Complies
SOC 2 EXPLAINERS

SOC 2 Controls List: AICPA CC1 to CC9 Common Criteria

JULY 2026 · 12 MIN READ · BY THE COMPLIES TEAM

The SOC 2 controls list is organized around nine common criteria series, CC1 through CC9, defined by the AICPA (the American Institute of Certified Public Accountants) in its Trust Services Criteria; every SOC 2 report must cover all nine, and optional categories add criteria for availability, confidentiality, processing integrity, and privacy. Here is each series, what it covers, and an example control you would actually implement.

How SOC 2 controls actually work

SOC 2 does not hand you a fixed checklist of named controls the way ISO 27001's Annex A does. The Trust Services Criteria define outcomes (the criteria), and you define the controls that meet them for your environment. Your auditor then tests whether those controls are suitably designed and, in a Type 2, whether they operated over the observation window. CC1-CC5 are adapted from the COSO internal control framework; CC6-CC9 are the more technical, security-specific series where engineering teams spend most of their time.

What is the difference between SOC 2 criteria and controls?

The criteria are the AICPA's required outcomes, and the controls are the specific things you do to achieve them. SOC 2 gives you 33 common criteria across CC1 to CC9 and expects you to design your own controls against each one, which is why no two SOC 2 controls lists are identical.

Take CC6.1, which asks that the entity implement logical access security software, infrastructure, and architectures over protected information assets. That is the criterion, and the wording is identical for a two-person startup and a national bank. The control is your answer to it: production access is granted through Okta groups, requires hardware MFA, and is provisioned only from an approved ticket. Your auditor tests your control and reports against the criterion. This trips up most first-time teams: a criterion is not something you install, it is a bar your control has to clear.

SOC 2 common criteria: CC1-CC9 table

Series Category What it covers Example control
CC1 Control environment Integrity, ethics, board oversight, organizational structure, accountability A code of conduct every employee acknowledges at hire and annually
CC2 Communication and information How security-relevant information reaches employees, customers, and vendors Published security policies; customer-facing incident notification commitments
CC3 Risk assessment Identifying and analyzing risks, including fraud risk and change-driven risk An annual documented risk assessment with likelihood x impact scoring and owners
CC4 Monitoring activities Ongoing evaluation that controls are present and functioning Quarterly control self-assessments; tracking remediation of findings to closure
CC5 Control activities Policies and procedures that put risk decisions into action A policy set reviewed and re-approved annually with recorded sign-off
CC6 Logical and physical access Access provisioning, authentication, least privilege, revocation, physical security SSO with MFA enforced; offboarding checklist revoking all access within 24 hours; quarterly access reviews
CC7 System operations Monitoring, detecting anomalies, incident response, recovery Centralized logging with alerting; a tested incident response plan with postmortems
CC8 Change management Authorizing, designing, testing, and approving changes to systems Every production deploy tied to a reviewed pull request and CI checks; emergency change procedure
CC9 Risk mitigation Mitigations for business disruption and vendor risk Annual vendor security reviews; business continuity plan with a tested backup restore

Who defines the SOC 2 controls list?

You do. The AICPA publishes the Trust Services Criteria your controls have to satisfy, your management writes the control descriptions that appear in the report's system description, and an independent CPA firm tests them. There is no official AICPA master list of controls to download, and any vendor selling you one is selling a starting point.

This shows up in the report itself: the controls printed alongside each criterion are your assertions about your systems, which is why an auditor can raise an exception against a control you wrote yourself. So pick controls you can actually operate. A quarterly access review you perform beats a monthly one you skip twice. A pre-built set mapped to the criteria is what SOC 2 compliance software is for, but treat it as a draft to edit against your architecture.

What is the AICPA points of focus?

Points of focus are the AICPA's suggested considerations under each criterion, describing characteristics an auditor might expect to see. They shipped with the 2017 Trust Services Criteria and were revised in 2022. They are guidance rather than a mandatory checklist: you do not have to address every point of focus, and you are not graded against them one by one.

The 2022 revision is widely misreported: it changed the points of focus only and did not alter a single 2017 criterion, so anyone telling you the criteria were rewritten is wrong. The refreshed guidance pulled in what had changed since 2017: cloud configuration, third-party and vendor concentration risk, ransomware, and a remote workforce.

Read them as an auditor's hint sheet, not as work to complete. The practical test: if you cannot connect a control to any point of focus under a criterion, the control is probably too thin.

The optional categories

Beyond the common criteria, you can scope additional Trust Services Criteria categories into your report:

  • Availability (A series). Capacity planning, monitoring, backup and disaster recovery against your uptime commitments. Add it if customers ask about SLAs; most B2B SaaS buyers do.
  • Confidentiality (C series). Identifying, protecting, and disposing of confidential information through its lifecycle. Common for companies holding sensitive business data.
  • Processing integrity (PI series). Processing is complete, valid, accurate, timely, and authorized. Mostly requested for fintech, payments, and data-pipeline products.
  • Privacy (P series). Personal information handling against the AICPA privacy criteria. Requested less often; teams with EU exposure usually address privacy through GDPR instead, and the two overlap heavily.

