Skip to main content
Category: Trust Services Criteria

Risk Assessment Criteria (CC3)

Also known as: CC3, CC3, Common Criteria Related to Risk Assessment, SOC 2 Risk Assessment Criteria
Simply put

CC3 is the group of SOC 2 Common Criteria that deals with how an organization identifies and manages risks to its systems. It generally expects a documented process for spotting potential threats, analyzing them, and deciding how to address them, including considering the possibility of fraud. Because CC3 is part of the Common Criteria, it applies in a SOC 2 examination regardless of which optional Trust Services categories are in scope.

Formal definition

CC3 comprises the Risk Assessment criteria within the SOC 2 Common Criteria (the Security category), evaluated as part of an AICPA SSAE 18 attestation examination. In most engagements, CC3 addresses specifying objectives with sufficient clarity to identify and assess related risks (commonly associated with CC3.1), identifying and analyzing risks across the entity (CC3.2), considering the potential for fraud in the risk assessment process (CC3.3), and identifying and assessing changes that could significantly affect the system of internal control (CC3.4). Practitioners typically expect a formal, documented, and repeatable process to identify, analyze, prioritize, and manage risk, with evidence of design (Type I) and, over a defined review period, operating effectiveness (Type II). CC3 reflects only the controls and period covered by the SOC 2 report and should not be conflated with ISO/IEC 27001 clause 6 risk assessment requirements or Annex A reference controls, though partial mapping between the frameworks is possible.

Why it matters

Risk assessment sits at the center of any credible security program because controls are only meaningful when they are aimed at the risks that actually threaten a system. CC3 formalizes this discipline within the SOC 2 Common Criteria, requiring an organization to demonstrate a documented, repeatable process for identifying threats, analyzing their significance, and deciding how to respond. Without a sound risk assessment, an organization may invest in controls that address the wrong problems while leaving material exposures unmanaged, which auditors and customers alike tend to view as a foundational weakness.

Because CC3 is part of the Common Criteria (the Security category), it applies in every SOC 2 examination regardless of which optional Trust Services categories, such as Availability or Confidentiality, are in scope. This makes it one of the criteria practitioners scrutinize closely: a gap here often cascades into deficiencies elsewhere, since the design of many other controls should trace back to identified risks. Notably, CC3 also requires organizations to explicitly consider the potential for fraud during the risk assessment process, extending the analysis beyond external threats to include internal misconduct and manipulation.

It is important to keep expectations calibrated. A SOC 2 report reflects only the controls and the period covered, so a favorable CC3 conclusion attests that a risk assessment process was suitably designed (Type I) and, over a defined review period, operating effectively (Type II), it does not guarantee that every risk was identified or that a breach cannot occur. CC3 should also not be conflated with ISO/IEC 27001 clause 6 risk assessment requirements or Annex A reference controls; while partial mapping between the frameworks is possible, satisfying CC3 does not automatically satisfy ISO 27001's ISMS requirements.

Who it's relevant to

Compliance and GRC Managers
CC3 is often where a SOC 2 program either holds together or unravels, since many other controls should trace back to identified risks. GRC managers are typically responsible for establishing and maintaining the documented, repeatable risk assessment process, including the fraud consideration and change-assessment components, and for producing the evidence auditors expect over the review period.
Security Engineers and Risk Analysts
Those who perform or support the risk assessment translate CC3's expectations into practice: identifying threats to systems, analyzing and prioritizing them, and reassessing risks as the environment changes. Their work generates the risk registers and analysis records that practitioners commonly review as evidence of design and, in a Type II engagement, operating effectiveness.
Auditors and Assessors
CPA firms conducting the SSAE 18 attestation evaluate whether the risk assessment controls are suitably designed and, for Type II, operating effectively over the defined period. Assessors focus on whether objectives are specified clearly enough to identify related risks, whether fraud is explicitly considered, and whether changes affecting internal control are captured, recognizing that specific controls and evidence vary by scope.
Executives and Service Organization Leadership
Leadership should understand that a favorable CC3 conclusion attests only to the controls and period covered and does not guarantee freedom from breaches. It also does not automatically satisfy ISO/IEC 27001 clause 6 risk assessment requirements, so organizations pursuing both frameworks should plan for partial rather than complete mapping.

Inside CC3

Objective Specification
The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. This provides the reference point against which risks are evaluated within the Security (Common Criteria) category of the Trust Services Criteria.
Risk Identification
The entity identifies risks to the achievement of its objectives across the entity and analyzes those risks as a basis for determining how they should be managed. Identification typically spans internal and external sources depending on the scope of the engagement.
Fraud Risk Consideration
The organization considers the potential for fraud when assessing risks to the achievement of objectives, including incentives, pressures, opportunities, and attitudes that may contribute to fraudulent activity.
Change Identification and Assessment
The entity identifies and assesses changes that could significantly affect the system of internal control, such as changes to the operating environment, technology, personnel, or business model.
Risk Analysis and Response
Identified risks are analyzed to estimate their significance and to inform decisions about how they will be managed, which supports the design and operating effectiveness of controls evaluated in a SOC 2 examination.

