What is the Peer Review process in CCSS audits?

What is the Peer Review process in CCSS™ audits?

The CCSS peer review process is an independent quality assurance step that occurs after a CCSS auditor (CCSSA) has completed their evidence gathering and audit documentation. Every CCSS audit must undergo peer review before certification can be issued. During this process, a separate certified auditor, known as a CCSSA Peer Reviewer (CCSSA-PR), reviews the audit methodology and documentation to help ensure the audit was performed with sufficient rigor.

To maintain independence and reduce the risk of conflicts of interest, auditors must select a peer reviewer from a randomized Peer Reviewer Options List (PROL) provided by C4 after submitting an Intent to Audit form. The CCSSA and CCSSA-PR must not have a conflict of interest with each other, nor the entity whose system is being audited.

Importantly, the CCSSA-PR does not review the entity’s audit evidence directly. Instead, the auditor redacts the Report on Compliance (RoC) and provides this redacted Report on Compliance (RoC), with sensitive information and personally identifiable information removed, to the CCSSA-PR. Prior to providing the redacted RoC to the CCSSA-PR, the CCSSA will obtain the entity’s approval to share the redacted RoC with the CCSSA-PR. The CCSSA-PR reviews this redacted RoC to determine whether the auditor used appropriate evidence-gathering techniques such as interviews, inspections, observations, and document reviews. The objective is to determine whether the auditor gathered sufficient and appropriate audit evidence to support their conclusions regarding the audited system’s compliance with the CCSS.

Throughout the peer review, the CCSSA-PR may submit questions, request clarification, or identify areas requiring remediation. After the CCSSA updates the RoC and shares an updated redacted RoC, that updated redacted RoC must be reviewed and approved by the CCSSA. Once all issues have been resolved, the CCSSA-PR provides written confirmation to the CCSSA that the peer review process is complete and no further remediation is required so that the CCSSA can continue with the audit process.” The final Summary Report on Compliance (SRoC) must then be signed by both the CCSSA and CCSSA-PR before submission to C4.

The peer review process helps ensure consistency, audit quality, and confidence in the resulting CCSS certification while maintaining the confidentiality of the audited entity system information.

Date Updated: June 26, 2026
Article Number: 22
Back to FAQ