Each category you add expands the control count, the evidence burden, and the auditor fee, so scope to what buyers actually request. Security alone plus availability and confidentiality is the most common first-report shape.

What are the 5 trust service principles?

There are five, and they have not officially been called principles since 2017. The AICPA renamed the Trust Services Principles to the Trust Services Criteria, and the five groupings are now called categories: security, availability, processing integrity, confidentiality, and privacy. Security is required in every SOC 2; the other four are optional.

The rename was not cosmetic. The 2013 COSO framework already uses "principles" for its 17 internal control factors, and since CC1 to CC5 are built on COSO, one word meaning two things inside one report was a real problem. The 2016 Trust Services Principles and Criteria were superseded for report periods ending on or after December 15, 2018. The old name survives in buyer language anyway: if a questionnaire asks which trust services principles you cover, they mean categories.

How many controls are in SOC 2?

SOC 2 has no fixed number of controls. It has criteria: 33 common criteria under CC1 to CC9 for security, plus 28 more across the four optional categories, for 61 in total. How many controls you write to satisfy them is your decision, and in practice the control count runs higher than the criteria count.

Here is how the 33 common criteria are distributed:

Series Criteria Range
CC1 5 CC1.1 to CC1.5
CC2 3 CC2.1 to CC2.3
CC3 4 CC3.1 to CC3.4
CC4 2 CC4.1 to CC4.2
CC5 3 CC5.1 to CC5.3
CC6 8 CC6.1 to CC6.8
CC7 5 CC7.1 to CC7.5
CC8 1 CC8.1
CC9 2 CC9.1 to CC9.2

The optional categories add availability (3 criteria), confidentiality (2), processing integrity (5), and privacy (18), which is why adding privacy costs so much more than adding confidentiality.

Two things stand out. CC6 carries eight criteria on its own, roughly a quarter of the common criteria, which is why logical access eats the largest share of every readiness project. CC8 change management has exactly one criterion, yet routinely produces a dozen controls. Criteria count and control count are nowhere near 1:1.

How many controls is that in practice?

Because SOC 2 lets you define the controls, counts vary, but a small SaaS company commonly lands between 60 and 100 controls across CC1-CC9 plus availability and confidentiality. Each control needs an owner, a frequency (continuous, monthly, quarterly, annual), and evidence that it ran; the recurring ones are what auditors sample in a Type 2, and missed runs surface as exceptions. The audit evidence examples guide shows what auditors expect per control area.

Are SOC 2 controls the same for every company?

No. The criteria are identical for everyone, but the controls are not, because your controls describe your actual systems. Two companies in the same market with the same scope routinely produce control lists that differ by dozens of entries, and both can earn a clean opinion, because the criteria are outcomes rather than instructions.

What drives the divergence, in rough order of impact:

  • Headcount and structure. CC1 assumes governance. A 200-person company has a board, a security committee, and named risk owners. An 8-person company has a founder who signs everything, so CC1 collapses into a handful of controls. Both satisfy the criteria.
  • Architecture. A single AWS account might need three or four CC6 access controls. Multi-cloud, multi-region, with customer-managed keys, needs many times that.
  • Physical footprint. CC6 covers physical access. Fully remote with no office? Several controls are replaced by a statement about your cloud provider's data centers.
  • Deploy cadence. A team shipping 40 times a day needs automated CC8 gates. A team shipping monthly can run a change advisory board on a calendar invite.
  • Subservice organizations. Carve out AWS and its controls stay out of your description, but the obligation to monitor AWS lands on you under CC9.

Evidence differs as much as the controls: an access review pulled from Okta looks nothing like one assembled by hand, and the second costs far more per cycle. Each control has to produce proof on a schedule, which is the problem compliance evidence collection solves. Copying another company's list is the surest way to end up with controls you cannot evidence.

One control set, many frameworks

Here is the part that saves real money: these controls are not SOC 2-specific. CC6 access controls map onto ISO 27001:2022 Annex A access control and identity management controls; CC3 risk assessment maps to ISO clause 6 and supports GDPR Article 32; CC8 change management maps to Annex A's technological controls. Completed SOC 2 work commonly pre-fills around 60% of ISO 27001. If a second framework is anywhere on your roadmap, implement each control once and map it everywhere, rather than building parallel per-framework checklists. The tradeoffs are laid out in SOC 2 vs ISO 27001.

The usual caveat applies: defining controls against this list prepares you for the audit, but the CPA firm decides what its report says. No list and no tool guarantees a clean opinion.

Turning the list into a working program

A controls list becomes a compliance program the day every row has an owner, a schedule, and evidence attached. Until then it is a document. The gap is operational: dozens of controls on different frequencies, spread across engineering, HR, and finance, is more recurring work than a spreadsheet survives. That is the job governance, risk, and compliance in one system is built for, holding controls, owners, schedules, risks, and evidence together instead of in four places that drift apart.

Complies ships the CC1-CC9 control set pre-built and cross-mapped across SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, so each control you stand up counts toward every framework that references it, with a live readiness score per framework. It is self-serve with published prices from $79 per month. See how control mapping software collapses five frameworks into one control set, and get started with the nine series above.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.