Frameworks / SOC 2 / SOC2-CC4.1 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC4.1: CC4.1 Ongoing and separate evaluations of control (COSO principle 16) The organisation chooses, builds and carries out ongoing or separate evaluations to confirm the control components are present and working. Points of focus: a balance between continuous and point-in-time evaluations; the pace of business change informs their design; a baseline of the control system is established; evaluators understand what they evaluate; ongoing evaluations are built into processes; scope and frequency vary with risk; separate evaluations give objective feedback; and varied techniques are used such as penetration testing, independent certification against a standard and internal audit. The 2022 revision widens the evaluation types to include monitoring and testing by the first line and the second line, internal audit, compliance and resilience assessments, vulnerability scanning, security assessments, penetration tests and assessments by outside parties.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 216 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.7 1.2.7 Six-monthly review of NSC configurations 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2.1 11.3.2.1 External scans after significant change 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 12.1.2 12.1.2 Security policy reviewed annually and updated as needed 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews 12.5.2 12.5.2 Annual and change-driven scope confirmation 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency 6.2.3.1 6.2.3.1 Manual code review independence and approval 7.1.1 7.1.1 Requirement 7 policies and procedures maintained 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically 9.4.1.1 9.4.1.1 Secure storage location for offline backups 9.4.5.1 9.4.5.1 Annual inventories of electronic media 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use 6.4.3 6.4.3 Payment page script management 7.2.4 7.2.4 User accounts and privileges reviewed every six months AC-2 Account Management AC-6(7) Review of User Privileges CA-1 Policy and Procedures CA-2 Control Assessments CA-6 Authorization CA-7 Continuous Monitoring CA-7(1) Independent Assessment CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8 Penetration Testing CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) CP-9(1) Testing for Reliability and Integrity IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2)) PL-1 Policy and Procedures PL-2 System Security and Privacy Plans RA-3 Risk Assessment SI-2(2) Automated Flaw Remediation Status AC-2 Account Management AC-6(7) Review of User Privileges CA-1 Policy and Procedures CA-2 Control Assessments CA-6 Authorization CA-7 Continuous Monitoring CA-7(1) Independent Assessment CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8 Penetration Testing CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) CP-9(1) Testing for Reliability and Integrity IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2)) PL-1 Policy and Procedures PL-2 System Security and Privacy Plans RA-3 Risk Assessment SI-2(2) Automated Flaw Remediation Status 10.1 Nonconformity and corrective action 4.4 Business continuity management system 6.1 Actions to address risks and opportunities 7.5 Documented information 7.5.3 Control of documented information 8.1 Operational planning and control 8.2.1 General 8.3.1 General 8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities 9.1 Monitoring, measurement, analysis and evaluation 9.2 Internal audit 9.2.1 General 9.2.2 Audit programme(s) 9.3.1 General CIS-11.5 Test Data Recovery CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-16.13 Conduct Application Penetration Testing CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.2 Perform Periodic External Penetration Tests CIS-18.4 Validate Security Measures CIS-18.5 Perform Periodic Internal Penetration Tests CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets 5.6.2 Information security risk assessment 5.7 Performance evaluation 5.7.1 Monitoring, measurement, analysis and evaluation 5.7.2 Internal audit 5.8 Improvement 5.8.1 Nonconformity and corrective action 5.8.2 Continual improvement 6.15.2 Information security reviews 6.9.1 Operational procedures and responsibilities 6.9.7 Information systems audit considerations NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.IM-01 Improvements are identified from evaluations NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use 10.1 Continual improvement 4.4 AI management system 8.3 AI risk treatment 9.1 Monitoring, measurement, analysis and evaluation 9.2 Internal audit 9.2.1 General 9.2.2 Internal audit programme 9.3 Management review 5.22 Monitoring, review and change management of supplier services 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.29 Security testing in development and acceptance 8.32 Change management 5.22 Monitoring, review and change management of supplier services 5.28 Collection of evidence 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.32 Change management CPS220-11 Annual Audit Review of the Framework CPS220-18 Triennial Comprehensive Review of the Framework CPS220-P46 Scope of the Comprehensive Review CPS220-P47 Minimum Assessment Required by the Framework Review CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing CPS230-66 Review of Operational Risk Management CPS230-P30 Monitoring, Review and Testing of Control Effectiveness CPS234-22 Systematic Control Testing Program CPS234-25 Internal Audit Review of Information Security Controls CPS234-P30 Independence and Skill of Testing Personnel CPS234-P31 Annual Review of Testing Program Sufficiency C5-COM-02 Policy for planning and conducting audits C5-COM-03 Internal audits of the information security management system C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures ASBv3-GS-5 Define and implement security posture management strategy ASBv3-PV-7 Conduct regular red team operations PV-2 Audit and enforce secure configurations DORA-Art.24 General requirements for the performance of digital operational resilience testing DORA-Art.50 Administrative penalties and remedial measures DORA-Art.6 ICT risk management framework EUAI-Art.17 Quality management system EUAI-Art.43 Conformity assessment EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems 53A-3.1 Prepare for Control Assessments 53A-3.3 Conduct Control Assessments 53A-F Ongoing Assessment and Automation AEO-13 Measurement, Analyses and Improvement P2-S1 Partnership 3.11.5e Assess Effectiveness of Security Solutions 3.12.1e Penetration Testing by Independent Agents E8-APP-ML2 Application Control (ML2) SOC3-MONITORING Monitoring Controls ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC4.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 216 it maps to, and the evidence behind each claim, over MCP and REST.