How is confidentiality maintained during a CCSS audit?

How is confidentiality maintained during a CCSS™ audit?

Confidentiality is a fundamental part of the CCSS audit process. CCSS Auditors (CCSSAs) are responsible for protecting sensitive information obtained during an audit and must ensure that their agreements with the organization include appropriate confidentiality provisions that comply with the laws and regulations of the jurisdiction where the audit is performed.

Throughout the audit, organizations may be asked to provide documentation, policies, procedures, system configurations, and other evidence. CCSSAs are required to securely store and transmit this information in accordance with the CCSS audit process and applicable laws and regulations. If an entity does not permit evidence to be stored outside its environment, or if the CCSSA chooses not to retain copies, the CCSSA may instead document metadata and detailed notes describing the evidence reviewed.

The peer review process also helps protect confidentiality. CCSSA Peer Reviewers (CCSSA-PRs) do not receive audit evidence or other audit artifacts. The only document provided to a CCSSA-PR is the redacted Report on Compliance (ROC), which allows them to evaluate the quality of the CCSSA’s work without exposing sensitive information about the audited system.

Date Updated: June 26, 2026
Article Number: 25
Back to FAQ