SOC 2 CC1.1: Integrity and Ethical Values

Reviewed by Ali Aleali, CISSP, CCSP · Last reviewed July 29, 2026

SOC 2 CC1.1 requires an organization to demonstrate a commitment to integrity and ethical values, starting with how the board and management behave and reaching every employee, contractor, and vendor who touches the system. It opens the CC1 series (Control Environment) and the Common Criteria as a whole, and a frequent finding under it is a code of conduct that everyone signed once with no record that contractors were ever included or that violations get handled.

CC1.1 at a glance

What does SOC 2 CC1.1 require?

The entity demonstrates a commitment to integrity and ethical values.

AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (TSC section 100), 2017, revised 2022. © AICPA. Quoted for purposes of commentary and reference.

In plain terms, CC1.1 is the foundation the rest of SOC 2 sits on. Every other criterion assumes there are people who will operate controls honestly, report problems truthfully, and follow the rules when nobody is watching. CC1.1 is where an auditor looks for evidence that the organization has set that expectation and backs it up.

CC1.1 maps to COSO Principle 1, the first principle of the Control Environment component. COSO puts it first on purpose: the control environment is the base of the internal control framework, and integrity and ethical values are the base of the control environment. If leadership treats security commitments as optional, no amount of tooling below it holds.

The criterion has a specific shape rather than a general aspiration. It expects the organization to set a standard of conduct, communicate it, check that people actually follow it, and deal with the cases where they do not. It also expects that standard to extend past employees on the payroll to the contractors and vendor personnel who work inside the system, which is where most small and mid-sized teams have the least coverage.

What are the CC1.1 points of focus?

The AICPA defines 5 points of focus for CC1.1. Because the Trust Services Criteria are AICPA copyrighted material, the points of focus below are paraphrased and grouped by theme rather than reproduced verbatim; consult the official TSC document for exact wording.

  • Sets the tone at the top. The board of directors and management model integrity and ethical values through their own directives, actions, and behavior, so the standard is demonstrated rather than only written down.
  • Establishes standards of conduct. Expectations for integrity and ethical values are defined in a code of conduct that is understood at all levels of the organization and by outsourced service providers and business partners.
  • Evaluates adherence to standards. Processes are in place to evaluate the performance of individuals and teams against the expected standards of conduct.
  • Addresses deviations in a timely manner. Deviations from the standards of conduct are identified and remedied consistently and on a timely basis.
  • Considers contractors and vendor employees. The standards of conduct, the evaluation of adherence, and the handling of deviations extend to contractors and vendor personnel, not only direct employees.

How do you meet SOC 2 CC1.1 in cloud environments?

Cloud environments meet CC1.1 by making the code of conduct a live, acknowledged, and enforced document rather than a file in a shared drive:

  • A code of conduct in the GRC or HR platform. The code of conduct and acceptable use policy live in a system such as Vanta, Drata, or an HRIS that timestamps who read and accepted each version, so acknowledgement is a record rather than a memory.
  • Onboarding acknowledgement in the joiner flow. New hires accept the code of conduct as a gated step in onboarding, and the platform blocks access provisioning until they do.
  • Contractor and vendor coverage. Contractors and vendor personnel with system access accept the same standards, either through the platform or through a signed clause in the contract, so the code of conduct reaches everyone who touches the environment.
  • Annual re-acknowledgement. Everyone re-accepts the current version on a set cadence, which is the evidence that the standard is understood at all levels and stays current.
  • A defined path for deviations. A disciplinary or corrective-action process, referenced from the code of conduct, describes how a reported violation is investigated and remedied, so deviations have somewhere to go.

How do you meet SOC 2 CC1.1 on-prem?

On-prem environments meet CC1.1 with the same standards applied through HR and manual records where a compliance platform is not the system of record:

  • A signed code of conduct on file. Each employee signs the code of conduct and acceptable use policy at hire, and the signed copy or acknowledgement is retained in the personnel file.
  • Contractor agreements that carry the standard. Contractor and vendor staff sign the code of conduct or a contract clause that binds them to the same conduct and acceptable use expectations before they get access.
  • Periodic re-acknowledgement. A scheduled review has staff re-sign the current version, with the signed forms kept as the record that the standard was recommunicated.
  • A documented disciplinary process. A written disciplinary or corrective-action procedure defines how violations are assessed and remedied, and completed cases are recorded so the process is demonstrable.
  • Management review of adherence. Adherence to the standards is checked through performance reviews or a periodic management review, with minutes or review records as evidence.

Cloud vs on-prem at a glance

Point-of-focus theme Cloud implementation On-prem implementation
Standards of conduct Code of conduct and AUP in the GRC or HR platform with version history Signed code of conduct and AUP retained in personnel files
Contractor and vendor coverage Same standards accepted in the platform or via contract clause Contractor agreements carry the conduct and acceptable use expectations
Evaluates adherence Acknowledgement reporting plus performance data in the platform Performance reviews and periodic management review with minutes
Addresses deviations Corrective-action workflow referenced from the code of conduct Written disciplinary procedure with completed cases recorded

What evidence do auditors expect for CC1.1?

