COSO Principle 17 — The entity evaluates and communicates internal control deficiencies in a timely manner to parties responsible for corrective action.
Also written as CC 4.2, TSC CC4.2, SOC2 CC4.2, SOC 2 Type 2 CC4.2.
Evaluating and communicating deficiencies is one of 2 criteria in the Monitoring Activities (CC4) series of the Security (Common Criteria) category. COSO Principle 17 — The entity evaluates and communicates internal control deficiencies in a timely manner to parties responsible for corrective action. CC4 is where internal audit, control self-assessment, and remediation tracking are tested; the auditor wants to see that you find your own control failures, not just that you fix the ones they find.
When preparing for a SOC 2 audit against CC4.2, gather artefacts such as:
CC4.2 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.27, A.5.35. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC4.2 rather than duplicating work.
Yes. CC4.2 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC4.2 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.
Yes — CC4.2 aligns with ISO 27001:2022 Annex A control(s) A.5.27, A.5.35. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.