Common questions

Answers to the questions practitioners most commonly ask about CC3.

Does the CC3 series of the SOC 2 Common Criteria satisfy the risk assessment requirements of ISO 27001?
Not automatically. The CC3 criteria address risk identification and assessment within the SOC 2 Trust Services Criteria framework, while ISO 27001 sets out its own risk assessment and risk treatment requirements in clauses 4 through 10, informing control selection through the Statement of Applicability. The two can be partially mapped, since both call for a defined and repeatable risk process, but satisfying CC3 does not by itself demonstrate conformance to the ISO 27001 requirements, and vice versa. Each is evaluated by a different type of practitioner: a licensed CPA firm attesting under SSAE 18 for SOC 2, and an accredited certification body for ISO 27001.
Is meeting CC3 the same as producing an ISO 27001 Statement of Applicability?
No. CC3 concerns how an organization identifies, analyzes, and responds to risks relevant to the Trust Services Criteria in scope. The Statement of Applicability is an ISO 27001 artifact that documents which Annex A reference controls are applicable and justifies inclusions and exclusions based on the ISMS risk assessment. They serve different frameworks and are not interchangeable, though a well-run risk assessment process may inform both. The CC3 criteria do not map to Annex A controls, and the Trust Services Criteria should not be conflated with Annex A.
How is CC3 assessed differently in a SOC 2 Type I versus a Type II examination?
In a Type I examination, the auditor assesses whether the CC3 risk assessment controls are suitably designed as of a point in time. In a Type II examination, the auditor evaluates both the suitability of design and the operating effectiveness of those controls over a defined review period, the length of which is set through scoping decisions rather than fixed by the standard. In practice this means a Type II typically expects evidence that risk assessment activities were performed consistently throughout the period, not just documented at a single moment.
What kinds of evidence are typically requested to support CC3 controls?
This varies by auditor and scope, but organizations commonly provide documentation of their risk assessment methodology, records of risk identification and analysis activities, evidence that risks were evaluated and responses determined, and materials showing that assessments occur on a defined cadence or in response to change. For a Type II examination, the evidence typically needs to demonstrate the process operated across the review period. The specific artifacts requested depend on the engagement and the practitioner's judgment.
How often should risk assessment activities be performed to align with CC3 expectations?
The appropriate frequency depends on the organization's environment, scope, and the auditor's expectations rather than a universally mandated interval. In most engagements, organizations perform risk assessments on a recurring basis and also upon significant changes to the business, technology, or threat landscape. Because a Type II examination looks at operating effectiveness over the review period, a defined and consistently followed cadence is generally more defensible than an ad hoc approach.
Can the same risk assessment process support both CC3 and an ISO 27001 ISMS?
In many organizations a single risk assessment program can inform both, since both frameworks call for a structured approach to identifying and treating risk. However, the outputs must still be tailored to each framework's requirements: CC3 evaluation against the Trust Services Criteria in scope, and ISO 27001 against its clause 4 through 10 requirements and the Statement of Applicability. Reusing a common process can reduce duplicated effort, but it does not merge the two assessments or make one outcome substitute for the other.

Common misconceptions

CC3 risk assessment criteria are the same as the risk assessment requirements in ISO 27001.
CC3 sits within the SOC 2 Trust Services Criteria (the Security/Common Criteria) evaluated in an AICPA SSAE 18 attestation examination, whereas ISO 27001 addresses risk assessment through its clauses 4 through 10 ISMS requirements and its Statement of Applicability. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other.
Meeting CC3 means the auditor has confirmed the organization identified every relevant risk.
A SOC 2 report attests only to the controls and the period covered by the engagement. It reflects the auditor's evaluation of the risk assessment process within the defined scope and does not guarantee that all risks were identified or that the organization is free from breaches.
A single prescribed risk assessment methodology is mandatory to satisfy CC3.
The criteria describe outcomes such as specifying objectives, identifying and analyzing risks, considering fraud, and assessing change, but the specific methodology typically depends on scope and the auditor's judgment rather than a universally mandated approach.

Best practices

Document objectives clearly before assessing risks, so that identified risks can be traced back to the objectives they threaten as CC3 expects.
Establish a repeatable, documented risk identification and analysis process rather than relying on ad hoc reviews, since a Type II examination assesses operating effectiveness over the review period.
Explicitly incorporate fraud risk considerations, including incentives, opportunities, and pressures, into the risk assessment rather than treating them only as an afterthought.
Define triggers and procedures for identifying and assessing significant changes to the environment, technology, personnel, and business model that could affect internal control.
Retain evidence of risk assessment activities across the review period to support the auditor's evaluation, keeping in mind the report covers only the controls and period in scope.
Where the organization also pursues ISO 27001, coordinate the CC3 process with the ISMS risk assessment while treating any mapping as partial rather than assuming equivalence.