CC9 Security (Common Criteria) · 2 criteria

SOC 2 CC9 — Risk Mitigation

CC9 covers business disruption and vendor risk. Evidence spans BCDR test results and the third-party review files showing you assess the vendors that handle your data — including the sub-processors your customers will ask about.

All 2 CC9 criteria

CC9.1 Business disruption risk mitigation
Risk mitigation activities are identified, selected, and developed for risks arising from potential business disruptions.
CC9.2 Vendor and business partner risk
Risks associated with vendors and business partners are assessed and managed.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC6 CC7 CC8 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC9?

CC9 Risk Mitigation contains 2 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC9 required in every SOC 2 report?

Yes. CC9 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC9?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.