Logical and Physical Access Controls (CC6)
CC6 is a group of SOC 2 Common Criteria that deals with how an organization restricts, monitors, and removes access to its systems, data, and physical facilities. It covers both digital ('logical') access, such as user logins and permissions, and physical access, such as entry to buildings or server rooms. The goal is to make sure only authorized people can reach sensitive information and production environments.
CC6 is a control family within the Security category (Common Criteria) of the SOC 2 Trust Services Criteria, addressing logical and physical access controls. It typically concerns how systems restrict access to data and production environments, provision and remove access, prevent unauthorized access, and monitor access activity, spanning both digital access mechanisms (such as authentication and authorization) and physical safeguards (such as facility and data center entry controls). As part of the Common Criteria, CC6 falls under the only required Trust Services category, Security, and is evaluated within a SOC 2 examination performed by a licensed CPA firm; the specific controls assessed and their operating effectiveness depend on the engagement scope and, for Type II reports, the defined review period. A SOC 2 report addressing CC6 attests only to the controls and period covered and does not guarantee freedom from breaches, and CC6 should not be conflated with ISO 27001 Annex A access control references, which are selected through a Statement of Applicability under a distinct certification framework.
Why it matters
Access controls are frequently the difference between a contained security event and a full compromise. CC6 sits within the Security category (the Common Criteria), which is the only required Trust Services category in a SOC 2 examination, so how an organization restricts, provisions, removes, and monitors access is nearly always in scope. Weaknesses here, such as orphaned accounts left active after an employee departs, over-broad permissions, or unguarded physical entry to a data center, are among the most common ways unauthorized parties reach sensitive data and production environments.
Because CC6 spans both logical access (authentication, authorization, and permission management) and physical access (facility and server room entry), it forces organizations to think about the full path an attacker or insider might take to reach protected information. A strong logical control posture provides limited protection if physical safeguards are absent, and vice versa. Auditors typically examine both dimensions together, which is why CC6 tends to carry significant weight in a SOC 2 engagement.
It is important to keep the boundaries clear: a SOC 2 report addressing CC6 attests only to the controls and the period covered by the examination, and it does not guarantee freedom from breaches. For a Type II report, effectiveness is evaluated over a defined review period set during scoping, so the assurance provided is tied to that window rather than being a perpetual guarantee. Readers should also avoid conflating CC6 with ISO 27001 Annex A access control references, which are selected through a Statement of Applicability under a separate certification framework.
Who it's relevant to
Inside CC6
Common questions
Answers to the questions practitioners most commonly ask about CC6.