CC1 Security (Common Criteria) · 5 criteria

SOC 2 CC1 — Control Environment

CC1 is lifted from the COSO internal-control framework rather than from security practice, which is why the evidence feels unlike the rest of a SOC 2: charters, board minutes, signed codes of conduct, background-check records. It is usually owned by HR, legal or the executive team rather than by security, and that split ownership is the most common reason CC1 evidence is late to fieldwork.

All 5 CC1 criteria

CC1.1 Integrity and ethical values
COSO Principle 1 — The entity demonstrates a commitment to integrity and ethical values.
CC1.2 Board independence and oversight
COSO Principle 2 — The board of directors demonstrates independence from management and exercises oversight of internal control.
CC1.3 Organizational structure and reporting lines
COSO Principle 3 — Management establishes structures, reporting lines, and appropriate authorities and responsibilities in pursuit of objectives.
CC1.4 Commitment to competence
COSO Principle 4 — The entity demonstrates a commitment to attract, develop, and retain competent individuals aligned with objectives.
CC1.5 Accountability for internal control
COSO Principle 5 — The entity holds individuals accountable for their internal control responsibilities.

Other criteria series

CC2 CC3 CC4 CC5 CC6 CC7 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC1?

CC1 Control Environment contains 5 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC1 required in every SOC 2 report?

Yes. CC1 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC1?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.