CC2.2
Communicates with External Parties
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Communicate relevant information with customers, regulators, vendors, and other external parties, and provide channels for receiving information from them.
Points of focus
- Provide external parties accurate information about commitments and controls
- Maintain channels for reports, complaints, and security concerns
- Route external information to responsible internal owners
Implementation notes
Maintain owned channels for security reports, privacy requests, status incidents, and vendor notices; define response clocks and ensure customer-facing claims are reviewed against actual production controls. Operationalize provide external parties accurate information about commitments and controls in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain trust center, status page, and customer security communications with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the status page omits a material outage affecting contractual commitments Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample trust center, status page, and customer security communications with dates and named reviewers. Be ready to walk through how you detect and correct: the status page omits a material outage affecting contractual commitments
Evidence auditors typically request:
- Trust center, status page, and customer security communications
- Published vulnerability-reporting channel and triage records
- Vendor notices and customer complaint escalation logs
Common gaps
- The status page omits a material outage affecting contractual commitments
- Security reports sent to a public mailbox are not assigned or tracked
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC2.2 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus