Skip to main content
Category: Trust Services Criteria

Logical and Physical Access Controls (CC6)

Also known as: CC6, CC6, Logical Access Controls, Logical and Physical Access Controls, SOC 2 CC6
Simply put

CC6 is a group of SOC 2 Common Criteria that deals with how an organization restricts, monitors, and removes access to its systems, data, and physical facilities. It covers both digital ('logical') access, such as user logins and permissions, and physical access, such as entry to buildings or server rooms. The goal is to make sure only authorized people can reach sensitive information and production environments.

Formal definition

CC6 is a control family within the Security category (Common Criteria) of the SOC 2 Trust Services Criteria, addressing logical and physical access controls. It typically concerns how systems restrict access to data and production environments, provision and remove access, prevent unauthorized access, and monitor access activity, spanning both digital access mechanisms (such as authentication and authorization) and physical safeguards (such as facility and data center entry controls). As part of the Common Criteria, CC6 falls under the only required Trust Services category, Security, and is evaluated within a SOC 2 examination performed by a licensed CPA firm; the specific controls assessed and their operating effectiveness depend on the engagement scope and, for Type II reports, the defined review period. A SOC 2 report addressing CC6 attests only to the controls and period covered and does not guarantee freedom from breaches, and CC6 should not be conflated with ISO 27001 Annex A access control references, which are selected through a Statement of Applicability under a distinct certification framework.

Why it matters

Access controls are frequently the difference between a contained security event and a full compromise. CC6 sits within the Security category (the Common Criteria), which is the only required Trust Services category in a SOC 2 examination, so how an organization restricts, provisions, removes, and monitors access is nearly always in scope. Weaknesses here, such as orphaned accounts left active after an employee departs, over-broad permissions, or unguarded physical entry to a data center, are among the most common ways unauthorized parties reach sensitive data and production environments.

Because CC6 spans both logical access (authentication, authorization, and permission management) and physical access (facility and server room entry), it forces organizations to think about the full path an attacker or insider might take to reach protected information. A strong logical control posture provides limited protection if physical safeguards are absent, and vice versa. Auditors typically examine both dimensions together, which is why CC6 tends to carry significant weight in a SOC 2 engagement.

It is important to keep the boundaries clear: a SOC 2 report addressing CC6 attests only to the controls and the period covered by the examination, and it does not guarantee freedom from breaches. For a Type II report, effectiveness is evaluated over a defined review period set during scoping, so the assurance provided is tied to that window rather than being a perpetual guarantee. Readers should also avoid conflating CC6 with ISO 27001 Annex A access control references, which are selected through a Statement of Applicability under a separate certification framework.

Who it's relevant to

Compliance and GRC Managers
CC6 is typically a core focus of any SOC 2 engagement because it falls under the required Security category. Compliance managers use it to organize access-related policies, provisioning and deprovisioning procedures, and physical security arrangements, and to gather the evidence auditors will expect. They should also communicate clearly to stakeholders that a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches.
Security Engineers and IT Administrators
Engineers implement the logical controls behind CC6, such as authentication, authorization, and permission management for systems and production environments, as well as the monitoring of access activity. They are often responsible for ensuring access is removed promptly when roles change or employees leave, since stale or over-broad access is a common finding in this area.
Facilities and Physical Security Teams
Because CC6 covers physical as well as logical access, teams responsible for building entry, server rooms, and data center controls play a direct role. Depending on scope, their entry controls and safeguards may be examined as part of the SOC 2 examination alongside digital access mechanisms.
Auditors and Assessors
Licensed CPA firms performing the SOC 2 examination evaluate the design of CC6 controls and, for Type II reports, their operating effectiveness over the defined review period. The specific controls assessed depend on the engagement scope and auditor judgment. Assessors should keep CC6 distinct from ISO 27001 Annex A access control references, which are selected through a Statement of Applicability under a separate framework.

Inside CC6

Logical Access Controls
Controls governing access to systems, applications, and data through mechanisms such as authentication, authorization, and identity management. Within the SOC 2 Trust Services Criteria, these fall under the Common Criteria (Security), which is the only required category.
Physical Access Controls
Controls restricting physical entry to facilities, data centers, and hardware that house systems and data, typically addressed through measures such as badge access, visitor logging, and monitored entry points. The specific controls implemented depend on scope and the auditor's assessment.
User Provisioning and Deprovisioning
Processes for granting access appropriate to a user's role and removing access when it is no longer needed, such as upon termination or role change. The design and operating effectiveness of these processes are evaluated depending on whether the examination is a Type I or Type II.
Authentication and Credential Management
Mechanisms used to verify identity and manage credentials. The particular methods used vary by engagement and scope rather than being universally prescribed by the criteria.
Access Restriction to Data and Information Assets
Controls that limit access to information based on classification and least-privilege principles. These are assessed against the Common Criteria and should not be conflated with ISO 27001 Annex A reference controls, which are selected separately via a Statement of Applicability.
Boundary and Scope of Assessment
CC6 controls are evaluated only within the system boundary and, for a Type II, over the defined review period established by scoping decisions. The report attests only to the controls and period covered.

