CC8 Security (Common Criteria) · 1 criteria

SOC 2 CC8 — Change Management

CC8 is a single criterion covering a very broad surface: every change to infrastructure, software and configuration needs authorisation, testing and approval. Auditors commonly sample changes directly from your ticketing or version-control system, so emergency-change handling and the exceptions to your own process are what get scrutinised.

All 1 CC8 criteria

CC8.1 Change management
Changes to infrastructure, data, software, and procedures are authorized, designed, developed or acquired, configured, documented, tested, approved, and implemented.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC6 CC7 CC9 A1 C1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 CC8?

CC8 Change Management contains 1 criterion. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is CC8 required in every SOC 2 report?

Yes. CC8 is part of the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in.

What is the difference between a Type 1 and Type 2 report for CC8?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.