CC6 Security (Common Criteria) · 8 criteria

SOC 2 CC6 — Logical and Physical Access Controls

CC6 is the heaviest-tested series in most SOC 2 reports and the one where exceptions most often appear. It covers logical access, physical access, encryption, and the full joiner-mover-leaver lifecycle. Expect user access reviews, provisioning and deprovisioning tickets, and configuration exports to be sampled across the entire review period — evidence assembled shortly before fieldwork is the classic Type 2 failure.

All 8 CC6 criteria

CC6.1 Logical access security architecture
Logical access security software, infrastructure, and architectures are implemented over protected information assets to restrict access to authorized users.
CC6.2 Provisioning and deprovisioning
New internal and external users are registered and authorized prior to issuing credentials; access is removed when no longer authorized.
CC6.3 Role-based access and least privilege
Access to data and resources is authorized, modified, or removed based on roles and responsibilities, considering least privilege and segregation of duties.
CC6.4 Physical access restriction
Physical access to facilities and protected information assets is restricted to authorized personnel.
CC6.5 Secure disposal
Logical and physical protections over assets are discontinued only after the ability to read or recover data has been diminished (secure disposal).
CC6.6 Protection against external threats
Logical access security measures are implemented to protect against threats from sources outside the system boundaries.
CC6.7 Protection of data in transmission and movement
The transmission, movement, and removal of information is restricted and protected during transmission, movement, or removal.
CC6.8 Prevention and detection of malicious software
Controls are implemented to prevent or detect and act upon the introduction of unauthorized or malicious software.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC7 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC6?

CC6 Logical and Physical Access Controls contains 8 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC6 required in every SOC 2 report?

Yes. CC6 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC6?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.