Frameworks / SOC 2 / SOC2-A1.1 SOC 2 SOC2-A1.1: A1.1 Managing processing capacity Current processing capacity and the use of infrastructure, data and software are maintained, monitored and evaluated so capacity demand can be managed and extra capacity added in time to meet objectives. Points of focus: usage is measured to set a capacity baseline and judge the risk of impaired availability; average and peak demand are forecast against capacity and tolerances, including capacity lost when components fail; and change management is triggered when forecasts exceed tolerances.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 117 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AU-4 Audit Log Storage Capacity CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1)) MA-6 Timely Maintenance (MA-6) SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-5 Denial-of-Service Protection AU-4 Audit Log Storage Capacity CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1)) MA-6 Timely Maintenance (MA-6) SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-5 Denial-of-Service Protection C5-OPS-01 Capacity Management - Planning C5-OPS-02 Capacity Management - Monitoring C5-OPS-03 Capacity Management - Controlling of Resources C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software 8.2.2 Business impact analysis 8.3.4 Resource requirements 8.3.5 Implementation of solutions 9.1 Monitoring, measurement, analysis and evaluation NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification 5.30 ICT readiness for business continuity 8.14 Redundancy of information processing facilities 8.6 Capacity management PCI-P2PE-11 Business continuity planning and testing PCI-P2PE-12 Disaster recovery procedures PCI-P2PE-14 Critical service identification PCI-PIN-13 Third-party dependency management PCI-PIN-14 Critical service identification PCI-PIN-15 Communication and escalation procedures PCI-SSF-12 Disaster recovery procedures PCI-SSF-14 Critical service identification PCI-SSF-15 Communication and escalation procedures IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.4 Resilience Testing CPS230-19 Tolerance Levels for Each Critical Operation CPS230-P25 Information and Technology Capability and Asset Health CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability CFTC-SS-12 Capacity and Performance Planning Category CFTC-SS-23 Resources Sufficient to Fulfil Obligations CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-8.3 Ensure Adequate Audit Log Storage 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience 8.14 Redundancy of information processing facilities 8.6 Capacity management 27031-8.1 Exercising and Testing 27031-B High availability embedded systems A.4 Resources for AI systems A.4.5 System and computing resources SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) OB-API.4 MI Reporting Specification OB-OPS.1 API Availability Requirements SEMD-CS-3 Cyber Resilience SEMD-ER-1 Emergency Exercise and Testing SOC3-AVAILABILITY Availability Criteria ASD37-20 Multi-factor authentication (Essential) BS65000-RM-03 Leadership and Culture COBIT-BAI04 Managed availability and capacity RMD-1 Reference Data Management CAT-D5-4 Resilience planning and testing 6.9.1 Operational procedures and responsibilities ISO20000-03 Capacity and availability management ISO-25012-4.13 Availability 27007-5.4 Establishing the Programme Resources ITIL4-03 Capacity and availability management Art.21.2.c Business continuity, backup management, disaster recovery and crisis management 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel SASB-BMI-2 Business Model Resilience SOC-CY-A1 Availability Commitments SSAE18-A1.1 A1.1 - Availability Commitments and Requirements UKAI-3 Bias Detection, Fairness, Validation UKOPRES-5 Third-Party Risk, Concentration Risk CERT-1 RRA Certification to EPA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in A - Availability You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-A1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 117 it maps to, and the evidence behind each claim, over MCP and REST.