CC2 Security (Common Criteria) · 3 criteria

SOC 2 CC2 — Communication and Information

CC2 tests whether security-relevant information actually reaches the people who need it, internally and externally. The distinction auditors draw is between publishing and communicating: a policy on an intranet nobody has acknowledged does not satisfy CC2, so distribution lists, acknowledgement records and customer-facing commitments carry the weight here.

All 3 CC2 criteria

CC2.1 Relevant, quality information
COSO Principle 13 — The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
CC2.2 Internal communication
COSO Principle 14 — The entity internally communicates information, including objectives and responsibilities for internal control.
CC2.3 External communication
COSO Principle 15 — The entity communicates with external parties regarding matters affecting the functioning of internal control.

Other criteria series

CC1 CC3 CC4 CC5 CC6 CC7 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC2?

CC2 Communication and Information contains 3 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC2 required in every SOC 2 report?

Yes. CC2 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC2?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.