Skip to content
compliancebase
SOC 2CC4 — Evaluates and Communicates Deficiencies

CC4.2

Evaluates and Communicates Deficiencies

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Assess control deficiencies, communicate them promptly to responsible parties and oversight bodies, and track corrective action.

Points of focus

  • Evaluate severity and aggregate related deficiencies
  • Communicate issues to people able to remediate and oversee
  • Monitor corrective actions until verified closure

Implementation notes

Centralize audit, incident, monitoring, and customer-reported deficiencies in one workflow; set severity-based escalation clocks and require independent retest evidence before closure. Operationalize evaluate severity and aggregate related deficiencies in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain deficiency register with severity, owner, due date, and status with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that audit findings are closed when a ticket is merged without retesting production behavior Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample deficiency register with severity, owner, due date, and status with dates and named reviewers. Be ready to walk through how you detect and correct: audit findings are closed when a ticket is merged without retesting production behavior

Evidence auditors typically request:

  • Deficiency register with severity, owner, due date, and status
  • Escalation records to executives or the board
  • Retest evidence confirming remediation effectiveness

Common gaps

  • Audit findings are closed when a ticket is merged without retesting production behavior
  • Repeated low-rated exceptions are never aggregated into a systemic deficiency

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC4.2This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Evaluates and Communicates Deficiencies applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — evaluate severity and aggregate related deficiencies — with evidence stored where auditors and customers can sample it.

Lead with deficiency register with severity, owner, due date, and status and pair it with escalation records to executives or the board. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because audit findings are closed when a ticket is merged without retesting production behavior Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above