Common questions

Answers to the questions practitioners most commonly ask about CC6.

Are CC6 controls the same as ISO 27001 Annex A access control requirements?
No. CC6 is part of the SOC 2 Common Criteria (Security) under the Trust Services Criteria, while ISO 27001 addresses access control through its ISMS requirements in clauses 4 through 10 and reference controls listed in Annex A, selected via a Statement of Applicability. Although the two frameworks cover overlapping subject matter, mapping between them is only partial, and satisfying CC6 in a SOC 2 examination does not automatically satisfy the corresponding ISO 27001 controls. The Trust Services Criteria and Annex A controls should not be conflated; they are structured differently and are assessed under different standards by different types of assessors.
Does passing a CC6 assessment mean an organization is protected against unauthorized access or breaches?
No. A SOC 2 report attests only to the controls included in scope and their design (in a Type I) or their design and operating effectiveness over the defined review period (in a Type II). It does not guarantee freedom from breaches or unauthorized access, and it does not extend to controls or periods outside those covered. CC6 findings describe how logical and physical access controls were designed and, in a Type II, whether they operated effectively during the examination period, not that access can never be compromised.
How does CC6 typically address both logical and physical access?
CC6 concerns logical and physical access controls together, so implementations typically cover both software-based access mechanisms, such as authentication, authorization, and access provisioning and deprovisioning, and physical safeguards over facilities and infrastructure. The specific controls in scope depend on the service being examined and the scoping decisions made for the engagement, so the balance between logical and physical measures varies across organizations and auditors.
What kinds of evidence are usually relevant for demonstrating CC6 controls in a Type II examination?
In most Type II engagements, evidence relates to how access controls operated across the review period rather than at a single point in time. Depending on scope and the auditor's approach, this can include records of access provisioning and removal, periodic access reviews, authentication configurations, and controls over physical entry. Because a Type II assesses operating effectiveness over time, evidence is typically expected to show consistent operation throughout the period rather than a one-time state, though the exact evidence depends on the engagement.
Where do the boundaries of CC6 fall when access is managed by third parties or shared responsibility applies?
The scope of CC6 is defined by the boundaries of the system under examination, which are set during scoping. Where access is managed partly by third parties or under a shared-responsibility model, the delineation of which controls fall within the examined organization's scope depends on those scoping decisions and the service being assessed. A SOC 2 report covers only the controls and period in scope, so responsibilities held by subservice organizations or customers may be treated differently depending on how the engagement is structured.
How should CC6 be approached when an organization also pursues ISO 27001 certification?
Organizations pursuing both frameworks can often leverage overlapping access control practices, but the two are assessed separately: SOC 2 is an attestation examination performed by a licensed CPA firm resulting in a report, while ISO 27001 is a certification issued by an accredited certification body against a management system standard covering only the defined ISMS scope. Mapping CC6 to ISO 27001 access-related controls is possible but partial, so evidence and control design may need to be tailored to each framework rather than assumed to transfer wholesale.

Common misconceptions

A clean SOC 2 report covering CC6 guarantees that an organization's access controls will prevent all breaches.
A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard. It attests only to the controls and, for a Type II, the review period covered, and does not guarantee freedom from breaches or unauthorized access outside that scope.
CC6 logical and physical access requirements are the same as ISO 27001's access control provisions, so satisfying one satisfies the other.
The Trust Services Criteria are distinct from ISO 27001 Annex A reference controls, which are selected via a Statement of Applicability informed by risk assessment. Mapping between the two frameworks is possible but partial, and meeting CC6 does not automatically satisfy ISO 27001 requirements.
A Type I and Type II examination assess CC6 access controls the same way.
A Type I assesses the suitability of the design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions.

Best practices

Define the system boundary and scope clearly before the examination so that both logical and physical access controls are assessed against the intended environment.
Maintain documented user provisioning and deprovisioning processes and retain evidence of their operation throughout the review period, particularly for a Type II engagement.
Enforce least-privilege access and periodically review user access rights against roles, documenting the review activity for the auditor.
Coordinate with the CPA firm early on how physical access to facilities and data centers within scope will be evidenced, since specific expectations vary by engagement.
Where the organization also pursues ISO 27001, map CC6 controls to the relevant ISMS and Annex A controls carefully, recognizing that the mapping is partial and does not create automatic equivalence.
Communicate to stakeholders that a SOC 2 report reflects controls over a defined period and scope rather than a certification or an ongoing guarantee of security.