CC6 is the heaviest-tested series in most SOC 2 reports and the one where exceptions most often appear. It covers logical access, physical access, encryption, and the full joiner-mover-leaver lifecycle. Expect user access reviews, provisioning and deprovisioning tickets, and configuration exports to be sampled across the entire review period — evidence assembled shortly before fieldwork is the classic Type 2 failure.
CC6 Logical and Physical Access Controls contains 8 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.
Yes. CC6 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.
A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.