CC2.1 CC2 · Communication and Information · Security (Common Criteria)

CC2.1 — Relevant, quality information

COSO Principle 13 — The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

Also written as CC 2.1, TSC CC2.1, SOC2 CC2.1, SOC 2 Type 2 CC2.1.

What SOC 2 CC2.1 requires

Relevant, quality information is one of 3 criteria in the Communication and Information (CC2) series of the Security (Common Criteria) category. COSO Principle 13 — The entity obtains or generates and uses relevant, quality information to support the functioning of internal control. CC2 is about whether information actually reaches the people who need it, so auditors look for distribution and acknowledgement records, not just the existence of a document.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC2.1, gather artefacts such as:

  • Data flow diagrams and system descriptions
  • Monitoring dashboards used by control owners
  • Data quality checks on control-relevant reports
  • System-generated reports used in control operation (with completeness/accuracy validation)

ISO 27001 mapping

CC2.1 has no clean one-to-one ISO 27001:2022 Annex A equivalent — it is largely a governance or reporting expectation that ISO 27001 handles through the management-system clauses (4–10) rather than an Annex A control. Treat it as its own requirement rather than assuming ISMS evidence covers it.

Map CC2.1 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC2.1 in the Risk Register.

Other Communication and Information criteria

CC2.2 Internal communication CC2.3 External communication

All CC2 Communication and Information criteria →

Frequently asked questions

Is CC2.1 required for a SOC 2 report?

Yes. CC2.1 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC2.1?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC2.1 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC2.1 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.