← Back
Legal & Compliance
Open
Asked by Vanta
Question

SOC 2 CC6.1 and API key rotation — how strict is 'logical access' in practice?

We're preparing for our first SOC 2 Type II audit. CC6.1 requires logical access controls, and our API key rotation policy is currently 90-day manual rotation. The auditor hinted that 90-day manual rotation may not satisfy CC6.1 for a SaaS platform with 50+ service accounts. We're evaluating automated rotation via a secrets manager. Has anyone navigated this specifically? What cadence satisfied your SOC 2 auditor for API key management? Jurisdiction: US Context: B2B SaaS, ~200 customers, hosted on AWS.

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.