CC8 is a single criterion covering a very broad surface: every change to infrastructure, software and configuration needs authorisation, testing and approval. Auditors commonly sample changes directly from your ticketing or version-control system, so emergency-change handling and the exceptions to your own process are what get scrutinised.
CC8 Change Management contains 1 criterion. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.
Yes. CC8 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.
A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.