Skip to main content
Category: Trust Services Criteria

Monitoring Activities Criteria (CC4)

Also known as: CC4, Monitoring of Controls, CC4 Common Criteria, SOC 2 Monitoring Activities
Simply put

CC4 is one of the Common Criteria used in a SOC 2 examination, focused on how an organization keeps an ongoing eye on whether its controls are actually working. It covers evaluating controls over time and fixing any weaknesses that are found. In practice, this means the organization checks its systems and processes on a continuing basis so it can spot problems and understand emerging threats.

Formal definition

CC4, the Monitoring Activities category within the SOC 2 Common Criteria (the required Security category of the Trust Services Criteria), addresses the selection, development, and performance of ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning, as well as the evaluation and communication of identified deficiencies for timely remediation. In most engagements, CC4 is examined across its component points of focus, such as considering a mix of ongoing and separate evaluations, considering the rate of change, establishing a baseline understanding, and using knowledgeable personnel, though the specific application depends on scope and the auditor's judgment. The objective is to provide reasonable assurance that the organization maintains awareness of existing and unfolding threats and that control deficiencies are identified and addressed. CC4 is one category among the Common Criteria and is assessed for suitability of design (Type I) or both design and operating effectiveness over a defined review period (Type II); it should not be conflated with ISO/IEC 27001 Annex A controls or clause requirements, and a SOC 2 report attests only to the controls and period covered rather than guaranteeing freedom from breaches.

Why it matters

Controls are not static, and neither are the threats they are meant to address. CC4 matters because it addresses the gap between having controls on paper and knowing whether those controls are actually operating as intended over time. Without ongoing or separate evaluations, an organization can drift into a state where documented controls have quietly stopped functioning, through configuration changes, staff turnover, or shifts in the underlying systems, long before anyone notices. CC4 is the mechanism by which an organization maintains awareness of existing and unfolding threats and confirms that the other components of its internal control remain present and functioning.

CC4 also matters because it closes the loop between detection and correction. It is not enough to identify a control deficiency; CC4 addresses the evaluation and communication of identified deficiencies so they can be remediated in a timely manner. In a SOC 2 Type II examination, where operating effectiveness is assessed over a defined review period, the presence of a functioning monitoring process is often what allows an organization to demonstrate that deficiencies were caught and addressed rather than left to persist. The rate of change within an environment typically influences how much ongoing versus separate evaluation is warranted.

It is worth being precise about what CC4 does and does not provide. A SOC 2 report attests only to the controls and the period covered; strong monitoring activities support reasonable assurance but do not guarantee freedom from breaches. CC4 is also one category among the Common Criteria and should not be read as a standalone certification or conflated with ISO/IEC 27001 requirements, satisfying CC4 does not, on its own, satisfy any ISO 27001 clause or Annex A control.

Who it's relevant to

Compliance and GRC Managers
Those responsible for preparing an organization for a SOC 2 examination need to establish and document how controls are monitored on a continuing basis and how identified deficiencies are tracked through to remediation. CC4 typically requires evidence that evaluations occur and that findings are communicated to the right people, so GRC managers often own the processes and documentation that demonstrate this over the review period.
Security Engineers and Operations Teams
These teams generally implement and maintain the ongoing evaluations, such as continuous monitoring of systems and processes, that CC4 relies on. They are often the knowledgeable personnel referenced in the points of focus and are typically positioned to detect when a control has stopped functioning as intended, particularly in environments with a high rate of change.
Auditors and Assessors
The CPA firm performing the SOC 2 examination evaluates whether monitoring activities are suitably designed (Type I) or both designed and operating effectively over the defined period (Type II). Auditors apply judgment in how CC4's points of focus are examined and assess whether the organization identifies and communicates deficiencies for timely remediation.
Executive and Risk Leadership
Leaders who rely on the assurance a SOC 2 report provides benefit from understanding that CC4 supports awareness of existing and unfolding threats but does not guarantee freedom from breaches. This helps set accurate expectations about what the report covers and where monitoring investment is warranted based on the organization's rate of change and risk profile.

Inside CC4

Common Criteria Placement
CC4 is one of the criteria groupings within the Security category (the Common Criteria) of the SOC 2 Trust Services Criteria. Because Security is the only required category, CC4 applies in every SOC 2 examination regardless of which optional categories (Availability, Processing Integrity, Confidentiality, Privacy) are also in scope.
Ongoing and Separate Evaluations
CC4 typically addresses how the service organization selects, develops, and performs evaluations to ascertain whether the components of internal control are present and functioning. These commonly include ongoing evaluations built into routine operations and separate evaluations conducted periodically, though the mix depends on scope and the organization's design decisions.
Evaluation and Communication of Deficiencies
CC4 generally concerns evaluating identified control deficiencies and communicating them to parties responsible for corrective action, including senior management and, where appropriate, those charged with governance. The specific channels and thresholds vary by engagement.
Relationship to Type I and Type II Reporting
In a Type I report, monitoring-related controls are assessed for suitability of design at a point in time; in a Type II report, they are assessed for both design and operating effectiveness over a defined review period whose length is set by scoping decisions.

