What CC6.4 covers

CC6.4 is one of the logical and physical access criteria in the AICPA Trust Services Criteria used for SOC 2. It asks that physical access to facilities and protected information assets, such as data center space, backup media storage and other sensitive locations, is restricted to authorized personnel. Its points of focus are creating or modifying physical access, removing it, and reviewing it.

We are not a CPA firm and do not issue SOC 2 reports. Your auditor decides scope and what evidence satisfies them. This guide describes what is commonly requested.

Evidence auditors commonly ask for

  • A list of sensitive areas and who is authorized to enter each.
  • Samples of access requests, showing approval before the badge was granted.
  • Samples of leavers, showing the badge was deactivated promptly after the leave date.
  • Periodic access reviews of the access control system’s cardholder list, signed off by area owners.
  • Visitor logs and escort procedures for sensitive areas.

Where exceptions usually come from

  • Leavers still active in the access control system, because it is not connected to HR. See why a terminated employee’s badge still works.
  • Access reviews that were performed but not evidenced, or were rubber-stamped with no changes quarter after quarter.
  • Shared or generic badges ("Contractor 3") that cannot be tied to a person.
  • Contractors and cleaners outside the provisioning process altogether.

If your systems run in the cloud

Companies hosted on a major cloud provider usually carve out the provider’s data centers and rely on that provider’s own SOC 2 report for them. That does not make CC6.4 disappear. Offices where laptops, backup media, network equipment or sensitive paper are kept can still be in scope, and so can any colocation cage you manage yourself.

The related criterion people miss

CC6.5 covers disposal: protections over physical assets should only be removed once the data on them can no longer be recovered. That is chain of custody for drives and media, from the rack to destruction, and it is one of the six areas we assess.

Testing before the auditor does

Our credential and access control assessment tests the controls behind this evidence: whether deactivated badges are really dead, whether reviews catch what they should, and whether sensitive areas are as restricted as the list says. Findings are prioritized, with a price range on each.

Last reviewed September 23, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.