The vendor monitoring evidence auditors ask for — mapped to SOC 2 CC9.2 and ISO 27001 A.5.22.

SOC 2 CC9.2 and ISO 27001 A.5.22 both require you to monitor your third-party vendors — and prove it. Statusfield watches 7,000+ vendors around the clock and keeps timestamped incident and status history for the period you monitored them, exportable for your auditor. No reconstructing the week before fieldwork.

Start Monitoring Free

Free plan · No credit card · No trial deadline

Dashboard

Live health across your 36 monitored services

Operational
32
89% of fleet
Degraded
3
needs attention
Down
1
unreachable
Incidents · 7d
1
↑ 1 vs last week
30-day uptime
91.66%

Fleet health

Live
Operational now
89%

32 of 36 services fully operational

32 operational3 degraded1 down
7-day fleet health
100Fri
100Sat
100Sun
100Mon
100Tue
97Wed
97Thu

Active incidents

4 open
StripeMajor Outage
DatadogPartial Outage
CloudflarePartial Outage
VercelDegraded

Services your monitoring evidence needs to cover

…and 7,000+ more in the catalog.

Exportable monitoring evidence

Generate a vendor monitoring report for any date range — per-vendor uptime %, a timestamped incident log with severity and duration, alert-delivery records, and the monitoring methodology. PDF for the file, or a shareable link for your auditor.

Timestamped history you can’t reconstruct later

Statusfield checks your vendors every 5–30 minutes, 24/7, and logs every incident, status change, and recovery as it happens — timestamped, for the length of the period you monitored them. This is the one piece of vendor evidence that can’t be back-filled: you can request a DPA in an afternoon, but you can’t go back and observe what a status page said at 03:00 last February.

7,000+ vendors, one dashboard

Demonstrate coverage across your full third-party stack — cloud, payments, communications, SaaS — down to individual components. Auditors see a complete picture, not a patchwork of status-page subscriptions.

SOC 2 CC9.2 · ISO 27001 A.5.22

The same evidence covers CC9.2 and A.5.22

SOC 2 CC9.2 (Vendor & Business Partner Management) and ISO 27001 A.5.22 (Supplier Service Monitoring) both ask for documented, ongoing vendor monitoring. One report answers both — generate it with either framing.

What the auditor actually gets

Per-vendor uptime %, a timestamped incident log with severity and duration, the alert-delivery records for those incidents, and the monitoring methodology. PDF for the file, or a shareable read-only link for your auditor.

Built for auditor review

Reports unlock after your first 30 days of monitoring history — auditors need a trail, not a snapshot — and cover exactly the period you monitored, stated on the report.

Evidence, not a certificate

Statusfield is not an auditor or a certification body. We produce the vendor-monitoring evidence CC9.2 and A.5.22 ask for — we don’t certify you or make you “SOC 2 compliant”, and we don’t replace Vanta or Drata. Only a licensed CPA firm issues a SOC 2 attestation; only an accredited body issues an ISO 27001 certificate.

Monitoring evidence is available on the Team plan.

Your auditor gets a read-only shareable link — no Statusfield account required.

Share a report with your auditor

Get notified where your team works

Route alerts to the tools you already use, with no context switching.

Email

Instant inbox alerts

Teams

Alerts in Teams channels

Slack

Native OAuth app

PagerDuty

Incidents that auto-resolve

Datadog

Events on your Datadog timeline

Webhooks

Any HTTP endpoint

API & MCP

Wire it into your own tools

Discord

Rich embed alerts

Telegram

Alerts in chats and groups

Common questions

What frameworks does this support?

SOC 2 CC9.2 (Vendor & Business Partner Management), ISO 27001 A.5.22 (Supplier Service Monitoring), and any framework requiring documented third-party monitoring evidence. Generate the report with either framing — the underlying data is the same.

Does Statusfield certify us, or make us SOC 2 compliant?

No. Statusfield is not an auditor or a certification body, and no software can certify you. A SOC 2 attestation is issued by a licensed CPA firm after a formal audit; an ISO 27001 certificate is issued by an accredited certification body. What we produce is one input your auditor evaluates — a continuous, timestamped record of your vendors’ availability, the incidents that occurred, and proof your team was alerted. Whether that satisfies a given control is your auditor’s determination, not ours.

How far back does the data go?

From the moment you add a vendor to your monitor list. Reports unlock after your first 30 days of monitoring history — auditors need a trail, not a snapshot — so the sooner you start, the more of your audit window is covered.

Can I share reports with my auditor directly?

Yes. The Team plan includes a shareable report link — your auditor gets a read-only view of your vendor monitoring data without needing a Statusfield account. You can also export a PDF for the file.

Does this replace a compliance platform like Vanta or Drata?

No. Statusfield produces the continuous monitoring evidence for vendor uptime and incidents — one part of vendor management. You still need your vendors’ own SOC 2 reports or certificates, contract and DPA tracking, and the rest of your audit program. It slots in alongside your compliance platform.

What vendor monitoring evidence does a SOC 2 audit require?

SOC 2 CC9.2 (and ISO 27001 A.5.22) ask for three things: ongoing availability monitoring of your critical subservice organizations and vendors, a record of any incidents during the audit period, and proof your team was actually alerted when they happened. Statusfield produces each — continuous vendor checks, a timestamped incident log, and alert-delivery records — packaged into one report on the Team plan, exportable as PDF or shared with your auditor via a read-only link.

Simple, transparent pricing

Every price on this page is the price you pay: flat, published, and cancellable in one click. Only Business is scoped to you, because multi-team rollouts genuinely differ.

MonthlyYearly
Save with yearly
Starter
$20/mo

One admin covering the whole stack

  • 15 monitors
  • 1 board
  • 150 subscribers
  • 2 seats
ProPopular
$60/mo

Keep staff and clients in the loop

  • 40 monitors
  • 3 boards
  • 600 subscribers
  • 4 seats
Team
$150/mo

When one person can't watch it all

  • 90 monitors
  • 10 boards
  • 1,200 subscribers
  • 8 seats
  • Monitoring evidence
Business
Custom

Multi-team, multi-client, or district-wide vendor monitoring.

  • Custom monitors
  • Custom boards
  • Custom subscribers
  • Custom seats
  • Monitoring evidence

Try any paid plan for 30 days, no credit card required. Free trial for first-time customers.

Don't be the last to know when a service you depend on goes down

Your vendors, your sites, your internal systems. One alert stream, one board, and the receipts to prove it.

Try any paid plan for 30 days, no credit card required. Free trial for first-time customers.

Start Monitoring Free