Skip to content
compliancebase
SOC 2CC2 — Communicates Quality Information

CC2.3

Communicates Quality Information

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Communicate complete, accurate, timely information about system objectives, responsibilities, and performance to internal and external stakeholders.

Points of focus

  • Define what information recipients need to make decisions
  • Check information for completeness, accuracy, and timeliness
  • Tailor communication to responsibilities and system commitments

Implementation notes

Give control metrics documented definitions, source queries, scope, owners, and freshness checks; version customer-facing reports and correct material inaccuracies through the same governed communication channel. Operationalize define what information recipients need to make decisions in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain data-quality checks for control and service reporting with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a security metric excludes subsidiaries or environments without disclosure Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample data-quality checks for control and service reporting with dates and named reviewers. Be ready to walk through how you detect and correct: a security metric excludes subsidiaries or environments without disclosure

Evidence auditors typically request:

  • Data-quality checks for control and service reporting
  • Owner-reviewed KPI definitions and dashboard lineage
  • Corrected communications and root-cause records for reporting errors

Common gaps

  • A security metric excludes subsidiaries or environments without disclosure
  • Customer reports use stale data because dashboard refresh failures are not monitored

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC2.3This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Communicates Quality Information applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — define what information recipients need to make decisions — with evidence stored where auditors and customers can sample it.

Lead with data-quality checks for control and service reporting and pair it with owner-reviewed kpi definitions and dashboard lineage. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a security metric excludes subsidiaries or environments without disclosure Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above