COSO Principle 1 — The entity demonstrates a commitment to integrity and ethical values.
Also written as CC 1.1, TSC CC1.1, SOC2 CC1.1, SOC 2 Type 2 CC1.1.
Integrity and ethical values is one of 5 criteria in the Control Environment (CC1) series of the Security (Common Criteria) category. COSO Principle 1 — The entity demonstrates a commitment to integrity and ethical values. CC1 criteria come from the COSO framework rather than from security practice, so the evidence is governance paperwork — charters, minutes, signed acknowledgements — and it usually lives with HR, legal, or the board rather than with the security team.
When preparing for a SOC 2 audit against CC1.1, gather artefacts such as:
The Trust Services Criteria set out points of focus that describe what an auditor considers when assessing CC1.1. They are not themselves requirements, but they shape the testing:
What actually gets raised against CC1.1, in rough order of how often it comes up:
CC1.1 is Common Criteria, so it applies to every SOC 2 engagement without exception. Its evidence sits almost entirely outside the security team — HR, legal and the executive — which is why it is disproportionately often the last evidence to arrive before fieldwork. Start collecting it early.
CC1.1 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.1, A.5.4, A.6.2, A.6.6. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC1.1 rather than duplicating work.
All CC1 Control Environment criteria →
Yes. CC1.1 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC1.1 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.
Yes — CC1.1 aligns with ISO 27001:2022 Annex A control(s) A.5.1, A.5.4, A.6.2, A.6.6. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.
Code of conduct signature coverage below headcount, usually because it was only ever collected at onboarding and never re-run. An ethics reporting channel that exists in policy but has no owner, no route, and no record of ever being tested.