Security events are evaluated to determine whether they could or have resulted in a failure to meet objectives (security incidents).
Also written as CC 7.3, TSC CC7.3, SOC2 CC7.3, SOC 2 Type 2 CC7.3.
Security event evaluation is one of 5 criteria in the System Operations (CC7) series of the Security (Common Criteria) category. Security events are evaluated to determine whether they could or have resulted in a failure to meet objectives (security incidents). CC7 covers detection and response, so the evidence is operational: monitoring configuration, alert samples, incident tickets with timestamps, and proof that identified issues were actually closed out.
When preparing for a SOC 2 audit against CC7.3, gather artefacts such as:
CC7.3 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.24, A.5.25, A.6.8. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC7.3 rather than duplicating work.
All CC7 System Operations criteria →
Yes. CC7.3 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC7.3 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.
Yes — CC7.3 aligns with ISO 27001:2022 Annex A control(s) A.5.24, A.5.25, A.6.8. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.