SOC 2 Control Implementation Guide

Security Architecture

Physical Access and Device Protection for SOC 2

Physical access to company facilities is restricted; hosting provider physical/environmental controls are relied upon and reviewed; company devices are recovered or securely disabled when no longer required.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

Access to company workspaces and devices is limited to authorized people, visitors are controlled, provider-operated facilities are evaluated through available assurance, and devices are recovered or securely disabled at end of use.

First SOC 2 program

A credible starting point

For a remote-first team, focus on company-device inventory, secure delivery and return, coworking or office keys, visitor handling, and verified remote lock or wipe. Document which physical safeguards are operated by cloud and office providers instead of claiming to operate their facilities directly.

As the company scales

Make it repeatable

Centralize badge and visitor records, reconcile access with active personnel, define restricted areas, maintain device chain of custody, test remote disablement, and periodically review hosting and workplace provider assurance and exceptions.

How to implement Physical Access and Device Protection

  1. 1

    Define physical scope and dependencies

    List company-controlled offices and storage areas, remote-worker device scenarios, cloud or colocation providers, restricted assets, and the party responsible for each physical safeguard.

    You should end up with: A physical-security scope map distinguishing company-operated controls from provider-operated safeguards.

  2. 2

    Authorize workplace access

    Issue badges or keys to named active personnel based on need, restrict sensitive areas, record issuance, and promptly disable or recover access when the need ends.

    You should end up with: A current physical-access list with issuance, authorization, status, and deactivation records.

  3. 3

    Control visitors

    Require visitor identification or host confirmation, record arrival and departure, provide visible temporary access where appropriate, and escort visitors in restricted areas.

    You should end up with: Dated visitor records and documented host or escort responsibility.

  4. 4

    Protect and recover devices

    Track device assignment and shipment, require secure storage and prompt loss reporting, and recover, lock, or wipe devices when employment, contract, ownership, or business need ends.

    You should end up with: Asset custody records plus confirmed return, remote lock, wipe, or retirement status.

  5. 5

    Review providers and access records

    Evaluate available facility and environmental assurance from hosting providers, review company access lists and exceptions, and follow up on stale badges, missing devices, or assurance gaps.

    You should end up with: A dated review of provider assurance, workplace access, device recovery, and completed corrective actions.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

Office access records

  • Confirm what the record proves

    Current badges, keys, codes, and restricted-area permissions are tied to named active people, approved need, issuance, use where logged, and timely revocation.

  • Include this context

    Person

  • Include this context

    Credential ID or type

  • Include this context

    Authorized location

  • Include this context

    Approval and issue date

  • Include this context

    Status and revocation time

  • Include this context

    Access event where available

Weak evidence to avoid

A list of badge numbers or shared door codes with no named holder, location scope, authorization, active status, revocation time, or review date.

visitor logs

  • Confirm what the record proves

    Non-employees entering controlled workspaces are attributable to a host, time-bounded, and subject to the intended visitor and escort process.

  • Include this context

    Visitor identity

  • Include this context

    Host

  • Include this context

    Purpose

  • Include this context

    Arrival and departure

  • Include this context

    Areas visited

  • Include this context

    Escort or temporary credential

Weak evidence to avoid

An undated visitor sign-in with an unreadable name and no host, departure time, purpose, area, escort, or temporary credential return.

asset recovery records

  • Confirm what the record proves

    A device due for return or disablement reached a verified custody, lock, wipe, repair, reuse, or disposal state tied to its former custodian.

  • Include this context

    Asset and serial ID

  • Include this context

    Former custodian

  • Include this context

    Recovery trigger and date

  • Include this context

    Return, lock, or wipe action

  • Include this context

    Completion timestamp

  • Include this context

    Verified final disposition

Weak evidence to avoid

A shipping label or wipe request with no serial number, receipt, remote-action result, custody transfer, or confirmed final disposition.

subservice SOC/ISO reports

  • Confirm what the record proves

    Available independent assurance for a hosting or workplace provider was reviewed for applicable facility and environmental safeguards, period coverage, exceptions, and customer responsibilities.

  • Include this context

    Provider and service

  • Include this context

    Report type and period

  • Include this context

    Applicable facility scope

  • Include this context

    Relevant exception

  • Include this context

    Customer responsibility

  • Include this context

    Reviewer and review date

Weak evidence to avoid

A provider trust-page badge or expired certificate with no report period, facility scope, exceptions, customer responsibilities, or internal review decision.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

As of the selected date, retain current workplace credential assignments, current device custody and management state, the latest visitor record review, and the latest applicable hosting or workplace provider assurance review.

