Skip to content
compliancebase
SOC 2CC1 — Commitment to Competence

CC1.4

Commitment to Competence

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Attract, develop, and retain people with the knowledge and skills needed to perform control responsibilities and meet objectives.

Points of focus

  • Define competence requirements for control-relevant roles
  • Evaluate skills and provide targeted development
  • Plan for succession and coverage of critical responsibilities

Implementation notes

Map critical SaaS duties to required skills, use onboarding labs for production and incident roles, and maintain trained secondary owners for identity, backups, billing, and customer-data operations. Operationalize define competence requirements for control-relevant roles in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain role descriptions with required qualifications with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a newly assigned control owner receives a title but no training or handoff Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample role descriptions with required qualifications with dates and named reviewers. Be ready to walk through how you detect and correct: a newly assigned control owner receives a title but no training or handoff

Evidence auditors typically request:

  • Role descriptions with required qualifications
  • Training plans, completion records, and skills assessments
  • On-call coverage and succession plans for critical SaaS operations

Common gaps

  • A newly assigned control owner receives a title but no training or handoff
  • Only one engineer understands key recovery or deployment procedures

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC1.4This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Commitment to Competence applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — define competence requirements for control-relevant roles — with evidence stored where auditors and customers can sample it.

Lead with role descriptions with required qualifications and pair it with training plans, completion records, and skills assessments. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a newly assigned control owner receives a title but no training or handoff Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above