SOC 2 CC1.4: Commitment to Competence

Reviewed by Ali Aleali, CISSP, CCSP · Last reviewed July 29, 2026

SOC 2 CC1.4 requires an organization to attract, develop, and retain people who are competent to carry out their responsibilities, and to hold outsourced providers and contractors to the same standard. It sits in the CC1 series (Control Environment), and a frequent finding under it is a growing company whose training, background checks, and competence handling are informal and cover only full-time staff, not the contractors who touch the same systems.

CC1.4 at a glance

What does SOC 2 CC1.4 require?

The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (TSC section 100), 2017, revised 2022. © AICPA. Quoted for purposes of commentary and reference.

In plain terms, SOC 2 CC1.4 asks whether the people responsible for security actually have the competence to do the work, and whether the organization has a process to keep it that way. Competence here is not a soft aspiration. It covers hiring the right skills, screening backgrounds before granting access, training people once they are in the role, and planning for what happens when someone in a control-important position leaves.

The criterion maps to COSO Principle 4, which frames competence as a management commitment rather than an individual trait. The organization sets expectations for the skills a role needs, evaluates people against those expectations, and addresses shortcomings when they appear. The Trust Services Criteria then extend that commitment past the payroll boundary: contractors and vendor employees who operate or affect controls are held to the same background and technical-competence standard as staff.

Two ideas carry the whole criterion. The first is that competence is defined and evaluated, not assumed. The second is that the definition includes everyone with access, so a company that trains its employees carefully but lets contractors onboard with no screening or training has met CC1.4 for only part of the population that matters.

What are the CC1.4 points of focus?

The AICPA defines 7 points of focus for CC1.4. Because the Trust Services Criteria are AICPA copyrighted material, the points of focus below are paraphrased and grouped by theme rather than reproduced verbatim; consult the official TSC document for exact wording.

  • Sets competence expectations. The organization establishes policies and practices that state the competence a role requires, so hiring and evaluation have a defined standard to work from.
  • Evaluates competence and addresses gaps. People and teams, including outsourced providers, are evaluated against those expectations, and shortcomings are remedied through training, reassignment, or other action.
  • Attracts, develops, and retains people. The organization mentors and trains individuals to build and keep the competence its objectives need.
  • Plans for succession. Contingency plans exist for control-important roles, so the loss of a key person does not leave a control unstaffed.
  • Considers background (TSC). The background of personnel, contractors, and vendor employees is considered before they are trusted with access.
  • Considers technical competency (TSC). The technical competency of personnel, contractors, and vendor employees is considered for the work they perform.
  • Provides training (TSC). Training, including continuing education, is provided so technical competencies stay current as systems and threats change.

How do you meet CC1.4 in cloud environments?

Cloud-native organizations meet SOC 2 CC1.4 by wiring competence and screening into the same onboarding automation they already run for access:

  • Background checks in onboarding. Pre-hire screening is a gate in the onboarding workflow for both employees and contractors, with the completed check stored against each person's record.
  • Role-based training tracks. Security awareness training is assigned automatically on start date through the HR or GRC platform, with completion tracked and overdue training flagged.
  • Defined skill expectations. Job descriptions and role definitions state the technical and security competencies each role needs, so evaluation has a documented baseline.
  • Continuing education for technical roles. Engineers and security staff have a budget and expectation for certifications or ongoing training, recorded so it is auditable.
  • Contractor parity. Contractor and vendor-employee onboarding runs through the same screening and training gates as staff, rather than a lighter side path.
  • Succession coverage. Control-important cloud roles (for example, the person who owns identity or logging configuration) have a documented backup so the control survives a departure.

How do you meet CC1.4 on-prem?

On-prem and hybrid organizations meet the same criterion through HR and training records rather than platform automation, but the obligations are identical:

  • Documented screening process. A written procedure defines what background screening is done before access is granted, applied consistently to staff and contractors.
  • Scheduled training and records. Security awareness and role-specific training run on a defined cadence, with attendance and completion recorded for every participant.
  • Job descriptions with security duties. Roles that operate controls carry documented security responsibilities and the competencies required to meet them.
  • Skills evaluation in reviews. Performance reviews assess whether people still meet the competence expectations for their role and capture any gaps and the plan to close them.
  • Confidentiality agreements. Personnel and contractors sign confidentiality or non-disclosure agreements before handling sensitive information, with the signed records retained.
  • Documented succession plans. Control-important roles have a named backup and enough documentation that the role can be covered when the incumbent is unavailable.

Cloud vs on-prem at a glance

Point-of-focus theme Cloud implementation On-prem implementation
Screening and background Pre-hire check gated in the onboarding workflow for staff and contractors Written screening procedure applied before access, records retained
Training and competence Awareness and role tracks auto-assigned and completion-tracked in the platform Scheduled training with attendance and completion records
Succession Documented backup owner for control-important cloud roles Named backup and role documentation for control-important roles

What evidence do auditors expect for CC1.4?

