CC1 is lifted from the COSO internal-control framework rather than from security practice, which is why the evidence feels unlike the rest of a SOC 2: charters, board minutes, signed codes of conduct, background-check records. It is usually owned by HR, legal or the executive team rather than by security, and that split ownership is the most common reason CC1 evidence is late to fieldwork.
CC1 Control Environment contains 5 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.
Yes. CC1 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.
A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.