Skip to main content
Category: Trust Services Criteria

Risk Mitigation Criteria (CC9)

Also known as: CC9, CC9, Risk Mitigation, CC9.0, SOC 2 Risk Mitigation Criteria
Simply put

CC9 is one of the Common Criteria used in a SOC 2 examination, and it focuses on how an organization plans ahead to reduce the impact of security risks and business disruptions. In practice, it looks at whether the organization has strategies ready to address problems before they cause harm, such as documented plans and backup arrangements. It is one part of the broader Security category that a CPA firm evaluates when reporting on an organization's controls.

Formal definition

CC9 (Risk Mitigation) is a Common Criteria category within the SOC 2 Trust Services Criteria that addresses an organization's strategies for mitigating risks arising from potential business disruptions. Based on the evidence, CC9 is typically organized into sub-criteria, with CC9.1 addressing the identification, selection, and development of risk mitigation activities. These activities commonly include developing planned policies, procedures, and communications, and selecting alternative or alternate processing arrangements, depending on the organization's scope and risk profile. As part of the Security Common Criteria, CC9 is evaluated during a SOC 2 attestation examination; the resulting report attests only to the controls and period covered and does not, on its own, guarantee freedom from disruption or breach. CC9 is distinct from the ISO/IEC 27001 ISMS requirements and Annex A controls, and satisfying CC9 does not by itself demonstrate conformity with ISO 27001.

Why it matters

Risk mitigation sits at the point where an organization moves from identifying what could go wrong to actually preparing for it. CC9 matters because a SOC 2 examination is not only interested in whether an organization can respond to security issues as they occur, but whether it has planned strategies kept on hand to reduce the impact of disruptions before they arise. Without documented risk mitigation activities, an organization may have strong day-to-day controls yet remain exposed when a significant disruption tests its ability to continue operating.

For customers and stakeholders relying on a SOC 2 report, CC9 provides evidence that a service organization has thought ahead about business disruption and has arrangements such as planned policies, procedures, communications, and alternative processing options in place. This forward-looking posture is what distinguishes mitigation from reactive incident handling. It signals that the organization treats resilience as a deliberate design choice rather than an afterthought.

It is important to keep the boundaries of this assurance in view. A SOC 2 report attests only to the controls and the period covered by the examination, and CC9 on its own does not guarantee that an organization will be free from disruption or breach. The presence of risk mitigation criteria demonstrates preparedness, not immunity, and readers of a report should evaluate CC9 alongside the other Common Criteria and any optional Trust Services categories in scope.

Who it's relevant to

Compliance and GRC managers
Those coordinating a SOC 2 examination need to ensure that risk mitigation activities under CC9 are documented and demonstrable. This typically involves confirming that planned policies, procedures, and communications exist, and that arrangements such as alternate processing sites are considered where appropriate to the organization's scope and risk profile.
Security engineers and operations teams
Teams responsible for resilience and continuity translate CC9 into practical measures, such as maintaining backup and alternative processing arrangements. Their work provides much of the underlying evidence an auditor examines when evaluating whether risk mitigation strategies are in place and, in a Type II engagement, operating over the review period.
Auditors performing the examination
CPA firms conducting a SOC 2 examination assess CC9 as part of the Security Common Criteria, evaluating the suitability of design and, for Type II, the operating effectiveness of risk mitigation controls over the defined period. They should remain clear that the resulting report attests only to the controls and period covered.
Customers and stakeholders reading the report
Those relying on a SOC 2 report can look to CC9 for evidence that a service organization has planned strategies to reduce the impact of business disruptions. They should interpret this as evidence of preparedness within a defined scope and period, not as a guarantee against future disruption or breach.

Inside CC9

CC9.1 - Risk Mitigation Activities
Addresses how an organization identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions. This typically includes activities that reduce the likelihood or impact of identified risks to a level consistent with the entity's risk tolerance.
CC9.2 - Vendor and Business Partner Risk Management
Focuses on assessing and managing risks associated with vendors, third parties, and business partners. This generally involves due diligence, defining responsibilities in agreements, and ongoing monitoring of the parties that could affect the entity's ability to meet its commitments.
Position Within the Common Criteria
CC9 is one of the criteria within the Security category (the Common Criteria) of the AICPA Trust Services Criteria, which is the only required category in a SOC 2 examination. The remaining categories, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and included based on scoping decisions.
Relationship to Risk Assessment
CC9 builds on the risk identification and assessment work reflected elsewhere in the Common Criteria, applying selected mitigation activities to the risks the entity has identified. The specific controls implemented depend on scope, the auditor's evaluation, and the entity's risk profile.

Common questions

Answers to the questions practitioners most commonly ask about CC9.

