SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity discontinues physical access to facilities and protected information assets when the access is no longer appropriate.
Points of focus
Removes physical access when no longer needed
Recovers access devices (badges, keys)
Coordinates with HR / facilities offboarding
Implementation notes
Under the AICPA Trust Services Criteria, CC6.5 expects physical access to be discontinued when employment, engagement, or business need ends — not only when someone remembers to ask facilities. Tie facilities offboarding to the same HRIS or offboarding ticket that drives logical access removal (CC6.3). Maintain a current badge and key inventory with named owners; deactivate badges and recover keys/fobs on the last day for terminations, and on role change when facility access is no longer required. For cloud-first SaaS with little or no owned office, document limited facility applicability in the system description, still run device return and remote-wipe steps for laptops, and record how coworking or landlord passes are revoked. Sample leavers quarterly to confirm badge timestamps match last day.
Audit tip: Sample leavers for badge deactivation timing aligned with last day.
Evidence auditors typically request:
□Badge deactivation records
□Asset return checklists
□Offboarding checklist including facilities
Common gaps
Badges remain active after termination
No inventory of physical keys
Contractors retain office access after engagement ends
Document limited facility access in the system description and emphasize device recovery, disk encryption, and remote wipe. Auditors still expect a clear story for any coworking passes, warehouse visits, or colo cage access your people control — even if day-to-day work is fully remote.
Align with your logical access SLA — typically same day as termination or engagement end. For involuntary terminations, deactivate before or as the person leaves the building. Record the badge system timestamp so Type II samples can prove timing against the HR last-day date.
Treat WeWork-style or landlord passes as credentials you must revoke. Keep a list of who holds building access, include provider revocation in the offboarding checklist, and retain confirmation (email or portal screenshot) that the pass was cancelled when the person left.
Auditors still test people and processes for any physical access your entity controls — badges, keys, visitor escorts, and cage lists. Provider data-center physical security is evidenced through their SOC reports and contracts; your job is to show how you discontinue access you issue.
CC6.3 addresses removal of logical access to systems and data when employment or business relationships change. CC6.5 addresses discontinuation of physical access to facilities and protected physical assets. Mature programs run both from one offboarding workflow so neither badge nor IdP account is left orphaned.