What's in the report
Every evidence report is structured to answer the questions auditors actually ask. Here is a real one, filled with sample data.
Watermarked PDF · fictional “Sample Company” data · no signup
Vendor Monitoring Report
Q1 2026 Monitoring Period
Alert Delivery Proof
Proof your team was actually notified for each incident. The evidence auditors ask for, and the part a status page can't give them.
| Incident | Channel | Recipient | Status | Latency |
|---|---|---|---|---|
| Stripe · Payments API | oncall@samplecompany.com | Delivered | 2 min | |
| Stripe · Payments API | Slack | #incidents | Delivered | 2 min |
| GitHub · Actions | oncall@samplecompany.com | Delivered | 3 min | |
| GitHub · Actions | PagerDuty | Platform on-call | Delivered | 3 min |
| Cloudflare · CDN / Cache | Webhook | hooks.samplecompany.com | Delivered | 4 min |
Summary
5
Services Monitored
99.97%
Average Uptime
3
Total Incidents
Per-Service Uptime
| Vendor | Component | Uptime | Incidents |
|---|---|---|---|
| AWSCritical | Amazon EC2 (US-East-1) | 100.0% | 0 |
| StripeCritical | Payments API | 99.96% | 1 |
| GitHubHigh | GitHub Actions | 99.90% | 1 |
| CloudflareHigh | CDN / Cache | 99.98% | 1 |
| SlackMedium | Messaging | 100.0% | 0 |
Incident Timeline
Monitoring Methodology
Vendor statuses are polled from official status pages and API health endpoints at 5-30 minute intervals. Incidents are logged with start time, end time, affected components, and severity. Uptime is calculated as the percentage of checks returning operational status over the reporting period. This report is generated automatically by Statusfield and reflects observed status data only.
Your auditor asks: “How do you monitor third-party vendors?”
Most teams give one of these answers. Auditors increasingly ask for ongoing monitoring, not point-in-time spreadsheets.
“We check their status pages manually”
“We have a spreadsheet we update monthly”
“We trust our vendors to tell us when something's wrong”
There's a better answer.
Continuous, automated monitoring with evidence you can hand directly to your auditor.
Continuous vendor monitoring with one-click SOC 2 & ISO evidence
Statusfield watches your vendor stack around the clock and generates a documented monitoring trail on demand.
24/7 Monitoring
Status checks every 5-30 minutes across 7,000+ vendors and tens of thousands of individual components. We check the API, not just the homepage banner. Automated, around the clock, with no manual spot-checks.
Monitoring Evidence
One-click evidence for SOC 2 CC9.2 & ISO 27001 A.5.22: uptime %, incident logs, and monitoring methodology.
Instant Alerts
Email, Slack, Discord, and webhook notifications the moment a vendor goes down.
What does CC9.2 actually require?
CC9.2 is the Vendor and Business Partner Management control within the Common Criteria of the SOC 2 framework. It requires organizations to:
- Identify and assess risks from third-party vendors and business partners
- Establish monitoring activities to track the performance and availability of critical vendors
- Maintain documented evidence of ongoing vendor monitoring for auditor review
- Define processes for responding to vendor service disruptions that affect your own availability commitments
SOC 2 CC9.2: Vendor & Business Partner Risk
The entity assesses and manages risks associated with vendors and business partners. For an availability-focused audit, that means knowing your critical vendors, monitoring their performance, and keeping documented evidence that you did.
How Statusfield maps to CC9.2
CC9.2 Requirement
Identify critical third-party vendors
Statusfield
Build a monitored vendor list from 7,000+ services across infrastructure, payments, communications, and more.
CC9.2 Requirement
Establish ongoing monitoring
Statusfield
Automated status checks run every 5-30 minutes, 24/7, without manual intervention.
CC9.2 Requirement
Document monitoring evidence
Statusfield
Generate a point-in-time monitoring report for any date range with uptime data, incident logs, and methodology.
CC9.2 Requirement
Respond to vendor disruptions
Statusfield
Instant multi-channel alerts ensure your team knows the moment a vendor is affected.
The same evidence covers ISO 27001 A.5.22
Annex A 5.22 (Supplier Service Monitoring) requires organizations to regularly monitor, review and manage changes to supplier service delivery. Auditors look for:
- A supplier inventory covering the services your business depends on
- Ongoing performance evaluation of supplier service delivery
- Incident management with records of supplier service disruptions
- Communication channels that alert your team when a supplier degrades
How Statusfield maps to A.5.22
A.5.22 Requirement
Supplier inventory
Statusfield
Build a monitored supplier list from 7,000+ services across infrastructure, payments, communications, and more.
A.5.22 Requirement
Ongoing performance evaluation
Statusfield
Automated uptime and status checks run every 5-30 minutes, 24/7, with per-supplier history.
A.5.22 Requirement
Records of supplier disruptions
Statusfield
Every supplier disruption is logged with severity, start time, resolution, and affected components.
A.5.22 Requirement
Communication channels
Statusfield
Instant email, Slack, Discord, and webhook alerts the moment a supplier degrades.
Your vendor monitoring report doubles as supplier monitoring evidence. Select the ISO 27001 framing when you generate it and hand your auditor the same uptime data, incident log, and methodology mapped to A.5.22.
