CC1.1 CC1 · Control Environment · Security (Common Criteria)

CC1.1 — Integrity and ethical values

COSO Principle 1 — The entity demonstrates a commitment to integrity and ethical values.

Also written as CC 1.1, TSC CC1.1, SOC2 CC1.1, SOC 2 Type 2 CC1.1.

What SOC 2 CC1.1 requires

Integrity and ethical values is one of 5 criteria in the Control Environment (CC1) series of the Security (Common Criteria) category. COSO Principle 1 — The entity demonstrates a commitment to integrity and ethical values. CC1 criteria come from the COSO framework rather than from security practice, so the evidence is governance paperwork — charters, minutes, signed acknowledgements — and it usually lives with HR, legal, or the board rather than with the security team.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC1.1, gather artefacts such as:

  • Code of conduct signed by all personnel
  • Ethics / whistleblower policy and reporting channel
  • Background check records for new hires
  • Records of disciplinary action for conduct violations

Points of focus for CC1.1

The Trust Services Criteria set out points of focus that describe what an auditor considers when assessing CC1.1. They are not themselves requirements, but they shape the testing:

How to implement CC1.1

  1. Get the code of conduct signed, and keep the signaturesThe artefact auditors sample is the signature list reconciled against the current employee roster. A code of conduct with no acknowledgement records evidences a document, not a control. Tie signing to onboarding and re-affirm annually.
  2. Give people a reporting channel that is genuinely usableA whistleblower or ethics channel needs to allow anonymity and reach someone outside the normal management line. An email address that goes to the person a complaint might be about does not satisfy the intent.
  3. Evidence the evaluation stepThe point of focus most commonly missed is evaluation. Something has to demonstrate that adherence is assessed — performance review criteria that reference conduct, an annual attestation, or a compliance review. Without it you have communicated standards and never checked them.
  4. Keep records of how deviations were handledThis is uncomfortable evidence to prepare because it involves personnel matters, but the auditor does not need names. A redacted log showing that conduct issues were raised, investigated and concluded consistently is sufficient and is far stronger than asserting none occurred.
  5. Cover contractors and partners explicitlyThe criterion extends to outsourced providers and business partners. That usually means a conduct or ethics clause in contracts rather than a signed code, but it needs to exist somewhere.

Common audit findings for CC1.1

What actually gets raised against CC1.1, in rough order of how often it comes up:

Scoping CC1.1

CC1.1 is Common Criteria, so it applies to every SOC 2 engagement without exception. Its evidence sits almost entirely outside the security team — HR, legal and the executive — which is why it is disproportionately often the last evidence to arrive before fieldwork. Start collecting it early.

ISO 27001 mapping

CC1.1 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.1, A.5.4, A.6.2, A.6.6. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC1.1 rather than duplicating work.

Map CC1.1 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC1.1 in the Risk Register.

Other Control Environment criteria

CC1.2 Board independence and oversight CC1.3 Organizational structure and reporting lines CC1.4 Commitment to competence CC1.5 Accountability for internal control

All CC1 Control Environment criteria →

Frequently asked questions

Is CC1.1 required for a SOC 2 report?

Yes. CC1.1 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC1.1?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC1.1 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC1.1 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.

Does SOC 2 CC1.1 map to ISO 27001?

Yes — CC1.1 aligns with ISO 27001:2022 Annex A control(s) A.5.1, A.5.4, A.6.2, A.6.6. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.

What are the most common audit findings for CC1.1?

Code of conduct signature coverage below headcount, usually because it was only ever collected at onboarding and never re-run. An ethics reporting channel that exists in policy but has no owner, no route, and no record of ever being tested.