Skip to content
compliancebase
SOC 2CC6 — Restricts Transmission of Information

CC6.7

Restricts Transmission of Information

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission.

Points of focus

  • Protects data during transmission
  • Restricts movement/removal of information to authorized channels
  • Uses encryption or equivalent protections for sensitive transit

Implementation notes

Enforce HTTPS everywhere customer or admin data moves, disable legacy TLS, and inventory bulk export and support-tool features that can remove data. Apply least privilege to who can run exports. Under AICPA CC6.7, protect transmission and restrict movement to authorized channels — document approved paths and encryption standards for Type II evidence. Treat support tooling, warehouse syncs, and partner SFTP drops as transmission channels with the same scrutiny as customer-facing APIs. Keep a short allowlist of approved transfer mechanisms and reject ad-hoc email or chat exports of production data. For the observation window, retain TLS configuration baselines, certificate inventories, and samples of export approvals so auditors can follow how data left the boundary — not only that encryption exists in theory.

Audit tip: Show encryption in transit for customer data paths and explain approved egress channels.

Evidence auditors typically request:

  • TLS configuration standards / certificates
  • DLP or egress controls where used
  • Secure file transfer procedures
  • Email/outbound data handling policy

Common gaps

  • Cleartext admin protocols on internal networks
  • Untracked exports to personal storage
  • Expired or weak TLS configurations

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.7This control
ISO 27001A.8.24, A.5.14Cryptography & information transfer
HIPAA164.312(e)(1)Transmission security
GDPRArticle 32(1)(a)Pseudonymisation/encryption measures

Primary sources

Frequently Asked Questions

TLS 1.2+ with modern ciphers is common baseline practice. Track deprecation guidance, disable weak suites, and evidence configuration standards (or scans) so auditors can see transit protection is intentional, not accidental.

DLP is one way to restrict unauthorized movement of information. If you do not run enterprise DLP, document compensating controls — export approvals, least privilege, logging, and acceptable-use restrictions on personal storage.

Treat backup replication as a transmission path — encrypt in transit and at rest, and control access to backup stores. Include backup vendors and regions in your data-flow and shared-responsibility narrative.

Yes — partner APIs that move customer data should use authenticated, encrypted channels with documented authorization. Map those integrations in data flows so CC6.7 evidence covers more than browser TLS.

If confidentiality is in scope, transmission protections often appear in both CC6.7 and confidentiality criteria. Align claims in the system description so you do not promise confidentiality controls you only partially evidence under Security.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above