TSC Security Required

Security TSC Overview

All 33 SOC 2 Security Trust Services Criteria from CC1 to CC9. Required for every SOC 2 engagement. Plain-English explanations and evidence tips.

33 Controls
8 Critical
12 High

CC1 Control Environment

CC1.1 medium

COSO Principles and Commitment to Integrity

Your company has a documented Code of Conduct, ethics policy, and clear expectations for employee behavior. This applies to executives and all employees.

View official AICPA language

The entity demonstrates a commitment to integrity and ethical values.

What auditors look for

Code of Conduct document, employee onboarding acknowledgement records, ethics training completion records

CC1.2 medium

Board Independence and Oversight

Your board (or equivalent governance body) actively oversees your security and compliance program, not just financial performance. Board meeting minutes should show security was discussed.

View official AICPA language

The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.

What auditors look for

Board meeting minutes referencing security/compliance, risk committee charter, board composition documentation

CC1.3 low

Organizational Structure and Accountability

Your org chart, reporting lines, and who is responsible for security are clearly documented. The security team or security owner has explicit authority.

View official AICPA language

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.

What auditors look for

Org chart, job descriptions for security roles, RACI matrix for security responsibilities

CC1.4 low

Commitment to Competence

You hire qualified security personnel, provide security training, and have a process to assess whether employees have the skills needed for their security-related roles.

View official AICPA language

The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

What auditors look for

Security training completion records, job descriptions requiring security qualifications, performance review templates

CC1.5 medium

Accountability for Internal Control

Employees know they are responsible for following security policies. Violations have consequences. Security responsibilities appear in performance reviews.

View official AICPA language

The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.

What auditors look for

Disciplinary policy, security responsibilities in performance review templates, acknowledgement of security policies

CC2 Communication & Information

CC2.1 medium

Information to Support Internal Control

You have an Information Security Policy (ISP) that is documented, current, and distributed to all employees. Security decisions are based on relevant data.

View official AICPA language

The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

What auditors look for

Information Security Policy document (dated within last 12 months), distribution list or acknowledgement records

CC2.2 low

Internal Communication of Control Information

Security policies, responsibilities, and objectives are actively communicated to all relevant employees — not just posted in a wiki nobody reads.

View official AICPA language

The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.

What auditors look for

Security policy communication emails/Slack announcements, all-hands security training records, policy wiki page view analytics

CC2.3 medium

External Communication

You communicate your security commitments to customers and third parties — through your Trust Portal, DPA, or vendor agreements. You also have a process for receiving security reports from external parties.

View official AICPA language

The entity communicates with external parties regarding matters affecting the functioning of internal control.

What auditors look for

Privacy policy, data processing agreements (DPAs), security page on website, vulnerability disclosure policy

CC3 Risk Assessment

CC3.1 high

Risk Assessment Objectives

You have defined your security objectives and do a formal risk assessment to identify what could prevent you from achieving them. This isn't just a list — it must be documented.

View official AICPA language

The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.

What auditors look for

Formal risk assessment document, risk register with likelihood and impact ratings, risk assessment meeting minutes

CC3.2 high

Risk Identification and Analysis

You systematically identify, analyze, and prioritize security risks. You consider both the likelihood of a risk occurring and the impact if it does.

View official AICPA language

The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.

What auditors look for

Risk register showing identified risks, likelihood/impact ratings, and assigned owners. Evidence of annual (or more frequent) reviews.

CC3.3 medium

Fraud Risk Assessment

Your risk assessment specifically considers fraud risks — both internal (employee fraud) and external (customer fraud, social engineering). This must be documented.

View official AICPA language

The entity considers the potential for fraud in assessing risks to the achievement of objectives.

What auditors look for

Risk register entries specifically labeled as fraud risks, fraud risk assessment section in your annual risk review

CC3.4 medium

Change Management Risk

When significant changes occur (new product features, new vendors, reorg, new tech stack), you re-assess the risks those changes introduce to your control environment.

View official AICPA language

The entity identifies and assesses changes that could significantly impact the system of internal control.

What auditors look for

Change risk assessment process documentation, examples of risk re-assessments triggered by significant changes

CC4 Monitoring Activities

CC4.1 high

Monitoring Control Performance

You have a process to continuously or periodically verify that your security controls are working. This could be internal audits, quarterly reviews, or automated monitoring.

View official AICPA language

The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

What auditors look for

Internal audit reports, quarterly security review meeting notes, automated control monitoring dashboards with screenshots

CC4.2 high

Evaluating and Communicating Deficiencies

When you find a control deficiency — through an audit, incident, or monitoring — you have a formal process to escalate it, assign ownership, and track remediation.

View official AICPA language

The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.

What auditors look for

Deficiency tracking records, incident tickets showing escalation and remediation, communication of findings to leadership

CC5 Control Activities

CC5.1 high

Controls Over Technology

You have selected appropriate technical controls (encryption, MFA, logging, etc.) that address the risks identified in your risk assessment. Controls are commensurate with the risk level.

View official AICPA language

The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

What auditors look for

Control matrix showing risk-to-control mapping, technical control configuration screenshots (MFA enabled, encryption settings)

CC5.2 high

Controls Over Technology Infrastructure

Your technology infrastructure has controls in place: secure configuration baselines, patching policies, and hardening standards for servers, containers, and cloud environments.

View official AICPA language

The entity also selects and develops general control activities over technology to support the achievement of objectives.

What auditors look for

CIS Benchmark compliance reports, cloud security posture reports (AWS Security Hub, GCP SCC), patch management records

CC5.3 medium

Policy Deployment

Security policies are deployed as executable procedures — not just documents. Employees know what to do, not just what the policy says.

View official AICPA language

The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.

