Understanding the 9 Common Criteria of the SOC 2 Security Principle

When tech companies prepare for a SOC 2 audit, they quickly learn that the Security principle is the only mandatory component of the evaluation. The American Institute of Certified Public Accountants refers to this foundation as the Common Criteria. This name is used because these exact controls form the baseline framework for the entire audit. If you choose to add optional principles like Availability or Privacy later on, they will all rest on top of this secure foundation.

To pass your audit, you must demonstrate specific internal controls that map directly to the nine categories within the Common Criteria. Understanding what auditors evaluate in each category is the best way to prepare your team and avoid surprises during fieldwork.

Breakdown of the Nine Common Criteria

The Common Criteria are organized from CC1 to CC9. They cover everything from corporate governance to technical access management.

CC1: Control Environment

This category focuses on corporate culture and leadership accountability. Auditors look for evidence that your business values integrity and ethical values. They will ask to see your official code of conduct, an up-to-date organizational chart, and documented job descriptions that outline security responsibilities.

CC2: Communication and Information

Security policies are useless if your team does not know they exist. This criterion evaluates how well your company communicates security responsibilities internally and externally. Auditors look for signed policy acknowledgments from employees, active security awareness training logs, and non-disclosure agreements with your vendors.

CC3: Risk Assessment

Your organization must proactively identify things that could disrupt your business operations or compromise data. Under CC3, auditors evaluate your formal risk assessment process. You need to show a documented risk register, periodic vulnerability scanning procedures, and regular penetration testing schedules.

CC4: Monitoring Activities

This area ensures that your internal controls actually do their job over time. Auditors want to see that your compliance team regularly tests your own systems. They will look for internal audit reports, automated configuration alerts, and proof that management reviews vendor performance.

CC5: Control Activities

This category looks at the specific actions and software rules you implement to mitigate risks. Auditors look for documented proof of backup verifications, regular policy reviews, and security assessments performed before code updates are pushed live.

CC6: Logical and Physical Access Controls

This is one of the most technical parts of the audit. It evaluates how you restrict digital and physical access to sensitive systems. Auditors expect to see multi-factor authentication enforced on all admin accounts, role-based access controls, and strict termination workflows that revoke employee access within 24 hours of departure.

CC7: System Operations

This category evaluates how you manage daily system performance and handle live anomalies. Auditors will evaluate your centralized log monitoring tools, your incident response plan, and your disaster recovery testing records to ensure you can detect and contain threats quickly.

CC8: Change Management

Uncontrolled changes to production environments are a major security risk. Under CC8, auditors check your software development lifecycle. They expect to see pull request peer reviews, documented change logs for deployments, and testing evidence in non-production environments.

CC9: Risk Mitigation and Third-Party Risk

Your security posture is only as strong as the weakest vendor in your supply chain. This final category looks at how you manage third-party risk. You must provide evidence of vendor risk assessments, thorough due diligence reviews, and active business continuity coordination with critical cloud providers.

Frequently Asked Questions

What does CC stand for in a SOC 2 audit?

CC stands for Common Criteria. These are the nine standard categories of security controls defined by the AICPA that form the core foundation of every SOC 2 report.

Why is the Security principle mandatory?

The Security principle is mandatory because it establishes the baseline environment for your infrastructure. Without access controls, risk management, and change governance, it is impossible to guarantee data privacy or system availability.

How often should we perform the risk assessments required in CC3?

Most auditors expect a formal enterprise-wide risk assessment to be conducted at least once a year. You should also run a new assessment whenever there are major changes to your business model or software architecture.

Share it :