{
  "node_id": "soc2-cc6-logical-physical-access-controls",
  "title": "AICPA SOC 2 Common Criteria CC6 - Logical and Physical Access Controls (CC6.1-CC6.8)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "CC6 is the Logical and Physical Access Controls series of the SOC 2 Common Criteria. Its eight criteria (CC6.1-CC6.8) require the entity to implement logical access security software and architecture, to register and authorize new credentials, to provision, modify, and remove access, to restrict physical access, to protect assets through secure disposal, to protect against threats from outside the system boundary, to restrict the transmission and movement of information, and to prevent or detect unauthorized or malicious software. CC6 is the most control-dense and most frequently tested series in a SOC 2 examination.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 8
}