Change Management Criteria (CC8)
Change Management (CC8) is the part of SOC 2's Security (Common Criteria) category that deals with how an organization makes changes to its systems, software, and processes in a controlled way. It typically calls for changes to be requested, reviewed, tested, and approved before they go live, so that unauthorized or risky modifications are prevented. Because CC8 sits within the required Security category, it is generally assessed in any SOC 2 examination.
CC8 is a category within the SOC 2 Common Criteria (the Security Trust Services Category, which is always in scope) that addresses how an entity manages changes to infrastructure, data, software, and procedures. Its criterion, CC8.1, typically requires that an entity recognize the need for changes, then authorize, design, test, approve, and deploy those changes through a controlled process while preventing or detecting unauthorized changes. The specific evidence and control activities used to satisfy CC8.1 are guided by the associated Points of Focus and depend on the engagement's scope and the auditor's judgment; in a SOC 2 Type II examination, operating effectiveness is evaluated over a defined review period, whereas a Type I addresses suitability of design at a point in time. As part of a SOC 2 examination, CC8 attests only to the controls and period covered and does not constitute a certification, nor does it guarantee freedom from unauthorized changes or breaches.
Why it matters
Changes to systems, software, and procedures are among the most common ways that security controls are unintentionally weakened. An unreviewed configuration change, an untested software deployment, or an unauthorized modification can introduce vulnerabilities, disrupt availability, or expose data, often without anyone noticing until an incident occurs. CC8 exists because a controlled change process is one of the primary defenses against this class of risk, requiring that modifications be recognized, authorized, designed, tested, approved, and deployed in a disciplined way rather than made ad hoc.
For organizations undergoing a SOC 2 examination, CC8 carries particular weight because it sits within the Security category (the Common Criteria), which is always in scope. This means change management is generally assessed in any SOC 2 engagement, regardless of which optional Trust Services Categories an organization selects. Weaknesses in how changes are governed can surface as findings that affect the overall report, making CC8 a criterion that service organizations typically cannot deprioritize.
It is important to keep the boundaries of CC8 in perspective. A SOC 2 report attests only to the controls and the period covered by the examination; it does not certify the organization, nor does it guarantee that no unauthorized change or breach will ever occur. CC8 provides assurance that a controlled change process was suitably designed, and, in a Type II examination, operating effectively over the defined review period, but it is not a warranty against future failures.
Who it's relevant to
Inside CC8
Common questions
Answers to the questions practitioners most commonly ask about CC8.