CC3 Security (Common Criteria) · 4 criteria

SOC 2 CC3 — Risk Assessment

CC3 is your risk assessment, and it has to be current, consider fraud explicitly, and visibly drive the controls tested elsewhere in the report. Auditors trace from a risk in your register to the control that addresses it, so a risk assessment that exists but connects to nothing is a recurring finding.

All 4 CC3 criteria

CC3.1 Objectives for risk assessment
COSO Principle 6 — The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
CC3.2 Risk identification and analysis
COSO Principle 7 — The entity identifies risks to the achievement of its objectives and analyzes them as a basis for determining how they should be managed.
CC3.3 Fraud risk assessment
COSO Principle 8 — The entity considers the potential for fraud in assessing risks to the achievement of objectives.
CC3.4 Assessing significant change
COSO Principle 9 — The entity identifies and assesses changes that could significantly impact the system of internal control.

Other criteria series

CC1 CC2 CC4 CC5 CC6 CC7 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC3?

CC3 Risk Assessment contains 4 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC3 required in every SOC 2 report?

Yes. CC3 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC3?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.