Security TSC Overview
All 33 SOC 2 Security Trust Services Criteria from CC1 to CC9. Required for every SOC 2 engagement. Plain-English explanations and evidence tips.
CC1 Control Environment
COSO Principles and Commitment to Integrity
Plain English
Your company has a documented Code of Conduct, ethics policy, and clear expectations for employee behavior. This applies to executives and all employees.
View official AICPA language
The entity demonstrates a commitment to integrity and ethical values.
What auditors look for
Code of Conduct document, employee onboarding acknowledgement records, ethics training completion records
Board Independence and Oversight
Plain English
Your board (or equivalent governance body) actively oversees your security and compliance program, not just financial performance. Board meeting minutes should show security was discussed.
View official AICPA language
The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
What auditors look for
Board meeting minutes referencing security/compliance, risk committee charter, board composition documentation
Organizational Structure and Accountability
Plain English
Your org chart, reporting lines, and who is responsible for security are clearly documented. The security team or security owner has explicit authority.
View official AICPA language
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
What auditors look for
Org chart, job descriptions for security roles, RACI matrix for security responsibilities
Commitment to Competence
Plain English
You hire qualified security personnel, provide security training, and have a process to assess whether employees have the skills needed for their security-related roles.
View official AICPA language
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
What auditors look for
Security training completion records, job descriptions requiring security qualifications, performance review templates
Accountability for Internal Control
Plain English
Employees know they are responsible for following security policies. Violations have consequences. Security responsibilities appear in performance reviews.
View official AICPA language
The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
What auditors look for
Disciplinary policy, security responsibilities in performance review templates, acknowledgement of security policies
CC2 Communication & Information
Information to Support Internal Control
Plain English
You have an Information Security Policy (ISP) that is documented, current, and distributed to all employees. Security decisions are based on relevant data.
View official AICPA language
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
What auditors look for
Information Security Policy document (dated within last 12 months), distribution list or acknowledgement records
Internal Communication of Control Information
Plain English
Security policies, responsibilities, and objectives are actively communicated to all relevant employees — not just posted in a wiki nobody reads.
View official AICPA language
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
What auditors look for
Security policy communication emails/Slack announcements, all-hands security training records, policy wiki page view analytics
External Communication
Plain English
You communicate your security commitments to customers and third parties — through your Trust Portal, DPA, or vendor agreements. You also have a process for receiving security reports from external parties.
View official AICPA language
The entity communicates with external parties regarding matters affecting the functioning of internal control.
What auditors look for
Privacy policy, data processing agreements (DPAs), security page on website, vulnerability disclosure policy
CC3 Risk Assessment
Risk Assessment Objectives
Plain English
You have defined your security objectives and do a formal risk assessment to identify what could prevent you from achieving them. This isn't just a list — it must be documented.
View official AICPA language
The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
What auditors look for
Formal risk assessment document, risk register with likelihood and impact ratings, risk assessment meeting minutes
Risk Identification and Analysis
Plain English
You systematically identify, analyze, and prioritize security risks. You consider both the likelihood of a risk occurring and the impact if it does.
View official AICPA language
The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
What auditors look for
Risk register showing identified risks, likelihood/impact ratings, and assigned owners. Evidence of annual (or more frequent) reviews.
Fraud Risk Assessment
Plain English
Your risk assessment specifically considers fraud risks — both internal (employee fraud) and external (customer fraud, social engineering). This must be documented.
View official AICPA language
The entity considers the potential for fraud in assessing risks to the achievement of objectives.
What auditors look for
Risk register entries specifically labeled as fraud risks, fraud risk assessment section in your annual risk review
Change Management Risk
Plain English
When significant changes occur (new product features, new vendors, reorg, new tech stack), you re-assess the risks those changes introduce to your control environment.
View official AICPA language
The entity identifies and assesses changes that could significantly impact the system of internal control.
What auditors look for
Change risk assessment process documentation, examples of risk re-assessments triggered by significant changes
CC4 Monitoring Activities
Monitoring Control Performance
Plain English
You have a process to continuously or periodically verify that your security controls are working. This could be internal audits, quarterly reviews, or automated monitoring.
View official AICPA language
The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
What auditors look for
Internal audit reports, quarterly security review meeting notes, automated control monitoring dashboards with screenshots
Evaluating and Communicating Deficiencies
Plain English
When you find a control deficiency — through an audit, incident, or monitoring — you have a formal process to escalate it, assign ownership, and track remediation.
View official AICPA language
The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.
What auditors look for
Deficiency tracking records, incident tickets showing escalation and remediation, communication of findings to leadership
CC5 Control Activities
Controls Over Technology
Plain English
You have selected appropriate technical controls (encryption, MFA, logging, etc.) that address the risks identified in your risk assessment. Controls are commensurate with the risk level.
View official AICPA language
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
What auditors look for
Control matrix showing risk-to-control mapping, technical control configuration screenshots (MFA enabled, encryption settings)
Controls Over Technology Infrastructure
Plain English
Your technology infrastructure has controls in place: secure configuration baselines, patching policies, and hardening standards for servers, containers, and cloud environments.
View official AICPA language
The entity also selects and develops general control activities over technology to support the achievement of objectives.
What auditors look for
CIS Benchmark compliance reports, cloud security posture reports (AWS Security Hub, GCP SCC), patch management records
Policy Deployment
Plain English
Security policies are deployed as executable procedures — not just documents. Employees know what to do, not just what the policy says.
View official AICPA language
The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.
