CC4.1 CC4 · Monitoring Activities · Security (Common Criteria)

CC4.1 — Ongoing and separate evaluations

COSO Principle 16 — The entity selects, develops, and performs ongoing and/or separate evaluations of internal control.

Also written as CC 4.1, TSC CC4.1, SOC2 CC4.1, SOC 2 Type 2 CC4.1.

What SOC 2 CC4.1 requires

Ongoing and separate evaluations is one of 2 criteria in the Monitoring Activities (CC4) series of the Security (Common Criteria) category. COSO Principle 16 — The entity selects, develops, and performs ongoing and/or separate evaluations of internal control. CC4 is where internal audit, control self-assessment, and remediation tracking are tested; the auditor wants to see that you find your own control failures, not just that you fix the ones they find.

Audit evidence assessors look for

When preparing for a SOC 2 audit against CC4.1, gather artefacts such as:

  • Internal audit or control self-assessment schedule and reports
  • Continuous monitoring / compliance tooling output
  • Penetration test and vulnerability scan reports
  • Independent assessments (SOC 2, ISO audits)

ISO 27001 mapping

CC4.1 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.22, A.5.35, A.5.36, A.8.29, A.8.34. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC4.1 rather than duplicating work.

Map CC4.1 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against CC4.1 in the Risk Register.

Other Monitoring Activities criteria

CC4.2 Evaluating and communicating deficiencies

All CC4 Monitoring Activities criteria →

Frequently asked questions

Is CC4.1 required for a SOC 2 report?

Yes. CC4.1 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.

How does an auditor test CC4.1?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC4.1 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if CC4.1 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.

Does SOC 2 CC4.1 map to ISO 27001?

Yes — CC4.1 aligns with ISO 27001:2022 Annex A control(s) A.5.22, A.5.35, A.5.36, A.8.29, A.8.34. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.