Artifact What it demonstrates Cadence
Code of conduct and acceptable use policy The standard of conduct is defined and documented Reviewed at least annually
Policy acknowledgement records for employees The standard is communicated to and accepted by staff At hire and annually
Contractor and vendor acknowledgements or contract clauses The standard extends to contractors and vendor personnel At engagement
Disciplinary or corrective-action process Deviations have a defined, consistent path to remediation Point-in-time policy plus per-case records
Board or leadership communications on ethics Tone at the top is set and demonstrated by leadership Periodic

A common gap: a code of conduct signed once, with contractors left out

A common gap that comes up during readiness assessments is a code of conduct that gets treated as a template to sign one time, with no durable record that contractors ever acknowledged it and no evidence that deviations are handled. A team writing policies for the first time often pulls a code of conduct and acceptable use policy from a template, has employees sign it during the initial push, and then leaves it untouched, so the same problem that shows up when policies and procedures are dumped into one document shows up here: the standard exists on paper but nobody can show it is current or that it reaches everyone. The contractor coverage point is where the gap is widest, because contractors and vendor personnel with system access are exactly the people CC1.1 asks about and exactly the people who never got the acknowledgement email. Under SOC 2 the fix is the same discipline that makes evidence collection manageable in the first place: batch the acknowledgements into the onboarding and annual cycles, keep the accepted-version records where an auditor can see them, and include contractors in the same run rather than as an afterthought. That turns the code of conduct from a one-time signature into evidence that the organization sets, communicates, and enforces a standard of conduct.

How does CC1.1 map to ISO 27001:2022?

ISO 27001:2022 Annex A controls Overlap type SOC 2 evidence reusable
A 5.1 (policies for information security), A 5.10 (acceptable use of information and other associated assets), A 6.2 (terms and conditions of employment) Partial Code of conduct, acceptable use policy, policy acknowledgement records

The overlap is partial because ISO 27001 spreads the integrity-and-ethics expectation across policy, acceptable use, and employment-terms controls rather than stating a single commitment-to-integrity clause, and the broader tone-at-the-top expectation sits in Clause 5 (Leadership) in the main body of the standard rather than in Annex A. A code of conduct, an acceptable use policy, and the acknowledgement records that go with them reuse across both frameworks. The SOC 2 to ISO 27001 control mapping covers the full crosswalk across all five Trust Services Categories.

Build a control environment that holds

Truvo helps you set and evidence the standards of conduct at the base of an effective security program.

Related criteria

CC1.1 opens the CC1 Control Environment series and leads into CC1.2, which covers how the board demonstrates independence and exercises oversight of internal control. The code of conduct that CC1.1 establishes is deployed through the wider policy and procedure discipline described under CC5.3, where policies state the expectation and procedures put it into action. Both draw on the same acknowledgement evidence, so the records built for CC1.1 carry forward across the Control Environment and Control Activities criteria.

Part of Truvo's criterion-by-criterion SOC 2 reference series

Browse every criterion in the Framework Explorer or start from the Trust Services Criteria guide. For a second set of eyes on control design before an audit as part of an effective security program, Truvo runs scoping calls.

 

Frequently Asked Questions

What does SOC 2 CC1.1 mean?

SOC 2 CC1.1 requires an organization to demonstrate a commitment to integrity and ethical values. In practice that means setting a standard of conduct through a code of conduct, communicating it so it is understood at all levels including contractors and vendor personnel, evaluating whether people follow it, and remedying deviations on a timely basis. It is the first criterion in the CC1 Control Environment series and maps to COSO Principle 1.

What does CC1 cover in SOC 2?

CC1 is the Control Environment series, the first group in the SOC 2 Common Criteria. It sets the governance foundation the other criteria build on: integrity and ethical values (CC1.1), board independence and oversight (CC1.2), organizational structures and reporting lines (CC1.3), commitment to competence (CC1.4), and accountability for internal control (CC1.5). CC1.1 is where the series starts because the whole framework assumes people will operate controls honestly.

What evidence satisfies CC1.1?

The core evidence is a documented code of conduct and acceptable use policy, acknowledgement records showing employees accepted them at hire and annually, equivalent acknowledgements or contract clauses for contractors and vendor personnel, a disciplinary or corrective-action process for handling deviations, and leadership communications that show tone at the top. Together these show the standard is defined, communicated to everyone who touches the system, and enforced.

Does CC1.1 apply to contractors and vendors?

Yes. One of the five points of focus specifically extends the standards of conduct, the evaluation of adherence, and the handling of deviations to contractors and vendor personnel, not only direct employees. Any contractor or vendor staff member with access to the system in scope should accept the same code of conduct and acceptable use expectations, and that acceptance should be recorded the same way an employee's is.

How is CC1.1 different from CC1.2?

CC1.1 covers the organization's commitment to integrity and ethical values across everyone who touches the system, evidenced through the code of conduct, acknowledgements, and a disciplinary process. CC1.2 covers the board of directors specifically: whether it is independent of management and whether it exercises oversight of internal control. CC1.1 sets the ethical baseline for the whole organization, and CC1.2 focuses on governance at the top.

Ready to Start Your Compliance Journey?

Get a clear, actionable roadmap with our readiness assessment.

Share this article:

About the Author

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.

How Ready Are You for SOC 2?

Score your security program in under 5 minutes. Free.

Take the Scorecard
Framework Explorer BETA Browse SOC 2 controls, guidance, and evidence — free.