The vendor monitoring evidence auditors ask for — mapped to SOC 2 CC9.2 and ISO 27001 A.5.22.
SOC 2 CC9.2 and ISO 27001 A.5.22 both require you to monitor your third-party vendors — and prove it. Statusfield watches 7,000+ vendors around the clock and keeps timestamped incident and status history for the period you monitored them, exportable for your auditor. No reconstructing the week before fieldwork.
Free plan · No credit card · No trial deadline
Dashboard
Live health across your 36 monitored services
Fleet health
32 of 36 services fully operational
Active incidents
Services your monitoring evidence needs to cover
Exportable monitoring evidence
Generate a vendor monitoring report for any date range — per-vendor uptime %, a timestamped incident log with severity and duration, alert-delivery records, and the monitoring methodology. PDF for the file, or a shareable link for your auditor.
Timestamped history you can’t reconstruct later
Statusfield checks your vendors every 5–30 minutes, 24/7, and logs every incident, status change, and recovery as it happens — timestamped, for the length of the period you monitored them. This is the one piece of vendor evidence that can’t be back-filled: you can request a DPA in an afternoon, but you can’t go back and observe what a status page said at 03:00 last February.
7,000+ vendors, one dashboard
Demonstrate coverage across your full third-party stack — cloud, payments, communications, SaaS — down to individual components. Auditors see a complete picture, not a patchwork of status-page subscriptions.
The same evidence covers CC9.2 and A.5.22
SOC 2 CC9.2 (Vendor & Business Partner Management) and ISO 27001 A.5.22 (Supplier Service Monitoring) both ask for documented, ongoing vendor monitoring. One report answers both — generate it with either framing.
What the auditor actually gets
Per-vendor uptime %, a timestamped incident log with severity and duration, the alert-delivery records for those incidents, and the monitoring methodology. PDF for the file, or a shareable read-only link for your auditor.
Built for auditor review
Reports unlock after your first 30 days of monitoring history — auditors need a trail, not a snapshot — and cover exactly the period you monitored, stated on the report.
Evidence, not a certificate
Statusfield is not an auditor or a certification body. We produce the vendor-monitoring evidence CC9.2 and A.5.22 ask for — we don’t certify you or make you “SOC 2 compliant”, and we don’t replace Vanta or Drata. Only a licensed CPA firm issues a SOC 2 attestation; only an accredited body issues an ISO 27001 certificate.
Monitoring evidence is available on the Team plan.
Your auditor gets a read-only shareable link — no Statusfield account required.
Share a report with your auditor →Get notified where your team works
Route alerts to the tools you already use, with no context switching.
Instant inbox alerts
Teams
Alerts in Teams channels
Slack
Native OAuth app
PagerDuty
Incidents that auto-resolve
Datadog
Events on your Datadog timeline
Webhooks
Any HTTP endpoint
API & MCP
Wire it into your own tools
Discord
Rich embed alerts
Telegram
Alerts in chats and groups
Common questions
What frameworks does this support?
SOC 2 CC9.2 (Vendor & Business Partner Management), ISO 27001 A.5.22 (Supplier Service Monitoring), and any framework requiring documented third-party monitoring evidence. Generate the report with either framing — the underlying data is the same.
Does Statusfield certify us, or make us SOC 2 compliant?
No. Statusfield is not an auditor or a certification body, and no software can certify you. A SOC 2 attestation is issued by a licensed CPA firm after a formal audit; an ISO 27001 certificate is issued by an accredited certification body. What we produce is one input your auditor evaluates — a continuous, timestamped record of your vendors’ availability, the incidents that occurred, and proof your team was alerted. Whether that satisfies a given control is your auditor’s determination, not ours.
How far back does the data go?
From the moment you add a vendor to your monitor list. Reports unlock after your first 30 days of monitoring history — auditors need a trail, not a snapshot — so the sooner you start, the more of your audit window is covered.
Can I share reports with my auditor directly?
Yes. The Team plan includes a shareable report link — your auditor gets a read-only view of your vendor monitoring data without needing a Statusfield account. You can also export a PDF for the file.
Does this replace a compliance platform like Vanta or Drata?
No. Statusfield produces the continuous monitoring evidence for vendor uptime and incidents — one part of vendor management. You still need your vendors’ own SOC 2 reports or certificates, contract and DPA tracking, and the rest of your audit program. It slots in alongside your compliance platform.
What vendor monitoring evidence does a SOC 2 audit require?
SOC 2 CC9.2 (and ISO 27001 A.5.22) ask for three things: ongoing availability monitoring of your critical subservice organizations and vendors, a record of any incidents during the audit period, and proof your team was actually alerted when they happened. Statusfield produces each — continuous vendor checks, a timestamped incident log, and alert-delivery records — packaged into one report on the Team plan, exportable as PDF or shared with your auditor via a read-only link.
Simple, transparent pricing
Every price on this page is the price you pay: flat, published, and cancellable in one click. Only Business is scoped to you, because multi-team rollouts genuinely differ.
One admin covering the whole stack
- 15 monitors
- 1 board
- 150 subscribers
- 2 seats
Keep staff and clients in the loop
- 40 monitors
- 3 boards
- 600 subscribers
- 4 seats
When one person can't watch it all
- 90 monitors
- 10 boards
- 1,200 subscribers
- 8 seats
- Monitoring evidence
Multi-team, multi-client, or district-wide vendor monitoring.
- Custom monitors
- Custom boards
- Custom subscribers
- Custom seats
- Monitoring evidence
Try any paid plan for 30 days, no credit card required. Free trial for first-time customers.
Don't be the last to know when a service you depend on goes down
Your vendors, your sites, your internal systems. One alert stream, one board, and the receipts to prove it.
Try any paid plan for 30 days, no credit card required. Free trial for first-time customers.
Start Monitoring Free