What auditors look for

Procedure documents (runbooks, SOPs), training records showing employees were trained on procedures, evidence procedures are followed

CC6 Logical & Physical Access Controls

CC6.1 critical

Logical Access Security Measures

You have implemented technical access controls (IAM, RBAC, MFA, SSO) that prevent unauthorized access to production systems and customer data. Access requires authentication.

View official AICPA language

The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.

What auditors look for

IAM configuration screenshots, MFA enrollment reports (must be 100%), SSO configuration, network firewall rules

CC6.2 critical

New Access Provisioning

When a new employee or contractor needs access, there is a formal process: request submitted, manager approved, access granted only after approval. No ad-hoc access grants.

View official AICPA language

Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity.

What auditors look for

Access request tickets (Jira/ServiceNow) showing requester, approver, and date. Onboarding checklist showing access provisioning steps.

CC6.3 critical

Access Removal on Termination

When an employee leaves, their access is revoked within a defined timeframe (typically 24 hours for terminations, immediate for involuntary). This must be consistently applied.

View official AICPA language

The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes.

What auditors look for

Offboarding checklist with access revocation steps, IAM audit logs showing account deactivation, HR termination records vs access logs

CC6.4 medium

Physical Access Controls

Physical access to offices, data centers, or server rooms is restricted and logged. For cloud-only companies, this means your cloud provider's data center controls (AWS/GCP/Azure SOC reports).

View official AICPA language

The entity restricts physical access to facilities and protected information assets to authorized individuals.

What auditors look for

AWS/GCP/Azure SOC 2 reports (sub-service organization), office access logs, security camera footage policy, visitor log

CC6.5 medium

Disposal of Assets

When disposing of hardware (laptops, hard drives), you have a documented process to wipe data before disposal. For cloud, this means terminating instances and ensuring data deletion.

View official AICPA language

The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required by the entity's commitments and system requirements.

What auditors look for

Asset disposal records, data destruction certificates, MDM remote wipe logs for decommissioned devices

CC6.6 high

Remote Access

Remote access to your production environment requires VPN and/or strong authentication (MFA + SSO). All remote sessions are logged. Malware protection is enforced on company endpoints.

View official AICPA language

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.

What auditors look for

VPN configuration and user list, MDM enrollment showing all endpoints have EDR/antivirus, MFA report for remote access users

CC6.7 high

Transmission and Movement of Data

Data is encrypted in transit (TLS 1.2+ on all endpoints). Sensitive data is not transmitted via unencrypted channels (email, Slack). Your API enforces HTTPS only.

View official AICPA language

The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission.

What auditors look for

TLS certificate reports, API gateway configuration showing HTTPS enforcement, DLP policy documentation

CC6.8 high

Anti-Malware Controls

All employee endpoints have EDR/antivirus deployed and managed centrally. Your MDM enforces this. You have alerts for malware detection and a process to respond.

View official AICPA language

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.

What auditors look for

MDM dashboard showing endpoint coverage, EDR coverage report, malware detection alert logs from the review period

CC7 System Operations

CC7.1 critical

Vulnerability Detection

You run regular vulnerability scans on your infrastructure and application. Findings are triaged, tracked, and remediated within defined SLAs (e.g., critical = 24h, high = 7 days).

View official AICPA language

To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations or the environment.

What auditors look for

Quarterly vulnerability scan reports, vulnerability tracker showing remediation timelines, CVSS severity-based SLA policy

CC7.2 critical

Security Incident Response

You have a Security Incident Response Plan (SIRP) and actually used it (or tested it) during the audit period. Security events are logged, alerts are configured, and there is an on-call rotation.

View official AICPA language

The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives.

What auditors look for

Security Incident Response Plan (dated), incident response tabletop exercise records, SIEM alert configuration, on-call schedule

CC7.3 critical

Incident Response Execution

When a security event occurs, you follow your SIRP: classify the event, contain it, investigate, remediate, and document a post-incident review. Stakeholders are notified appropriately.

View official AICPA language

The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives.

What auditors look for

Post-incident review reports, incident tickets showing classification, containment actions, and root cause analysis

CC7.4 high

Incident Response — Recovery

After a security incident, you restore affected systems to their prior state, verify data integrity, and communicate with affected parties within contractually or legally required timeframes.

View official AICPA language

The entity responds to identified security incidents by executing a defined incident response program.

What auditors look for

Recovery runbooks, backup restoration test records, customer notification templates and logs, DR test results

CC7.5 high

Disclosure to Affected Parties

You have a documented process for notifying affected customers and regulatory bodies after a security incident. Notification timelines comply with GDPR, CCPA, or contract requirements.

View official AICPA language

The entity identifies, develops, and implements activities to recover from identified security incidents.

What auditors look for

Breach notification policy, example notification templates, documented stakeholder communication list

CC8 Change Management

CC8.1 critical

Change Management Process

Every production code change goes through a formal change management process: code review by a second person, automated testing, staging deployment, and documented approval before production release.

View official AICPA language

The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures.

What auditors look for

GitHub/GitLab PR history showing required reviewers, CI/CD pipeline logs, staging environment configuration, deployment approval records

CC9 Risk Mitigation

CC9.1 high

Risk Mitigation

You have a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that address how you maintain or restore services after a major disruption.

View official AICPA language

The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.

What auditors look for

Business Continuity Plan document, DR runbooks, annual DR test results (RTO/RPO verification), backup configuration

CC9.2 critical

Vendor & Third-Party Risk Management

You maintain a vendor inventory, assess each vendor's security posture before and during the relationship, and have contractual protections (DPAs, security requirements) in vendor agreements.

View official AICPA language

The entity assesses and manages risks associated with vendors and business partners.

What auditors look for

Vendor inventory list, security questionnaires or SOC 2 reports collected from critical vendors, DPAs signed with each vendor

Track all 33 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today