Skip to content
compliancebase
SOC 2CC6 — Removes Access When Appropriate

CC6.3

Removes Access When Appropriate

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity removes access to protected information assets when appropriate based on changes in employment or business relationship.

Points of focus

  • Removes access when employment or engagement ends
  • Modifies access when roles change
  • Coordinates removal across systems administering access

Implementation notes

In AICPA TSC terms, CC6.3 is about removing access when employment or business relationships change — leavers and movers, not only new hires. Integrate HRIS termination and role-change events into your IdP so workforce accounts disable on a defined SLA (commonly same business day). Maintain an offboarding runbook for non-SSO systems: cloud consoles, CI secrets, VPN, production databases, and customer-support tools that may hold local accounts. For movers, require an explicit role recertification — do not leave prior privileged groups attached after a transfer. Run periodic orphan-account scans against HR active headcount and fix exceptions with tickets. Evidence for Type II is the population of leavers/movers with IdP disable timestamps and samples showing downstream app cleanup.

Audit tip: Sample terminated users: prove disable time relative to last day and check high-risk apps for residual access.

Evidence auditors typically request:

  • Leaver tickets with disable timestamps
  • IdP termination logs
  • Mover access change records
  • Periodic orphan account scans

Common gaps

  • HR termination not synced to IdP same day
  • SaaS apps outside SSO retaining local accounts
  • Movers keep previous privileged roles

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.3This control
ISO 27001A.5.18, A.8.2Access rights modification/removal
HIPAA164.308(a)(3)(ii)(C)Termination procedures
GDPRArticle 32(1)(b)Access no longer needed

Primary sources

Frequently Asked Questions

Same business day is a common target for workforce terminations; involuntary exits often disable before the person leaves. Document your SLA in policy, meet it consistently, and retain IdP timestamps so auditors can compare last day to disable time for Type II samples.

Disable accounts and revoke session tokens immediately — do not wait on hardware. Treat device recovery as a parallel facilities or IT asset process with inventory tracking and remote wipe where MDM allows. Logical access removal under CC6.3 should not be blocked by shipping delays.

Yes. When a human owner leaves or an integration retires, rotate or disable service credentials, API keys, and bot accounts they controlled. Keep an owned inventory of non-human identities so offboarding checklists cover secrets, not only user logins.

They typically select terminations (and often role changes) from HR lists for the period, then trace each person to IdP disable evidence and a subset of high-risk applications. Incomplete populations or apps outside SSO without cleanup evidence are common findings.

Apply the same removal expectations with explicit end dates and automatic expiry where the IdP supports it. Do not rely on a manager remembering to disable. Extend tickets and timestamps to contractor and vendor users whose access you administer.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above