SOC 2 CC1: control environment evidence
CC1 is the family engineering-led companies score worst on, because none of it is technical and all of it is somebody writing something down.
CC1 has five criteria and every one of them is satisfied by a document rather than a system. It asks whether your company demonstrates a commitment to integrity and ethical values, whether somebody independent of management oversees internal control, whether reporting lines and authorities are defined, whether you hire and keep competent people, and whether individuals are held accountable for their control responsibilities. For a 25 person SaaS company, the whole family is about a week of writing and two hours of a director's time.
5 documents What CC1 costs a company that has none of them yet
What are the five CC1 criteria?
- CC1.1 Integrity and ethical values
- The company demonstrates a commitment to integrity and ethical values. In practice: a code of conduct that every person has acknowledged, and a way to raise a concern that does not go through the person you are concerned about.
- CC1.2 Independent oversight
- The board of directors demonstrates independence from management and exercises oversight of internal control. In practice: minuted evidence that someone who is not the CEO looked at the security program.
- CC1.3 Structure, authority and responsibility
- Management establishes structures, reporting lines, and appropriate authorities and responsibilities. In practice: an org chart and a written statement of who owns security.
- CC1.4 Competence
- The company demonstrates a commitment to attract, develop and retain competent individuals. In practice: job descriptions with security responsibilities in them, background checks where lawful, and training records.
- CC1.5 Accountability
- The company holds individuals accountable for their internal control responsibilities. In practice: security objectives in performance reviews, or a documented consequence for policy violations that has actually been applied.
What if we do not have a board?
Most companies at this size do not have an independent board, and CC1.2 is written as though every entity does. Name the oversight body you actually have and evidence it running. An investor-appointed director, a lead investor, an advisory board, or in the smallest companies a co-founder who is not the person running the security program, all work, as long as the oversight is minuted and periodic.
What does not work is claiming the CEO oversees the CEO. If your entire management team is two people and one of them runs security, say so in the system description, name the compensating arrangement, and hold a quarterly security review with the other co-founder that produces dated notes. An auditor handles a stated limitation very differently from a silent one. The same applies to separation of duties in a small engineering team.
| Criterion | Artifact | Cadence | Who signs it |
|---|---|---|---|
| CC1.1 | Code of conduct, plus acknowledgement records per person | At hire and annually | Every employee and contractor |
| CC1.2 | Minutes of a security review by someone outside management | Quarterly or semi-annual | Director, investor or advisor |
| CC1.3 | Org chart, dated, plus a one-paragraph security ownership statement | Reviewed annually | Management |
| CC1.4 | Job descriptions naming security duties, background check records, training completions | Per hire, plus annual training | Whoever runs hiring |
| CC1.5 | Performance review template with a security line, or a disciplinary process document | Annual | Management |
What gets CC1 evidence sent back?
Four things, in the order they come up.
An undated org chart. The auditor is testing that the structure existed during the observation window, and a chart exported from a tool last Tuesday proves nothing about February. Save a dated PDF at the start of the window and again at the end.
Acknowledgement gaps. CC1.1 is tested by sampling people, so a code of conduct signed by eleven of your thirteen staff is an exception whatever the two people had going on. For the same reason the policy templates page argues for one acknowledgement flow rather than one per document.
Oversight minutes that are a calendar invite. The record has to show attendees, a date, and what was discussed. "Security sync" on a calendar is not a minute.
Background checks that started after the window. You cannot retroactively check somebody hired eighteen months ago and present it as evidence for the window. State the date the practice began, apply it to everyone hired after, and say so in the policy.
What to do this week
0 of 6 done ·
CC1 feeds into CC4, because the oversight body you name here is usually the same forum that receives control deficiencies. Getting the two aligned saves you inventing a second meeting. The common criteria overview has the whole map if you are working through the families in order.
Get CC1 evidence in place without a board
CC1 is where companies without a formal board lose time arguing with an auditor. Send your scope and compare readiness firms that have made this argument before.
Get matchedCommon questions
Does a startup with no board fail CC1.2?
No, as long as you name and evidence an alternative oversight arrangement. Auditors routinely accept an advisory board, a lead investor, or a non-executive co-founder, provided the reviews are periodic and minuted. What fails is having no oversight forum at all, or claiming one that never met during the window.
Are background checks required for SOC 2 in Canada?
SOC 2 does not require them by name. CC1.4 asks that you demonstrate a commitment to competent people, and a background check is the usual evidence. Canadian employment and human rights law limits what you can check and when, so the defensible position is a criminal record check plus reference and identity verification, applied consistently from a stated date and written into the policy.
How many CC1 criteria are there?
Five: CC1.1 through CC1.5. They map to the first five COSO internal control principles, which is why the language sounds like accounting rather than security.
Do contractors need to sign the code of conduct?
If they have access to the system in scope, yes. Auditors build the sample from everyone with access, not from the payroll list, and a contractor with production access who never acknowledged anything is the exception that turns up in almost every first report.