Frameworks / SOC 2 / SOC2-CC8.1 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC8.1: CC8.1 Managing changes to procedures, software, data and infrastructure Every change to procedures, software, data or infrastructure is authorised, designed or acquired, configured, documented, tested, approved and implemented. Points of focus: changes are managed across the system life cycle; they are authorised before development, designed and developed, documented, tracked before implementation, configured, tested, approved and deployed; the effect on objectives is evaluated through the life cycle; changes needed to remediate incidents are identified and started; a configuration baseline is maintained for IT and control systems; emergency changes follow their own authorise-test-approve path; and confidential and personal information are protected during design, development, testing and change. The 2022 revision adds: segregation of responsibilities so one person cannot develop, test and deploy a change alone; testing of internally developed and acquired changes before production (unit, integration, regression, static and dynamic code analysis, quality assurance or automated testing); a process to identify, assess, test, approve and roll out patches on time; for availability, designing for resilience and testing it during development; and, for privacy, building privacy requirements into design and collecting and processing only the personal information the purpose needs.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 299 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.1 1.2.1 Ruleset configuration standards for NSCs 1.2.2 1.2.2 Network connection and NSC changes under change control 1.2.7 1.2.7 Six-monthly review of NSC configurations 1.2.8 1.2.8 NSC configuration files secured and consistent 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.6.3 10.6.3 Time sync configuration and time data protected 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2.1 11.3.2.1 External scans after significant change 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 11.5.2 11.5.2 Change detection on critical files 11.6.1 11.6.1 Payment page tamper detection 12.5.1 12.5.1 Inventory of in-scope system components 12.6.1 12.6.1 Formal security awareness program 2.2.1 2.2.1 System configuration standards maintained 2.2.4 2.2.4 Only necessary functionality enabled 2.2.5 2.2.5 Insecure services, protocols or daemons secured 2.2.6 2.2.6 System security parameters configured against misuse 2.3.2 2.3.2 Wireless encryption keys changed on triggers 3.7.7 3.7.7 Prevent unauthorized substitution of keys 6.2.1 6.2.1 Secure development of bespoke and custom software 6.2.3 6.2.3 Code review before release 6.2.3.1 6.2.3.1 Manual code review independence and approval 6.2.4 6.2.4 Engineering techniques against common software attacks 6.5.6 6.5.6 Remove test data and accounts before production 8.2.4 8.2.4 User ID lifecycle changes authorized 6.3.2 6.3.2 Inventory of bespoke software and components 6.3.3 6.3.3 Timely installation of security patches 6.4.3 6.4.3 Payment page script management 6.5.1 6.5.1 Change control procedure for production 6.5.2 6.5.2 Confirm PCI DSS controls after significant change 6.5.3 6.5.3 Separate pre-production from production 6.5.4 6.5.4 Separate roles between production and pre-production CA-9 Internal System Connections CM-2 Baseline Configuration CM-2(2) Automation Support for Accuracy and Currency CM-2(3) Retention of Previous Configurations CM-3 Configuration Change Control CM-3(2) Testing, Validation, and Documentation of Changes CM-3(4) Security and Privacy Representatives CM-4 Impact Analyses CM-4(2) Impact Analyses | Verification of Controls (CM-4(2)) CM-5 Access Restrictions for Change CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5)) CM-6(1) Automated Management, Application, and Verification CM-7(1) Periodic Review CM-8(1) Updates During Installation and Removal CM-9 Configuration Management Plan CP-4(1) Coordinate with Related Plans MA-2 Controlled Maintenance MA-3 Maintenance Tools (MA-3) RA-5(2) Update Vulnerabilities to be Scanned SA-10 Developer Configuration Management SA-11 Developer Testing and Evaluation SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2)) SA-22 Unsupported System Components (SA-22) SA-3 System Development Life Cycle SA-8 Security and Privacy Engineering Principles SI-2 Flaw Remediation SI-7 Software, Firmware, and Information Integrity SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2)) CA-9 Internal System Connections CM-2 Baseline Configuration CM-2(2) Automation Support for Accuracy and Currency CM-2(3) Retention of Previous Configurations CM-3 Configuration Change Control CM-3(2) Testing, Validation, and Documentation of Changes CM-3(4) Security and Privacy Representatives CM-4 Impact Analyses CM-4(2) Impact Analyses | Verification of Controls (CM-4(2)) CM-5 Access Restrictions for Change CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5)) CM-6(1) Automated Management, Application, and Verification CM-7(1) Periodic Review CM-8(1) Updates During Installation and Removal CM-9 Configuration Management Plan CP-4(1) Coordinate with Related Plans MA-2 Controlled Maintenance MA-3 Maintenance Tools (MA-3) RA-5(2) Update Vulnerabilities to be Scanned SA-10 Developer Configuration Management SA-11 Developer Testing and Evaluation SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2)) SA-22 Unsupported System