Type 2

Evidence across the review period

Include every workplace badge, key, code, and restricted-area issuance, change, and revocation; every recorded visitor entry; every device recovery, lock, wipe, or disposal action triggered during the review period; and every required provider facility-assurance review, exception, and follow-up.

Completeness check

Reconcile active and departed personnel to current workplace credentials, reception records to visitor logs, lifecycle events to assigned-device recovery or remote-action state, and the in-scope hosting and workplace provider inventory to current assurance reviews and tracked exceptions.

Build the record set from

  • Workplace access-control system
  • Visitor registration records
  • Human-resources and contractor roster
  • Hardware and device inventory
  • Endpoint management and IT tickets
  • Provider assurance repository and review tracker

Keep these fields for each record

  • Person, visitor, asset, or provider
  • Credential, visit, device, or report ID
  • Trigger, scope, or purpose
  • Issue, event, or review timestamp
  • Owner, host, custodian, or reviewer
  • Revocation, final disposition, or follow-up

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: Access to company workspaces and devices is limited to authorized people, visitors are controlled, provider-operated facilities are evaluated through available assurance, and devices are recovered or securely disabled at end of use.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (Infrastructure / Security Operations / IT), then compare dated records with the stated cadence: Continuous/ongoing; periodic review by risk.

  • Establish the complete audit record set

    Reconcile active and departed personnel to current workplace credentials, reception records to visitor logs, lifecycle events to assigned-device recovery or remote-action state, and the in-scope hosting and workplace provider inventory to current assurance reviews and tracked exceptions.

  • Prepare the as-of-date evidence for a Type 1 engagement

    As of the selected date, retain current workplace credential assignments, current device custody and management state, the latest visitor record review, and the latest applicable hosting or workplace provider assurance review.

  • Prepare period evidence for a Type 2 engagement

    Include every workplace badge, key, code, and restricted-area issuance, change, and revocation; every recorded visitor entry; every device recovery, lock, wipe, or disposal action triggered during the review period; and every required provider facility-assurance review, exception, and follow-up.

  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect Office access records

      For each selected record, confirm it demonstrates Current badges, keys, codes, and restricted-area permissions are tied to named active people, approved need, issuance, use where logged, and timely revocation.

      • Person
      • Credential ID or type
      • Authorized location
      • Approval and issue date
      • Status and revocation time
      • Access event where available
    • Inspect visitor logs

      For each selected record, confirm it demonstrates Non-employees entering controlled workspaces are attributable to a host, time-bounded, and subject to the intended visitor and escort process.

      • Visitor identity
      • Host
      • Purpose
      • Arrival and departure
      • Areas visited
      • Escort or temporary credential
    • Inspect asset recovery records

      For each selected record, confirm it demonstrates A device due for return or disablement reached a verified custody, lock, wipe, repair, reuse, or disposal state tied to its former custodian.

      • Asset and serial ID
      • Former custodian
      • Recovery trigger and date
      • Return, lock, or wipe action
      • Completion timestamp
      • Verified final disposition
    • Inspect subservice SOC/ISO reports

      For each selected record, confirm it demonstrates Available independent assurance for a hosting or workplace provider was reviewed for applicable facility and environmental safeguards, period coverage, exceptions, and customer responsibilities.

      • Provider and service
      • Report type and period
      • Applicable facility scope
      • Relevant exception
      • Customer responsibility
      • Reviewer and review date
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • Coworking or shared-office controls are assumed to be sufficient without documenting company responsibilities for keys, visitors, and restricted assets.
  • Shared keys or door codes cannot be tied to a named person or promptly revoked.
  • Visitors enter work areas without a retained arrival, departure, host, or escort record.
  • A return label is sent for a departed worker’s device, but receipt, lock, wipe, or final disposition is never confirmed.
  • The company claims physical safeguards for cloud facilities without retaining and reviewing available provider assurance.

Before you call this control ready

  • Can every active badge, key, or door credential be tied to a current person and approved need?
  • Do visitor records show who entered, when they left, and who hosted or escorted them?
  • Can every company device be traced to a current custodian or documented final disposition?
  • For a lost or unreturned device, can we show the remote lock or wipe result rather than only the request?
  • Are cloud and workplace provider physical safeguards reviewed without confusing them with company-operated controls?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC6.4
  • CC6.5
  • A1.2

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.