What Statusfield covers, and what it doesn't
Vendor management has several parts. We automate the monitoring evidence; your GRC tool or auditor checklist handles the rest.
Statusfield covers
- Continuous vendor uptime and incident monitoring
- Timestamped incident log with severity and duration
- Proof that your team was alerted for each incident
- Vendor inventory with business-impact tiering
- Exportable monitoring reports for your audit period
You still need
- Collecting your vendors' own SOC 2 reports or certificates
- Documented review and sign-off of those reports
- Vendor due diligence before you onboard a new provider
- Contract and DPA tracking for each vendor
- Offboarding and access removal when you drop a vendor
- The rest of your audit (policies, access reviews, etc.)
Already using Vanta or Drata? Statusfield slots in as your continuous monitoring evidence, alongside their document workflows.
Statusfield is not an auditor or a certification body
We produce monitoring evidence that can support your SOC 2 or ISO 27001 audit. We do not certify you, audit you, or make you “SOC 2 compliant” — only a licensed CPA firm can issue a SOC 2 attestation, and only an accredited certification body can issue an ISO 27001 certificate. What we give you is one input your auditor evaluates: a continuous, timestamped record of how your vendors performed and when your team was alerted. Whether it satisfies any particular control is your auditor's call, not ours.
When a vendor won't share their SOC 2 report
Some vendors gate their SOC 2 Type II report behind an enterprise plan or refuse to share it at all. That's a documented exception, not a failed audit — as long as you write it down properly.
First
Ask properly, then exhaust the alternatives
Request the report, check the vendor trust center, and ask about a startup or early-stage exception. Many vendors will share an ISO 27001 certificate or pen test summary when they won’t share SOC 2.
Then
Assemble compensating evidence
Security documentation, DPA and subprocessor list, contractual terms, a shared-responsibility mapping — and a continuous, timestamped record of how the vendor has actually behaved.
Finally
Record the exception
The gap, the residual risk, the compensating controls, a named owner, and a re-review date. An undocumented gap is a finding; a documented one is a risk decision.
Where Statusfield fits: one line of that evidence package — timestamped incident and status history for the vendor, running the length of the period you monitored them, plus the records showing your team was alerted. It's also the only line you can't produce retroactively: you can request a DPA in an afternoon, but you can't go back and observe what a vendor's status page said at 03:00 last February. It supports the compensating-controls field of your exception record. It is not a substitute for the vendor's SOC 2 report, and it says nothing about their internal controls such as encryption or access management.
Read the full walkthrough, including the exception-record templateMonitoring evidence is available on the Team plan
Continuous vendor monitoring evidence for SOC 2 and ISO, generated automatically instead of tracked by hand.
Team
- PDF evidence export for your audit file
- Shareable auditor link, no Statusfield account required
- 90 component monitors
- Email, Slack, Discord, webhooks
- Automated checks every 5-30 minutes
- Component-level monitoring
- Incident history (1-year retention)
Try Team free for 30 days* — no card needed.
Reports unlock after your first 30 days of monitoring history. Auditors need history, not a snapshot.
* Free trial for first-time customers.
Frequently asked questions
- How do you monitor third-party vendors for SOC 2?
- With continuous, automated monitoring instead of point-in-time spreadsheets. Statusfield checks vendor status pages every 5-30 minutes around the clock, logs every outage with severity and duration, and generates documented monitoring reports you can hand directly to your auditor.
- What does SOC 2 CC9.2 actually require?
- CC9.2 is the Vendor and Business Partner Management control within the Common Criteria of the SOC 2 framework. It requires organizations to identify and assess risks from third-party vendors and business partners, establish monitoring activities to track their performance and availability, maintain documented evidence of ongoing monitoring for auditor review, and define processes for responding to vendor service disruptions.
- What is in a vendor monitoring report?
- Per-vendor uptime percentages for your audit period, a timestamped incident log with severity and duration, alert delivery records showing your team was notified, and the monitoring methodology. Reports are exportable as PDF or shareable with auditors via a secure link.
- Does the vendor monitoring report work for ISO 27001?
- Yes. ISO 27001 Annex A 5.22 (Supplier Service Monitoring) requires organizations to regularly monitor, review and manage changes to supplier service delivery. The same vendor monitoring report (uptime data, incident log, alert records, and methodology) can be generated with ISO 27001 framing mapped to A.5.22.
- Does Statusfield replace a compliance platform like Vanta or Drata?
- No. Statusfield produces the continuous monitoring evidence for vendor uptime and incidents, one part of vendor management. You still need your vendors’ own SOC 2 reports or certificates, contract and DPA tracking, and the rest of your audit program. Statusfield slots in alongside your compliance platform and document workflows.
- How do I demonstrate vendor monitoring to an auditor?
- Auditors ask for two things: proof you monitor your critical vendors, and proof your team was actually alerted when something went wrong. Statusfield’s vendor monitoring report covers both — the vendors monitored, a timestamped incident log for the period, and alert-delivery records showing who was notified and when. It’s available on the Team plan and can be shared with your auditor via a secure link, no Statusfield account required.