Skip to content
compliancebase
SOC 2CC6 — Restricts Access to Physical Assets

CC6.4

Restricts Access to Physical Assets

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity restricts physical access to facilities and protected information assets to authorized personnel to meet the entity's objectives.

Points of focus

  • Restricts physical access to facilities
  • Manages physical access credentials
  • Monitors physical access where appropriate

Implementation notes

CC6.4 in the AICPA Trust Services Criteria is about restricting physical access to facilities and protected assets to authorized people. Inventory where physical assets exist: offices with network gear, storage of spare laptops, colo cages, or warehouses. Use badge or equivalent access control for facilities you operate; keep visitor procedures and, where risk warrants, access logs. For hyperscaler-hosted production, inherit data-center physical security via current provider SOC 2/ISO reports and contract language, and state the shared-responsibility boundary in your system description. Secure equipment disposal and media sanitization should be documented for company-owned devices. Cloud-only teams still need a written story for any office or device physical risk they actually own.

Audit tip: For cloud-first SaaS, map physical controls to provider assurances and show how you restrict any on-prem or office-sensitive areas.

Evidence auditors typically request:

  • Office access control policy
  • Badge access logs or provider SOC reports covering physical security
  • Visitor procedures
  • Secure equipment disposal records

Common gaps

  • Assuming cloud physical security without citing provider reports
  • Unlogged visitor access to office network closets
  • Laptops stored insecurely in shared offices

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.4This control
ISO 27001A.7.1, A.7.2Physical security perimeters & entry
HIPAA164.310(a)(1)Facility access controls
GDPRArticle 32(1)Physical measures as appropriate

Primary sources

Frequently Asked Questions

Rarely fully N/A. Document device physical protection (encryption, secure storage expectations) and any colocation or warehouse access. Cloud data-center physical security is largely provider-assured — cite current provider reports and explain the shared-responsibility model clearly in the system description.

Only if you operate facilities or cages yourself. Otherwise inherit provider physical controls via SOC/ISO reports and contracts, and focus your own evidence on offices, devices, and any physical access credentials your entity issues.

Typically through acceptable use, full-disk encryption, screen privacy, and secure handling of printed or portable media — not through badge systems at residences. If highly sensitive work requires extra measures, document them in policy rather than inventing home-office physical audits you cannot sustain.

Current hyperscaler or colo provider reports covering physical security, plus office badge or visitor evidence where you have facilities. Be ready to walk through how spare devices are stored and how media disposal is controlled for in-scope assets.

CC6.4 is about authorizing and restricting physical access to facilities and protected assets. CC6.5 is about discontinuing that physical access when it is no longer appropriate — badge return, key recovery, and facilities offboarding. Design restriction and timely removal as a pair.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above