Risk Mitigation Criteria (CC9)
CC9 is one of the Common Criteria used in a SOC 2 examination, and it focuses on how an organization plans ahead to reduce the impact of security risks and business disruptions. In practice, it looks at whether the organization has strategies ready to address problems before they cause harm, such as documented plans and backup arrangements. It is one part of the broader Security category that a CPA firm evaluates when reporting on an organization's controls.
CC9 (Risk Mitigation) is a Common Criteria category within the SOC 2 Trust Services Criteria that addresses an organization's strategies for mitigating risks arising from potential business disruptions. Based on the evidence, CC9 is typically organized into sub-criteria, with CC9.1 addressing the identification, selection, and development of risk mitigation activities. These activities commonly include developing planned policies, procedures, and communications, and selecting alternative or alternate processing arrangements, depending on the organization's scope and risk profile. As part of the Security Common Criteria, CC9 is evaluated during a SOC 2 attestation examination; the resulting report attests only to the controls and period covered and does not, on its own, guarantee freedom from disruption or breach. CC9 is distinct from the ISO/IEC 27001 ISMS requirements and Annex A controls, and satisfying CC9 does not by itself demonstrate conformity with ISO 27001.
Why it matters
Risk mitigation sits at the point where an organization moves from identifying what could go wrong to actually preparing for it. CC9 matters because a SOC 2 examination is not only interested in whether an organization can respond to security issues as they occur, but whether it has planned strategies kept on hand to reduce the impact of disruptions before they arise. Without documented risk mitigation activities, an organization may have strong day-to-day controls yet remain exposed when a significant disruption tests its ability to continue operating.
For customers and stakeholders relying on a SOC 2 report, CC9 provides evidence that a service organization has thought ahead about business disruption and has arrangements such as planned policies, procedures, communications, and alternative processing options in place. This forward-looking posture is what distinguishes mitigation from reactive incident handling. It signals that the organization treats resilience as a deliberate design choice rather than an afterthought.
It is important to keep the boundaries of this assurance in view. A SOC 2 report attests only to the controls and the period covered by the examination, and CC9 on its own does not guarantee that an organization will be free from disruption or breach. The presence of risk mitigation criteria demonstrates preparedness, not immunity, and readers of a report should evaluate CC9 alongside the other Common Criteria and any optional Trust Services categories in scope.
Who it's relevant to
Inside CC9
Common questions
Answers to the questions practitioners most commonly ask about CC9.