CC6.2
Prior to Issuing System Credentials
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity.
Points of focus
- Registers new users prior to issuing credentials
- Authorizes new user access before credentials are issued
- Documents approvals for access grants
Implementation notes
Make IdP provisioning wait on an approved ticket so registration and authorization precede credentials — the core of AICPA CC6.2. Use SCIM where possible to reduce manual grants. Time-box contractor and vendor access with automatic expiry and a named sponsor. Keep role matrices so auditors can see what was authorized, not only that someone clicked approve. For Type II, export joiner/mover/leaver populations from the IdP and ticketing system for the full observation window, including service accounts. Spot-check that privileged roles still match the current org chart after reorganizations. Document break-glass accounts separately with dual control and logging — they are a frequent sample target when left undocumented.
Audit tip: Auditors sample new hires and contractors: show request, approval, and credential issue timestamps in order.
Evidence auditors typically request:
- Access request / approval tickets
- Role-based access matrices
- Joiner checklist including IdP account creation
- Screenshots or exports showing approval before grant timestamps
Common gaps
- Admin creates accounts before approval is recorded
- Shared onboarding Slack approvals without durable tickets
- External users provisioned without sponsor or expiry
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC6.2 | This control |
| ISO 27001 | A.5.16, A.5.18 | Identity management & access rights |
| HIPAA | 164.308(a)(3), 164.312(a)(1) | Workforce clearance / access |
| GDPR | Article 32(1)(b) | Access restriction measures |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus