What documentation should we prepare before an audit?

What documentation should we prepare before an audit?

Before a CCSS™ audit, entities should gather documentation that demonstrates how their system is designed, operated, and secured. The specific evidence required will depend on the system architecture and the CCSS requirements being assessed.

Commonly requested documentation includes:

  • System and wallet architecture diagrams
  • Key inventory and key management procedures
  • Policies and operational procedures
  • Access control and authorization records
  • Approval and signing workflows
  • Backup and recovery procedures
  • Incident response and key compromise plans
  • Threat models and risk assessments
  • Change management records
  • Audit logs and monitoring records
  • System configurations
  • Training records

In addition to documentation, organizations should be prepared to demonstrate how their controls operate in practice. CCSS Auditors will conduct interviews, inspections, observations, review documentation.

Preparing documentation in advance and ensuring it is accurate, complete, and up to date can significantly streamline the audit process. Working with a CCSS Implementer is one way entities can prepare for a CCSS audit before engaging a CCSS Auditor. If a CCSS Auditor’s readiness assessment identifies significant gaps that would likely prevent a successful audit, it may be beneficial to engage a CCSS Implementer to address those gaps before returning to the auditor to continue the certification process.

Date Updated: June 26, 2026
Article Number: 26
Back to FAQ