CC3.1
Specifies Suitable Objectives
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
State clear, measurable objectives that allow risks to those objectives to be identified and assessed.
Points of focus
- Align system objectives with customer commitments and applicable obligations
- Express objectives precisely enough to measure performance
- Review objectives when strategy, services, or commitments change
Implementation notes
Translate contractual promises into measurable SaaS objectives such as availability, recovery, support access, and vulnerability timelines; link each objective to telemetry and an accountable owner. Operationalize align system objectives with customer commitments and applicable obligations in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved system and security objectives with measurable indicators with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that objectives say only 'keep data secure' and cannot drive a risk assessment Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample approved system and security objectives with measurable indicators with dates and named reviewers. Be ready to walk through how you detect and correct: objectives say only 'keep data secure' and cannot drive a risk assessment
Evidence auditors typically request:
- Approved system and security objectives with measurable indicators
- Service commitments mapped to SLOs and control activities
- Product-planning records showing objective reviews
Common gaps
- Objectives say only 'keep data secure' and cannot drive a risk assessment
- New AI or regional services launch without updating system objectives
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC3.1 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus