SOC 2 CC6.4: Restricting Physical Access to Facilities and Assets

Reviewed by Ali Aleali, CISSP, CCSP · Last reviewed July 28, 2026

SOC 2 CC6.4 requires that physical access to facilities and protected information assets is restricted to authorized personnel. It sits in the CC6 series (Logical and Physical Access Controls) and is the one criterion in that series that most SaaS teams do not operate themselves: physical security usually belongs to a colocation or cloud provider, and a frequent finding under CC6.4 is a company that assumed the provider's report covered everything and documented nothing on its own side.

CC6.4 at a glance

  • Series: CC6 Logical and Physical Access Controls | Source: AICPA TSC 2017 (rev. 2022)
  • COSO principle: AICPA supplemental (beyond the 17 COSO principles)
  • Points of focus: 3
  • ISO 27001:2022: A 7.1, A 7.2, A 7.3, A 7.4 (Full overlap)
  • Reference card: FEX Framework Explorer
  • Part of: the SOC 2 Trust Services Criteria guide

What does SOC 2 CC6.4 require?

The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.

AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (TSC section 100), 2017, revised 2022. © AICPA. Quoted for purposes of commentary and reference.

In plain terms, CC6.4 asks who can physically reach the places where data and systems live, and how that access is granted, removed, and checked. The protected assets it names are concrete: server rooms, colocation cages, backup media storage, and the offices where people handle sensitive information. The criterion is technology-neutral and infrastructure-neutral. It applies whether the servers sit in a hyperscaler region, a third-party data center, or a rack in the company's own building.

Most SOC 2 programs do not run their own data center, which changes how CC6.4 is satisfied more than any other CC6 criterion. When a cloud or colocation provider controls the building, the physical access controls are the provider's, and the company relies on them through a subservice relationship. That reliance is legitimate and standard, but it is not automatic evidence. The criterion still expects the company to show that the reliance is deliberate, reviewed, and paired with the physical controls the company does operate, starting with its own offices and employee devices.

CC6.4 also reaches past the data center. Backup media storage, a network closet in a corporate office, and a locked cabinet holding decommissioned drives all fall inside its scope. A company with no servers of its own still has an office, a badge system, and visitors, and those are in scope for CC6.4.

What are the CC6.4 points of focus?

The AICPA defines 3 points of focus for CC6.4. Because the Trust Services Criteria are AICPA copyrighted material, the points of focus below are paraphrased and grouped by theme rather than reproduced verbatim; consult the official TSC document for exact wording.

  • Authorized physical access. Physical access to facilities and protected assets is created or modified on an authorized basis, so entry rights trace to an approval tied to a role or responsibility.
  • Physical access removal. Physical access is removed when an individual no longer needs it, whether through departure, role change, or the end of a contract, on the same timeline as logical access.
  • Periodic review of physical access. The list of people who hold physical access is reviewed on a defined cadence and reconciled against current staff and contractors.

How do you meet CC6.4 in cloud and hosted environments?

Cloud and hosted environments satisfy CC6.4 largely through inherited controls, documented as a subservice relationship rather than operated in-house. The data center physical security belongs to the provider, and the company's job is to prove the reliance is managed:

  • Carve-out documentation for the provider. The SOC 2 system description names the cloud or colocation provider as a subservice organization and states that facility access, environmental controls, and physical monitoring are the provider's responsibility. The carve-out method is the standard treatment for AWS, Azure, GCP, and established colocation vendors.
  • Annual review of the provider's SOC 2 report. Management reviews the provider's current SOC 2 report each year, checks that the physical security controls are covered and unqualified, and watches for bridge-letter gaps between the provider's report period and the company's own.
  • Complementary controls on the company side. The provider's report often lists complementary user entity controls the company must operate. For physical security these are modest but real: keeping the authorized-personnel list current and restricting who can request data center access.
  • Office and endpoint physical controls. Badge or keycard access to the company's own offices, a visitor sign-in and escort process, locked storage for any on-hand media, and a clear-desk expectation for sensitive material. These are the physical controls the company operates directly, and they are what an auditor samples when there is no owned server room.

Companies that manage their own cage inside a colocation facility carry more than pure inheritance. They hold the badge or biometric credentials for the cage, they maintain the authorized-visitor list with the facility, and they are responsible for who they escort in. Those cage-access controls are the company's own, not the provider's, and they generate the company's own CC6.4 evidence.

How do you meet CC6.4 on-prem?

On-prem and self-hosted environments satisfy CC6.4 by operating the physical controls directly, because there is no provider report to inherit them from. The bare-metal SOC 2 readiness guide covers the full picture; the shape is:

  • Layered physical perimeter. Controlled building entry, a locked server room or cage, and separate credentials for the most sensitive spaces, so reaching the servers means passing more than one barrier.
  • Badge and access logs. An electronic access system records every entry to the server room and retains the log. The access list is defined by role, and each grant traces to an approval.
  • Visitor handling. Visitors to the server room sign in, are escorted, and are logged, with the record kept for the audit period.
  • Environmental and monitoring controls. Where the company owns the facility, power, cooling, fire suppression, and camera coverage of entry points fall into scope alongside access control.
  • Removable media and decommissioned hardware. Backup tapes, spare drives, and retired disks are stored in locked, access-controlled storage until they are handled under CC6.5 disposal.

