Monitoring Activities Criteria (CC4)
CC4 is one of the Common Criteria used in a SOC 2 examination, focused on how an organization keeps an ongoing eye on whether its controls are actually working. It covers evaluating controls over time and fixing any weaknesses that are found. In practice, this means the organization checks its systems and processes on a continuing basis so it can spot problems and understand emerging threats.
CC4, the Monitoring Activities category within the SOC 2 Common Criteria (the required Security category of the Trust Services Criteria), addresses the selection, development, and performance of ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning, as well as the evaluation and communication of identified deficiencies for timely remediation. In most engagements, CC4 is examined across its component points of focus, such as considering a mix of ongoing and separate evaluations, considering the rate of change, establishing a baseline understanding, and using knowledgeable personnel, though the specific application depends on scope and the auditor's judgment. The objective is to provide reasonable assurance that the organization maintains awareness of existing and unfolding threats and that control deficiencies are identified and addressed. CC4 is one category among the Common Criteria and is assessed for suitability of design (Type I) or both design and operating effectiveness over a defined review period (Type II); it should not be conflated with ISO/IEC 27001 Annex A controls or clause requirements, and a SOC 2 report attests only to the controls and period covered rather than guaranteeing freedom from breaches.
Why it matters
Controls are not static, and neither are the threats they are meant to address. CC4 matters because it addresses the gap between having controls on paper and knowing whether those controls are actually operating as intended over time. Without ongoing or separate evaluations, an organization can drift into a state where documented controls have quietly stopped functioning, through configuration changes, staff turnover, or shifts in the underlying systems, long before anyone notices. CC4 is the mechanism by which an organization maintains awareness of existing and unfolding threats and confirms that the other components of its internal control remain present and functioning.
CC4 also matters because it closes the loop between detection and correction. It is not enough to identify a control deficiency; CC4 addresses the evaluation and communication of identified deficiencies so they can be remediated in a timely manner. In a SOC 2 Type II examination, where operating effectiveness is assessed over a defined review period, the presence of a functioning monitoring process is often what allows an organization to demonstrate that deficiencies were caught and addressed rather than left to persist. The rate of change within an environment typically influences how much ongoing versus separate evaluation is warranted.
It is worth being precise about what CC4 does and does not provide. A SOC 2 report attests only to the controls and the period covered; strong monitoring activities support reasonable assurance but do not guarantee freedom from breaches. CC4 is also one category among the Common Criteria and should not be read as a standalone certification or conflated with ISO/IEC 27001 requirements, satisfying CC4 does not, on its own, satisfy any ISO 27001 clause or Annex A control.
Who it's relevant to
Inside CC4
Common questions
Answers to the questions practitioners most commonly ask about CC4.