Common questions

Answers to the questions practitioners most commonly ask about CC4.

Does CC4 require a specific security monitoring tool such as a SIEM to be considered satisfied?
No. CC4 addresses the entity's monitoring activities over its system of internal control, and does not mandate any particular technology, product, or tool. In most engagements, an organization can satisfy CC4 through a combination of ongoing evaluations, separate evaluations, and processes for communicating deficiencies. The specific mechanisms depend on scope, the auditor's assessment, and the nature of the environment, so no single tool is inherently required.
Is CC4 the same as the ISO 27001 requirement to monitor and evaluate the ISMS?
They address related themes but are not the same. CC4 is part of the SOC 2 Common Criteria under the Trust Services Criteria and is examined in an attestation performed by a CPA firm. ISO 27001 addresses monitoring, measurement, and evaluation within its clauses 4 through 10 as ISMS requirements, and outcomes are assessed by an accredited certification body. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other.
What kinds of evidence typically demonstrate that CC4 monitoring activities are operating?
Evidence depends on the controls in scope and the review period, but organizations commonly retain records of ongoing and separate evaluations, such as results of internal reviews, control self-assessments, management review outputs, and documentation showing that identified deficiencies were tracked and communicated. In a Type II examination, this evidence typically spans the defined period rather than a single point in time. The sufficiency of any evidence is ultimately assessed by the auditor.
How do ongoing evaluations and separate evaluations differ in practice under CC4?
Ongoing evaluations are typically built into routine operations and occur as part of normal business processes, while separate evaluations are conducted periodically and independently of day-to-day activity. Many organizations use a mix of both, with the balance depending on scope, risk, and the maturity of the control environment. The appropriate mix is a scoping and judgment decision rather than a fixed rule.
How does CC4 relate to the way deficiencies are handled during an engagement?
CC4 generally includes evaluating results of monitoring and communicating identified deficiencies to parties responsible for corrective action. In practice, this means having a process to escalate and track findings so they can be remediated. How deficiencies affect the overall SOC 2 report depends on their nature and the auditor's evaluation; a report attests only to the controls and period covered and does not guarantee freedom from breaches.
Does the required duration of monitoring under CC4 differ between a Type I and a Type II report?
Yes, conceptually. A Type I assesses the suitability of the design of controls at a point in time, so CC4 evidence typically demonstrates that monitoring activities are designed appropriately as of that date. A Type II assesses both design and operating effectiveness over a defined review period, so CC4 evidence is generally expected to show monitoring operating across that period. The period length varies and is set by scoping decisions rather than being fixed.

Common misconceptions

CC4 monitoring controls are the same as ISO 27001's internal audit and management review requirements, so meeting one satisfies the other.
While both frameworks address ongoing evaluation of controls, CC4 is part of the AICPA Trust Services Criteria assessed in a SOC 2 attestation examination, whereas ISO 27001 addresses monitoring through its ISMS requirements in clauses 4 through 10. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
Passing a SOC 2 examination with strong CC4 monitoring controls guarantees the organization will detect and prevent all security incidents.
A SOC 2 report attests only to the controls and the period covered by the examination. Effective monitoring controls under CC4 do not guarantee freedom from breaches or that every deficiency will be detected outside the scope and timeframe of the report.
CC4 mandates a specific set of monitoring tools or a fixed evaluation frequency.
The criteria describe the objectives to be met rather than prescribing particular tools or frequencies. In most engagements, the auditor evaluates whether the chosen approach is suitable for the organization's scope, so appropriate methods and cadence depend on scoping decisions and auditor judgment.

Best practices

Establish a defined mix of ongoing evaluations embedded in routine operations and periodic separate evaluations, sized appropriately for the organization's scope rather than assuming a single mandated cadence.
Document how identified control deficiencies are evaluated, tracked, and communicated to the parties responsible for corrective action, including senior management where appropriate.
For Type II engagements, retain evidence demonstrating that monitoring controls operated consistently throughout the defined review period, not only at a single point in time.
Confirm early with the CPA firm performing the examination how CC4 monitoring activities will be tested and what evidence will be expected, since expectations can vary by engagement and scope.
Where the organization also pursues ISO 27001, coordinate monitoring evidence with the ISMS requirements to reduce duplicated effort, while recognizing that the mapping is partial and each framework must be satisfied on its own terms.
Maintain a clear record of deficiency remediation timelines and outcomes so that the effectiveness of monitoring can be demonstrated over the period covered.