Skip to main content

Industry standard · United States, used worldwide

What SOC 2 CC9.2 asks of your vendors

Service organisations whose SOC 2 examination includes the common criteria, which every SOC 2 report does. The 2017 criteria with the 2022 revised points of focus are current. AICPA Trust Services Criteria (2017, revised points of focus 2022), CC9.2

Check my vendors

2 requirements that reach your vendors

Each provision, the evidence that usually supports it, and how many vendors in the index publish that evidence. Reviewed 21 Sep 2026.

CC9.2

Assess and manage vendor risk

"The entity assesses and manages risks associated with vendors and business partners."

  • Independent security assurance

    758 vendors in the index

    A current SOC 2 report or ISO/IEC 27001 certificate is the usual evidence that a supplier operates appropriate security measures.

  • Security testing and documentation

    441 vendors in the index

    A penetration test report, a completed standard questionnaire (SIG, CAIQ, HECVAT) or security documentation shows how the supplier tests and runs its controls.

CC9.2, points of focus

Vendor commitments and their monitoring

Points of focus include establishing requirements and commitments for vendors, assessing their performance periodically, and obtaining confidentiality commitments.

  • Data processing agreement

    191 vendors in the index

    The DPA is where processing instructions, confidentiality, security, sub-processing and audit rights are written down.

  • Published subprocessor list

    436 vendors in the index

    A current list of subprocessors, with purpose and location, is how a customer knows who else touches its data.

Vendors publishing the most SOC 2 CC9.2 evidence

Among the most-searched vendors in the index, ranked by how many of the requirements above their public evidence reaches. Open one to see each item with its date and source.

Questions buyers ask

What does SOC 2 CC9.2 require from vendors?

Assess and manage vendor risk (CC9.2); Vendor commitments and their monitoring (CC9.2, points of focus). Each is listed below with the evidence that may support it.

Who does SOC 2 CC9.2 apply to?

Service organisations whose SOC 2 examination includes the common criteria, which every SOC 2 report does. The 2017 criteria with the 2022 revised points of focus are current.

Is a SOC 2 report enough for SOC 2 CC9.2?

A SOC 2 report or ISO 27001 certificate may support the security parts of SOC 2 CC9.2, but vendor commitments and their monitoring need other evidence. Confirm sufficiency with your counsel or auditor.

Other regulations

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.