Cloud vs on-prem at a glance

Point-of-focus theme Cloud / hosted implementation On-prem implementation
Authorized physical access Provider controls the data center; company keeps the authorized-personnel list and its own office badge grants Badge grants to the server room by role, each tied to an approval
Physical access removal Removal from the provider's authorized list plus office badge deactivation at offboarding Badge deactivation and cage-list removal at offboarding or role change
Periodic review of physical access Annual review of the provider's SOC 2 report plus a review of office and cage access holders Periodic review of the server-room access list against current staff

What evidence do auditors expect for CC6.4?

Artifact What it demonstrates Cadence
Provider SOC 2 report and annual review record Reliance on the subservice organization's physical controls is managed Reviewed annually
Subservice organization language in the system description Physical controls are formally scoped as carved out Per audit
Authorized physical access list Access maps to roles and current personnel Reviewed periodically
Badge or access system logs Entry to protected spaces is recorded and restricted Continuous
Visitor logs and escort records Non-authorized entry is controlled and accountable Per visit
Physical access review records The access list is reconciled against staff and contractors Quarterly or semi-annually
Office and media storage controls The company's own physical controls operate Continuous

A common gap: the provider report treated as the whole answer

A common gap that comes up during readiness assessments is treating the provider's SOC 2 report as the whole of CC6.4 and leaving the company's own side undocumented. A team relying on a colocation or cloud provider for data center physical security has usually made a sound decision, but without an annual review of that report, a check for bridge-letter gaps, and evidence of the company's own office and access controls, there is nothing to hand the auditor beyond a third party's document. The remediation is ordinary: record the annual provider-report review, name the complementary controls the company operates, and keep the office badge and visitor logs an auditor can sample. Physical access is one of the areas where good practice with no paper trail earns no credit.

How does CC6.4 map to ISO 27001:2022?

ISO 27001:2022 Annex A controls Overlap type SOC 2 evidence reusable
A 7.1 (physical security perimeters), A 7.2 (physical entry), A 7.3 (securing offices, rooms, and facilities), A 7.4 (physical security monitoring) Full Access lists, badge and entry logs, visitor records, physical access review evidence

Organizations pursuing both frameworks can reuse CC6.4 evidence directly for these Annex A physical controls. The SOC 2 to ISO 27001 control mapping covers the full crosswalk across all five Trust Services Categories.

Related criteria

CC6.4 applies the access discipline of the rest of the CC6 series to the physical world. SOC 2 CC6.1 covers the logical access architecture, and CC6.4 is its physical counterpart: the same authorize, remove, and review lifecycle applied to doors and racks instead of accounts. CC6.3 governs role-based access to systems, and physical access lists follow the same role logic. The next criterion, CC6.5, picks up where physical control ends, covering how assets are sanitized before protections are dropped. Physical monitoring of entry points also feeds the system monitoring covered under CC7.2.

Part of Truvo's criterion-by-criterion SOC 2 reference series

Browse every criterion in the Framework Explorer or start from the Trust Services Criteria guide. For a second set of eyes on control scoping before an audit as part of an effective security program, Truvo runs scoping calls.

 

Frequently Asked Questions

What does SOC 2 CC6.4 mean?

SOC 2 CC6.4 requires that physical access to facilities and protected information assets, such as data centers, backup media storage, and sensitive offices, is restricted to authorized personnel. In practice it asks who can physically reach systems and data, and whether that access is granted on approval, removed when no longer needed, and reviewed periodically.

What evidence satisfies CC6.4?

For companies in a cloud or colocation facility, the core evidence is the provider's SOC 2 report with a documented annual review, the subservice-organization language in the system description, and the company's own office badge logs, visitor records, and access list. On-prem, it is the server-room access list, badge and entry logs, visitor logs, and periodic access reviews.

Does CC6.4 apply to SaaS companies with no data center?

Yes. Even a company running entirely in the cloud has offices, a badge system, visitors, and often on-hand backup media, all of which are in scope for CC6.4. The data center physical security is inherited from the provider and handled as a subservice organization, but the company's own physical controls still need evidence.

How does CC6.4 work when a colocation provider handles physical security?

The provider's physical controls are carved out of the audit scope and referenced through the provider's own SOC 2 report. The company documents the reliance, reviews the provider's report annually, watches for bridge-letter gaps, and operates the complementary controls it owns, such as the cage-access list and its own office security.

How is CC6.4 different from CC6.1?

CC6.1 covers logical access: the software, infrastructure, and architecture that restrict access to systems and data. CC6.4 covers physical access: who can enter the facilities and reach the hardware where that data lives. The two use the same authorize, remove, and review lifecycle, applied to accounts in CC6.1 and to doors and racks in CC6.4.

Ready to Start Your Compliance Journey?

Get a clear, actionable roadmap with our readiness assessment.

Share this article:

About the Author

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.

How Ready Are You for SOC 2?

Score your security program in under 5 minutes. Free.

Take the Scorecard
Framework Explorer BETA Browse SOC 2 controls, guidance, and evidence — free.