → deploy (CC8.1)
- Incident records incl. evaluation, response, communication (CC7.3–7.5)
- Vendor register with assessments, agreements and review records (CC9.2)
Security (Common Criteria) FAQ
Is the Security category mandatory in SOC 2?
Yes — the Common Criteria (Security) are included in every SOC 2 examination; Availability, Processing Integrity, Confidentiality and Privacy are added based on the commitments you make to customers.
What is the difference between Type I and Type II?
Type I opines on design of controls at a point in time; Type II adds operating effectiveness over a period (commonly 6–12 months). Enterprise customers almost always ask for Type II.
Who can issue a SOC 2 report?
Only a licensed CPA firm can issue the attestation. A readiness partner like CyberSigma prepares you — gap assessment, remediation, evidence — and coordinates the audit with the CPA firm.
Security (Common Criteria) in your SOC 2 scope
We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.
