CC4 Security (Common Criteria) · 2 criteria

SOC 2 CC4 — Monitoring Activities

CC4 is about whether you find your own control failures. Internal audit results, control self-assessments, monitoring dashboards and remediation tracking all sit here, and the strongest evidence is a documented deficiency that you identified, tracked and closed without the auditor prompting it.

All 2 CC4 criteria

CC4.1 Ongoing and separate evaluations
COSO Principle 16 — The entity selects, develops, and performs ongoing and/or separate evaluations of internal control.
CC4.2 Evaluating and communicating deficiencies
COSO Principle 17 — The entity evaluates and communicates internal control deficiencies in a timely manner to parties responsible for corrective action.

Other criteria series

CC1 CC2 CC3 CC5 CC6 CC7 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC4?

CC4 Monitoring Activities contains 2 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC4 required in every SOC 2 report?

Yes. CC4 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC4?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.