Risk Assessment Criteria (CC3)
CC3 is the group of SOC 2 Common Criteria that deals with how an organization identifies and manages risks to its systems. It generally expects a documented process for spotting potential threats, analyzing them, and deciding how to address them, including considering the possibility of fraud. Because CC3 is part of the Common Criteria, it applies in a SOC 2 examination regardless of which optional Trust Services categories are in scope.
CC3 comprises the Risk Assessment criteria within the SOC 2 Common Criteria (the Security category), evaluated as part of an AICPA SSAE 18 attestation examination. In most engagements, CC3 addresses specifying objectives with sufficient clarity to identify and assess related risks (commonly associated with CC3.1), identifying and analyzing risks across the entity (CC3.2), considering the potential for fraud in the risk assessment process (CC3.3), and identifying and assessing changes that could significantly affect the system of internal control (CC3.4). Practitioners typically expect a formal, documented, and repeatable process to identify, analyze, prioritize, and manage risk, with evidence of design (Type I) and, over a defined review period, operating effectiveness (Type II). CC3 reflects only the controls and period covered by the SOC 2 report and should not be conflated with ISO/IEC 27001 clause 6 risk assessment requirements or Annex A reference controls, though partial mapping between the frameworks is possible.
Why it matters
Risk assessment sits at the center of any credible security program because controls are only meaningful when they are aimed at the risks that actually threaten a system. CC3 formalizes this discipline within the SOC 2 Common Criteria, requiring an organization to demonstrate a documented, repeatable process for identifying threats, analyzing their significance, and deciding how to respond. Without a sound risk assessment, an organization may invest in controls that address the wrong problems while leaving material exposures unmanaged, which auditors and customers alike tend to view as a foundational weakness.
Because CC3 is part of the Common Criteria (the Security category), it applies in every SOC 2 examination regardless of which optional Trust Services categories, such as Availability or Confidentiality, are in scope. This makes it one of the criteria practitioners scrutinize closely: a gap here often cascades into deficiencies elsewhere, since the design of many other controls should trace back to identified risks. Notably, CC3 also requires organizations to explicitly consider the potential for fraud during the risk assessment process, extending the analysis beyond external threats to include internal misconduct and manipulation.
It is important to keep expectations calibrated. A SOC 2 report reflects only the controls and the period covered, so a favorable CC3 conclusion attests that a risk assessment process was suitably designed (Type I) and, over a defined review period, operating effectively (Type II), it does not guarantee that every risk was identified or that a breach cannot occur. CC3 should also not be conflated with ISO/IEC 27001 clause 6 risk assessment requirements or Annex A reference controls; while partial mapping between the frameworks is possible, satisfying CC3 does not automatically satisfy ISO 27001's ISMS requirements.
Who it's relevant to
Inside CC3
Common questions
Answers to the questions practitioners most commonly ask about CC3.