Artifact What it demonstrates Cadence
Background-check records for staff and contractors Backgrounds are considered before access is granted Per hire or engagement
Security awareness training completion records Training is provided and competence is maintained At onboarding plus annually
Job descriptions with defined competencies Competence expectations are set for each role Point-in-time, refreshed on change
Signed confidentiality or non-disclosure agreements Personnel and contractors are bound before handling sensitive data Per hire or engagement
Performance reviews and succession plans Competence is evaluated and control-important roles are covered Periodic

A common gap: contractors left outside the competence process

A common gap that comes up during readiness assessments is a company that has scaled past the point where informal competence handling holds, without building a defined process that includes contractors. Compliance workload grows with headcount: every new person needs screening, training, access, and eventually a review, and a team of forty that includes offshore contractors with access to customer data generates far more of that work than a team of ten. Employees usually get covered because HR already touches them, but contractors are brought on through a separate, lighter path with no background check, no assigned training, and no record that either happened. CC1.4 expects competence and background to be considered for personnel and for contractors and vendor employees, so a process that stops at the payroll boundary leaves a visible gap. The remediation is one onboarding and training procedure that applies the same screening, competence expectations, and training records to everyone with access, regardless of whether they are on payroll.

How does CC1.4 map to ISO 27001:2022?

ISO 27001:2022 Annex A controls Overlap type SOC 2 evidence reusable
A 6.1 (screening), A 6.2 (terms and conditions of employment), A 6.3 (awareness, education and training), A 6.6 (confidentiality or non-disclosure agreements) Full Background-check records, security awareness training completion, confidentiality agreements, performance reviews

The overlap is full because ISO 27001 addresses the same people-competence obligations directly through its Annex A people controls, so screening, training, employment terms, and confidentiality agreements built for CC1.4 satisfy the ISO controls with little rework. The SOC 2 to ISO 27001 control mapping covers the full crosswalk across all five Trust Services Categories.

Build competence into onboarding, not around it

Truvo helps you screen, train, and cover control-important roles for staff and contractors alike as part of an effective security program.

Related criteria

CC1.4 follows CC1.3, which establishes the structures, reporting lines, and authorities that CC1.4 then staffs with competent people. It leads into CC1.5, which holds those individuals accountable for the internal control responsibilities their competence is meant to support. Together the three cover who is responsible, whether they are capable, and whether they answer for the result.

Part of Truvo's criterion-by-criterion SOC 2 reference series

Browse every criterion in the Framework Explorer or start from the Trust Services Criteria guide. For a second set of eyes on how your onboarding, training, and contractor screening line up with the criteria as part of an effective security program, Truvo runs scoping calls.

 

Frequently Asked Questions

What does SOC 2 CC1.4 mean?

SOC 2 CC1.4 means an organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with its objectives. In practice it requires defined competence expectations for roles, background screening before access, training that keeps skills current, and succession planning for control-important roles. The commitment extends to contractors and vendor employees, not only full-time staff. It is the fourth criterion in the CC1 Control Environment series and maps to COSO Principle 4.

What evidence satisfies CC1.4?

The core evidence is background-check records for staff and contractors, security awareness training completion records at onboarding and annually, job descriptions that state the competencies each role needs, signed confidentiality or non-disclosure agreements, and performance reviews and succession plans for control-important roles. Together these show that competence is defined, evaluated, and maintained across everyone with access.

Does CC1.4 apply to contractors and vendor employees?

Yes. Three of the seven points of focus specifically extend background consideration, technical-competency consideration, and training to contractors and vendor employees. If a contractor operates or affects a control, they are in scope, and screening and training that cover only employees leave a gap an auditor will find.

How does CC1.4 relate to security awareness training?

Security awareness training is one of the main ways an organization satisfies the develop-and-train and provide-training points of focus. Completion records at onboarding and on an annual cadence, covering both staff and contractors, are standard evidence that competence is being built and kept current.

How is CC1.4 different from CC1.3?

CC1.3 establishes the structures, reporting lines, and authorities that assign responsibility for internal control. CC1.4 asks whether the people placed in those roles are competent to carry the responsibility, and whether the organization keeps them competent through screening, training, and succession planning. CC1.3 defines the roles; CC1.4 staffs them with capable people.

Ready to Start Your Compliance Journey?

Get a clear, actionable roadmap with our readiness assessment.

Share this article:

About the Author

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.

How Ready Are You for SOC 2?

Score your security program in under 5 minutes. Free.

Take the Scorecard
Framework Explorer BETA Browse SOC 2 controls, guidance, and evidence — free.