Does CC9 require me to eliminate all identified risks before I can pass a SOC 2 examination?
No. CC9 focuses on risk mitigation, not risk elimination. The criteria address how an organization identifies, selects, and develops risk mitigation activities, including for risks arising from business disruptions and from the use of vendors and business partners. A SOC 2 examination assesses whether the controls supporting these criteria are suitably designed (Type I) and, in a Type II, operating effectively over the review period. It does not certify that all risk has been removed, and a SOC 2 report attests only to the controls and period covered rather than guaranteeing freedom from future incidents.
Is CC9 the same as an ISO 27001 risk assessment, so satisfying one covers the other?
Not directly. CC9 is part of the Trust Services Criteria (the Common Criteria) evaluated in a SOC 2 attestation examination, whereas ISO 27001 addresses risk through its ISMS requirements in clauses 4 through 10, with reference controls selected via a Statement of Applicability. Mapping between the two is possible but partial. Concepts overlap, both involve identifying and treating risk, but the structures, evidence expectations, and outcomes differ. Satisfying CC9 in a SOC 2 engagement does not automatically satisfy ISO 27001's risk treatment requirements, and vice versa.
How does CC9 typically relate to the risk assessment criteria in CC3?
In most engagements CC9 builds on the risk identification and assessment activities addressed under CC3. CC3 typically concerns how the organization specifies objectives and identifies and analyzes risks to achieving them, while CC9 concerns the selection and development of activities to mitigate those risks, including risks from business disruption and third parties. Auditors often expect to see a coherent flow from how risks are identified to how they are mitigated, though the specific evidence depends on scope and the service organization's design.
What kinds of evidence do auditors commonly look for when evaluating CC9?
Evidence varies by auditor and scope, but organizations frequently provide documentation of their risk mitigation approach, such as business continuity and disaster recovery planning, insurance or other risk transfer arrangements where applicable, and vendor risk management materials. For a Type II, the auditor typically also looks for evidence that these activities operated over the review period. Because CC9 addresses vendor and business partner risk, records of due diligence and ongoing monitoring of third parties are often relevant, depending on the environment.
How should vendor and business partner risk be handled to support CC9?
CC9 typically encompasses the identification and mitigation of risks associated with vendors and business partners, so organizations often maintain a process for assessing third parties during onboarding and monitoring them over time. Practices commonly include reviewing vendors' own SOC 2 reports or other assurance where available, though the depth of review generally depends on the criticality of the vendor and the scope of the engagement. The specific controls that satisfy this expectation are not fixed and should be designed to fit the organization's risk profile.
Does CC9 apply if we haven't selected the Availability category in our scope?
Yes. CC9 is part of the Common Criteria, which map to the Security category that is required in every SOC 2 examination. The optional categories, Availability, Processing Integrity, Confidentiality, and Privacy, are selected based on scope and add their own criteria, but they do not determine whether the Common Criteria apply. CC9's focus on risk mitigation, including business disruption and vendor risk, is in scope regardless of whether Availability or other optional categories are included.

Common misconceptions

Meeting CC9 in a SOC 2 report means the organization is certified as having mitigated all its risks.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report, not a certification. The report attests only to the controls and period covered and does not guarantee freedom from breaches or that all risks have been eliminated.
CC9's vendor risk management requirements are equivalent to the supplier-related controls in ISO 27001 Annex A.
The Trust Services Criteria and ISO 27001 Annex A reference controls are distinct frameworks. Mapping between them is possible but partial, and satisfying CC9 does not automatically satisfy the corresponding ISO 27001 requirements, which are selected via a Statement of Applicability informed by risk assessment.
CC9 prescribes a specific, mandatory set of risk mitigation controls every organization must implement.
The criteria describe objectives rather than a fixed checklist. In most engagements the specific mitigation activities depend on the entity's scope, risk tolerance, and the auditor's evaluation, so implementations vary between organizations.

Best practices

Document how identified risks connect to selected mitigation activities so that the linkage between risk assessment and CC9 controls is clear to the examining CPA firm.
Establish a vendor due diligence and ongoing monitoring process that defines responsibilities in agreements and evaluates third parties whose services could affect your commitments.
Align mitigation activities to your documented risk tolerance rather than aiming for absolute risk elimination, and revisit them as the risk profile changes.
Maintain evidence of the operating effectiveness of mitigation activities over time, which is typically necessary to support a SOC 2 Type II examination covering a defined review period.
Clarify the boundaries of what CC9 covers within your SOC 2 scope, and avoid overstating that meeting it addresses risks outside the controls and period examined.
If pursuing both frameworks, map CC9 activities to relevant ISO 27001 requirements deliberately, treating any overlap as partial rather than assuming full equivalence.