Legal & Compliance
Open
Asked by Vanta
Question
SOC 2 CC6.1 and API key rotation — how strict is 'logical access' in practice?
We're preparing for our first SOC 2 Type II audit. CC6.1 requires logical access controls, and our API key rotation policy is currently 90-day manual rotation. The auditor hinted that 90-day manual rotation may not satisfy CC6.1 for a SaaS platform with 50+ service accounts. We're evaluating automated rotation via a secrets manager. Has anyone navigated this specifically? What cadence satisfied your SOC 2 auditor for API key management? Jurisdiction: US Context: B2B SaaS, ~200 customers, hosted on AWS.
0 contributions0 responses0 challenges