CC6.4
Restricts Access to Physical Assets
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity restricts physical access to facilities and protected information assets to authorized personnel to meet the entity's objectives.
Points of focus
- Restricts physical access to facilities
- Manages physical access credentials
- Monitors physical access where appropriate
Implementation notes
CC6.4 in the AICPA Trust Services Criteria is about restricting physical access to facilities and protected assets to authorized people. Inventory where physical assets exist: offices with network gear, storage of spare laptops, colo cages, or warehouses. Use badge or equivalent access control for facilities you operate; keep visitor procedures and, where risk warrants, access logs. For hyperscaler-hosted production, inherit data-center physical security via current provider SOC 2/ISO reports and contract language, and state the shared-responsibility boundary in your system description. Secure equipment disposal and media sanitization should be documented for company-owned devices. Cloud-only teams still need a written story for any office or device physical risk they actually own.
Audit tip: For cloud-first SaaS, map physical controls to provider assurances and show how you restrict any on-prem or office-sensitive areas.
Evidence auditors typically request:
- Office access control policy
- Badge access logs or provider SOC reports covering physical security
- Visitor procedures
- Secure equipment disposal records
Common gaps
- Assuming cloud physical security without citing provider reports
- Unlogged visitor access to office network closets
- Laptops stored insecurely in shared offices
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC6.4 | This control |
| ISO 27001 | A.7.1, A.7.2 | Physical security perimeters & entry |
| HIPAA | 164.310(a)(1) | Facility access controls |
| GDPR | Article 32(1) | Physical measures as appropriate |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus