Skip to content
compliancebase
SOC 2CC3 — Specifies Suitable Objectives

CC3.1

Specifies Suitable Objectives

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

State clear, measurable objectives that allow risks to those objectives to be identified and assessed.

Points of focus

  • Align system objectives with customer commitments and applicable obligations
  • Express objectives precisely enough to measure performance
  • Review objectives when strategy, services, or commitments change

Implementation notes

Translate contractual promises into measurable SaaS objectives such as availability, recovery, support access, and vulnerability timelines; link each objective to telemetry and an accountable owner. Operationalize align system objectives with customer commitments and applicable obligations in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved system and security objectives with measurable indicators with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that objectives say only 'keep data secure' and cannot drive a risk assessment Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample approved system and security objectives with measurable indicators with dates and named reviewers. Be ready to walk through how you detect and correct: objectives say only 'keep data secure' and cannot drive a risk assessment

Evidence auditors typically request:

  • Approved system and security objectives with measurable indicators
  • Service commitments mapped to SLOs and control activities
  • Product-planning records showing objective reviews

Common gaps

  • Objectives say only 'keep data secure' and cannot drive a risk assessment
  • New AI or regional services launch without updating system objectives

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC3.1This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Specifies Suitable Objectives applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — align system objectives with customer commitments and applicable obligations — with evidence stored where auditors and customers can sample it.

Lead with approved system and security objectives with measurable indicators and pair it with service commitments mapped to slos and control activities. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because objectives say only 'keep data secure' and cannot drive a risk assessment Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above