Skip to content
compliancebase
SOC 2CC6 — Discontinues Physical Access

CC6.5

Discontinues Physical Access

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity discontinues physical access to facilities and protected information assets when the access is no longer appropriate.

Points of focus

  • Removes physical access when no longer needed
  • Recovers access devices (badges, keys)
  • Coordinates with HR / facilities offboarding

Implementation notes

Under the AICPA Trust Services Criteria, CC6.5 expects physical access to be discontinued when employment, engagement, or business need ends — not only when someone remembers to ask facilities. Tie facilities offboarding to the same HRIS or offboarding ticket that drives logical access removal (CC6.3). Maintain a current badge and key inventory with named owners; deactivate badges and recover keys/fobs on the last day for terminations, and on role change when facility access is no longer required. For cloud-first SaaS with little or no owned office, document limited facility applicability in the system description, still run device return and remote-wipe steps for laptops, and record how coworking or landlord passes are revoked. Sample leavers quarterly to confirm badge timestamps match last day.

Audit tip: Sample leavers for badge deactivation timing aligned with last day.

Evidence auditors typically request:

  • Badge deactivation records
  • Asset return checklists
  • Offboarding checklist including facilities

Common gaps

  • Badges remain active after termination
  • No inventory of physical keys
  • Contractors retain office access after engagement ends

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.5This control
ISO 27001A.7.2, A.7.3Physical entry controls & securing offices
HIPAA164.310(a)(2)(iii)Access control & validation
GDPRArticle 32(1)Physical access as appropriate

Primary sources

Frequently Asked Questions

Document limited facility access in the system description and emphasize device recovery, disk encryption, and remote wipe. Auditors still expect a clear story for any coworking passes, warehouse visits, or colo cage access your people control — even if day-to-day work is fully remote.

Align with your logical access SLA — typically same day as termination or engagement end. For involuntary terminations, deactivate before or as the person leaves the building. Record the badge system timestamp so Type II samples can prove timing against the HR last-day date.

Treat WeWork-style or landlord passes as credentials you must revoke. Keep a list of who holds building access, include provider revocation in the offboarding checklist, and retain confirmation (email or portal screenshot) that the pass was cancelled when the person left.

Auditors still test people and processes for any physical access your entity controls — badges, keys, visitor escorts, and cage lists. Provider data-center physical security is evidenced through their SOC reports and contracts; your job is to show how you discontinue access you issue.

CC6.3 addresses removal of logical access to systems and data when employment or business relationships change. CC6.5 addresses discontinuation of physical access to facilities and protected physical assets. Mature programs run both from one offboarding workflow so neither badge nor IdP account is left orphaned.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above