CC7 Security (Common Criteria) · 5 criteria

SOC 2 CC7 — System Operations

CC7 covers detection and response: monitoring configuration, vulnerability management, incident handling and recovery. The evidence is operational rather than documentary — alert samples, incident tickets with timestamps, and proof that what was detected was actually closed out.

All 5 CC7 criteria

CC7.1 Vulnerability and configuration monitoring
Detection and monitoring procedures are used to identify configuration changes that introduce vulnerabilities and susceptibilities to newly discovered vulnerabilities.
CC7.2 Anomaly and security event monitoring
System components and operations are monitored for anomalies indicative of malicious acts, natural disasters, and errors, and for security events.
CC7.3 Security event evaluation
Security events are evaluated to determine whether they could or have resulted in a failure to meet objectives (security incidents).
CC7.4 Incident response execution
Identified security incidents are responded to through the execution of a defined incident response program.
CC7.5 Incident recovery
Activities are identified, developed, and implemented to recover from identified security incidents.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC6 CC8 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC7?

CC7 System Operations contains 5 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC7 required in every SOC 2 report?

Yes. CC7 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC7?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.