What auditors look for
Procedure documents (runbooks, SOPs), training records showing employees were trained on procedures, evidence procedures are followed
CC6 Logical & Physical Access Controls
Logical Access Security Measures
Plain English
You have implemented technical access controls (IAM, RBAC, MFA, SSO) that prevent unauthorized access to production systems and customer data. Access requires authentication.
View official AICPA language
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.
What auditors look for
IAM configuration screenshots, MFA enrollment reports (must be 100%), SSO configuration, network firewall rules
New Access Provisioning
Plain English
When a new employee or contractor needs access, there is a formal process: request submitted, manager approved, access granted only after approval. No ad-hoc access grants.
View official AICPA language
Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity.
What auditors look for
Access request tickets (Jira/ServiceNow) showing requester, approver, and date. Onboarding checklist showing access provisioning steps.
Access Removal on Termination
Plain English
When an employee leaves, their access is revoked within a defined timeframe (typically 24 hours for terminations, immediate for involuntary). This must be consistently applied.
View official AICPA language
The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes.
What auditors look for
Offboarding checklist with access revocation steps, IAM audit logs showing account deactivation, HR termination records vs access logs
Physical Access Controls
Plain English
Physical access to offices, data centers, or server rooms is restricted and logged. For cloud-only companies, this means your cloud provider's data center controls (AWS/GCP/Azure SOC reports).
View official AICPA language
The entity restricts physical access to facilities and protected information assets to authorized individuals.
What auditors look for
AWS/GCP/Azure SOC 2 reports (sub-service organization), office access logs, security camera footage policy, visitor log
Disposal of Assets
Plain English
When disposing of hardware (laptops, hard drives), you have a documented process to wipe data before disposal. For cloud, this means terminating instances and ensuring data deletion.
View official AICPA language
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required by the entity's commitments and system requirements.
What auditors look for
Asset disposal records, data destruction certificates, MDM remote wipe logs for decommissioned devices
Remote Access
Plain English
Remote access to your production environment requires VPN and/or strong authentication (MFA + SSO). All remote sessions are logged. Malware protection is enforced on company endpoints.
View official AICPA language
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.
What auditors look for
VPN configuration and user list, MDM enrollment showing all endpoints have EDR/antivirus, MFA report for remote access users
Transmission and Movement of Data
Plain English
Data is encrypted in transit (TLS 1.2+ on all endpoints). Sensitive data is not transmitted via unencrypted channels (email, Slack). Your API enforces HTTPS only.
View official AICPA language
The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission.
What auditors look for
TLS certificate reports, API gateway configuration showing HTTPS enforcement, DLP policy documentation
Anti-Malware Controls
Plain English
All employee endpoints have EDR/antivirus deployed and managed centrally. Your MDM enforces this. You have alerts for malware detection and a process to respond.
View official AICPA language
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.
What auditors look for
MDM dashboard showing endpoint coverage, EDR coverage report, malware detection alert logs from the review period
CC7 System Operations
Vulnerability Detection
Plain English
You run regular vulnerability scans on your infrastructure and application. Findings are triaged, tracked, and remediated within defined SLAs (e.g., critical = 24h, high = 7 days).
View official AICPA language
To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations or the environment.
What auditors look for
Quarterly vulnerability scan reports, vulnerability tracker showing remediation timelines, CVSS severity-based SLA policy
Security Incident Response
Plain English
You have a Security Incident Response Plan (SIRP) and actually used it (or tested it) during the audit period. Security events are logged, alerts are configured, and there is an on-call rotation.
View official AICPA language
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives.
What auditors look for
Security Incident Response Plan (dated), incident response tabletop exercise records, SIEM alert configuration, on-call schedule
Incident Response Execution
Plain English
When a security event occurs, you follow your SIRP: classify the event, contain it, investigate, remediate, and document a post-incident review. Stakeholders are notified appropriately.
View official AICPA language
The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives.
What auditors look for
Post-incident review reports, incident tickets showing classification, containment actions, and root cause analysis
Incident Response — Recovery
Plain English
After a security incident, you restore affected systems to their prior state, verify data integrity, and communicate with affected parties within contractually or legally required timeframes.
View official AICPA language
The entity responds to identified security incidents by executing a defined incident response program.
What auditors look for
Recovery runbooks, backup restoration test records, customer notification templates and logs, DR test results
Disclosure to Affected Parties
Plain English
You have a documented process for notifying affected customers and regulatory bodies after a security incident. Notification timelines comply with GDPR, CCPA, or contract requirements.
View official AICPA language
The entity identifies, develops, and implements activities to recover from identified security incidents.
What auditors look for
Breach notification policy, example notification templates, documented stakeholder communication list
CC8 Change Management
Change Management Process
Plain English
Every production code change goes through a formal change management process: code review by a second person, automated testing, staging deployment, and documented approval before production release.
View official AICPA language
The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures.
What auditors look for
GitHub/GitLab PR history showing required reviewers, CI/CD pipeline logs, staging environment configuration, deployment approval records
CC9 Risk Mitigation
Risk Mitigation
Plain English
You have a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that address how you maintain or restore services after a major disruption.
View official AICPA language
The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
What auditors look for
Business Continuity Plan document, DR runbooks, annual DR test results (RTO/RPO verification), backup configuration
Vendor & Third-Party Risk Management
Plain English
You maintain a vendor inventory, assess each vendor's security posture before and during the relationship, and have contractual protections (DPAs, security requirements) in vendor agreements.
View official AICPA language
The entity assesses and manages risks associated with vendors and business partners.
What auditors look for
Vendor inventory list, security questionnaires or SOC 2 reports collected from critical vendors, DPAs signed with each vendor
Track all 33 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today