{
  "node_id": "soc2-cc3-risk-assessment",
  "title": "AICPA SOC 2 Common Criteria CC3 - Risk Assessment (COSO Principles 6-9)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "CC3 is the Risk Assessment series of the SOC 2 Common Criteria (COSO Principles 6-9). It requires the entity to specify objectives with sufficient clarity, identify and analyze risks to those objectives, consider the potential for fraud, and identify and assess changes that could significantly affect the system of internal control. The criteria are CC3.1-CC3.4.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 5
}