Get Demo
↑

SOC 2 Common Criteria CC1–CC9 Explained

CC1 through CC9 are the Security criterion’s control categories in the 2017 Trust Services Criteria — from control environment to risk mitigation.

Published: September 2026 Compliance · SOC 2 8–12 min read

When people say “SOC 2 Security,” they usually mean the Common Criteria (CC1–CC9) in the AICPA 2017 Trust Services Criteria. These categories structure how auditors evaluate whether your controls support the Security criterion.

Related: Five TSC · CC7 & SIEM · Controls list.

Common Criteria CC1–CC9: These are the Security criterion’s control categories in the 2017 Trust Services Criteria (CC1 Control Environment through CC9 Risk Mitigation). Organisations define their own controls to address TSC points of focus — AICPA does not publish a single fixed “N controls” checklist that every company must copy.

CC1–CC9 at a Glance

Category
Focus
CC1 Control Environment
Integrity, ethics, board oversight, organisational structure, competence, accountability
CC2 Communication & Information
Internal and external communication of quality information needed for control
CC3 Risk Assessment
Objectives, risk identification/analysis, fraud risk, change impact
CC4 Monitoring Activities
Ongoing and separate evaluations; deficiency communication
CC5 Control Activities
Selection and development of control activities and technology general controls; policies put into action
CC6 Logical & Physical Access
Access restriction, authentication, credentials, access removal, physical security
CC7 System Operations
Detection of changes/anomalies, incident evaluation and response — see CC7 monitoring guide
CC8 Change Management
Authorised changes to infrastructure, data, software, and procedures
CC9 Risk Mitigation
Business disruption risk mitigation; vendor and business-partner risk

Points of Focus, Not a Fixed Control Count

Each CC category includes criteria and illustrative points of focus. Your organisation designs controls that achieve those criteria. Tool vendors and consultants often publish sample control libraries — treat those as starting points, not an official AICPA headcount.

Evidence Patterns Auditors Expect

How CyberSilo Helps

CSA organises CC-mapped control status and artefacts; ThreatHawk supplies operational monitoring evidence commonly requested under CC7.

Map CC1–CC9 Without Spreadsheet Drift

Walk through a TSC-aligned control library and evidence owners with CyberSilo.

Frequently Asked Questions

Are CC1–CC9 the same as the five Trust Services Criteria?

No. CC1–CC9 are the control categories for the Security criterion. The five TSC are Security, Availability, Processing Integrity, Confidentiality, and Privacy.

How many SOC 2 controls does AICPA require?

AICPA publishes criteria and points of focus, not a single mandatory fixed control count. You define controls that address the criteria in scope.

Is CC7 only about SIEM?

CC7 covers system operations including detection of anomalies and incident response. Many organisations use a SIEM as part of that evidence, but the criterion is broader than any one tool.

SOC 2 hub · TSC · Checklist · Policies

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!