Components (SA-22) SA-3 System Development Life Cycle SA-8 Security and Privacy Engineering Principles SI-2 Flaw Remediation SI-7 Software, Firmware, and Information Integrity SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2)) CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-12.3 Securely Manage Network Infrastructure CIS-12.4 Establish and Maintain Architecture Diagram(s) CIS-16.1 Establish and Maintain a Secure Application Development Process CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure CIS-16.8 Separate Production and Non-Production Systems CIS-2.1 Establish and Maintain a Software Inventory CIS-2.2 Ensure Authorized Software is Currently Supported CIS-4.1 Establish and Maintain a Secure Configuration Process CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure CIS-4.6 Securely Manage Enterprise Assets and Software CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-7.2 Establish and Maintain a Remediation Process CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.7 Remediate Detected Vulnerabilities CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients 5.23 Information security for use of cloud services 5.8 Information security in project management 7.13 Equipment maintenance 8.18 Use of privileged utility programs 8.19 Installation of software on operational systems 8.25 Secure development life cycle 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.29 Security testing in development and acceptance 8.30 Outsourced development 8.31 Separation of development, test and production environments 8.32 Change management 8.34 Protection of information systems during audit testing 8.4 Access to source code 8.8 Management of technical vulnerabilities 8.9 Configuration management 5.22 Monitoring, review and change management of supplier services 5.8 Information security in project management 7.13 Equipment maintenance 8.15 Logging 8.19 Installation of software on operational systems 8.25 Secure development life cycle 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.28 Secure coding 8.29 Security testing in development and acceptance 8.31 Separation of development, test and production environments 8.32 Change management 8.34 Protection of information systems during audit testing 8.4 Access to source code 8.8 Management of technical vulnerabilities 8.9 Configuration management 10.1 Continual improvement 7.5 Documented information 7.5.2 Creating and updating documented information 7.5.3 Control of documented information 8.1 Operational planning and control 8.3 AI risk treatment A.6 AI system life cycle A.6.2.3 Documentation of AI system design and development A.6.2.5 AI system deployment A.6.2.6 AI system operation and monitoring NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-ID.IM-01 Improvements are identified from evaluations NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked NIST-CSF-PR.PS-01 Configuration management practices are established and applied NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed 5.6 Operation 5.6.1 Operational planning and control 6.11 Systems acquisition, development and maintenance 6.11.2 Security in development and support processes 6.9 Operations security 6.9.1 Operational procedures and responsibilities 6.9.5 Control of operational software 6.9.7 Information systems audit considerations 8.5.8 Change of subcontractor to process PII SEC01-BP06 Automate deployment of standard security controls SEC11-BP02 Automate testing throughout the development and release lifecycle SEC11-BP04 Conduct code reviews SEC11-BP06 Deploy software programmatically SEC11-BP07 Regularly assess security properties of the pipelines AM-2 Use only approved services ASBv3-DS-3 Secure DevOps infrastructure ASBv3-GS-10 Define and implement DevOps security strategy ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities DS-6 Enforce security of workload throughout DevOps lifecycle CFTC-SS-32 Timely Advance Notice of Material Planned Changes CFTC-SS-4 Systems Operations Category CFTC-SS-5 Systems Development and Quality Assurance Category 6.3 Planning changes to the business continuity management system 7.5.2 Creating and updating 8.3.5 Implementation of solutions EUAI-Art.43 Conformity assessment EUAI-Art.60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes IEC62304-8.2 Change Control IEC62304-9.4 Use Change Control Process SSAE18-CC3.4 CC3.4 - COSO Principle 9: Change Management SSAE18-CC8.1 CC8.1 - Infrastructure and Software Change Management E8-PATCHOS-ML1 Patch Operating Systems (ML1) SOC3-CHANGE-MGT Change Management ANSSI-HYG-34 Define an Update Policy for Information System Components API1164-23 Change management procedures CPS230-9 Management of the Full Range of Operational Risks Clause 10 Change and configuration management AUCDR-IS-4 Formal vulnerability management program BSI-24 Configuration change control FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) IEC62443-23 Change management procedures ISO-26262-8-8 Change management ISO30401-18 Innovation and change management ISO20000-06 Change management processes ISO27019-23 Change management procedures ITIL4-06 Change management processes Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure SASB-BMI-5 Physical Impacts of Climate Change SOC-CY-S3 Change Management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC8.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 299 it maps to, and the evidence behind each claim, over MCP and REST.