CC1.4 CC1 · Control Environment · Security (Common Criteria)

CC1.4 — Commitment to competence

COSO Principle 4 — The entity demonstrates a commitment to attract, develop, and retain competent individuals aligned with objectives.

Also written as CC 1.4, TSC CC1.4, SOC2 CC1.4, SOC 2 Type 2 CC1.4.

What SOC 2 CC1.4 requires

Commitment to competence is one of 5 criteria in the Control Environment (CC1) series of the Security (Common Criteria) category. COSO Principle 4 — The entity demonstrates a commitment to attract, develop, and retain competent individuals aligned with objectives. CC1 criteria come from the COSO framework rather than from security practice, so the evidence is governance paperwork — charters, minutes, signed acknowledgements — and it usually lives with HR, legal, or the board rather than with the security team.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC1.4, gather artefacts such as:

  • Job descriptions with required qualifications
  • Security training and certification records
  • Performance review process documentation
  • Training budget or professional development plans

ISO 27001 mapping

CC1.4 corresponds to the following ISO 27001:2022 Annex A control(s): A.6.1, A.6.2, A.6.3, A.6.5. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC1.4 rather than duplicating work.

Map CC1.4 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC1.4 in the Risk Register.

Other Control Environment criteria

CC1.1 Integrity and ethical values CC1.2 Board independence and oversight CC1.3 Organizational structure and reporting lines CC1.5 Accountability for internal control

All CC1 Control Environment criteria →

Frequently asked questions

Is CC1.4 required for a SOC 2 report?

Yes. CC1.4 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC1.4?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC1.4 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC1.4 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.

Does SOC 2 CC1.4 map to ISO 27001?

Yes — CC1.4 aligns with ISO 27001:2022 Annex A control(s) A.6.1, A.6.2, A.6.3, A.6.5. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.