CC5 Security (Common Criteria) · 3 criteria

SOC 2 CC5 — Control Activities

CC5 connects the risks identified in CC3 to concrete control activities, including the technology controls and the policies that govern them. A control matrix mapping risk to control to owner is the artefact that satisfies this series most cleanly.

All 3 CC5 criteria

CC5.1 Control activities mitigating risk
COSO Principle 10 — The entity selects and develops control activities that contribute to the mitigation of risks to acceptable levels.
CC5.2 General controls over technology
COSO Principle 11 — The entity selects and develops general control activities over technology to support the achievement of objectives.
CC5.3 Policies and procedures
COSO Principle 12 — The entity deploys control activities through policies that establish what is expected and procedures that put policies into action.

Other criteria series

CC1 CC2 CC3 CC4 CC6 CC7 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC5?

CC5 Control Activities contains 3 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC5 required in every SOC 2 report?

Yes. CC5 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC5?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.