Bring the monitoring record to your audit review
See which vendors you monitored, what changed, and which alerts were delivered. Preview the report before you start collecting evidence for your own review.
Sample PDF: fictional data, no account required. Your own reports need the Team plan and a workspace that started monitoring at least 30 days ago.
What's in the report
Follow the sample from vendor coverage to an incident and its notification records. The data is fictional; the downloadable PDF uses the same report format available in the product.
Watermarked PDF · fictional “Sample Company” data · no signup
Vendor Monitoring Report
Q1 2026 Monitoring Period
Alert Delivery Proof
See which alerts were delivered, when, and through which channel.
| Incident | Channel | Recipient | Status | Latency |
|---|---|---|---|---|
| Stripe · Payments API | oncall@samplecompany.com | Delivered | 2 min | |
| Stripe · Payments API | Slack | #incidents | Delivered | 2 min |
| GitHub · Actions | oncall@samplecompany.com | Delivered | 3 min | |
| GitHub · Actions | PagerDuty | Platform on-call | Delivered | 3 min |
| Cloudflare · CDN / Cache | Webhook | hooks.samplecompany.com | Delivered | 4 min |
Summary
5
Services Monitored
99.97%
Average Uptime
3
Total Incidents
Per-Service Uptime
| Vendor | Component | Uptime | Incidents |
|---|---|---|---|
| AWSCritical | Amazon EC2 (US-East-1) | 100.0% | 0 |
| StripeCritical | Payments API | 99.96% | 1 |
| GitHubHigh | GitHub Actions | 99.90% | 1 |
| CloudflareHigh | CDN / Cache | 99.98% | 1 |
| SlackMedium | Messaging | 100.0% | 0 |
Incident Timeline
Monitoring Methodology
Vendor statuses are polled from official status pages and API health endpoints. Polling cadence adapts to demand and provider conditions. Incidents are logged with start time, end time, affected components, and severity. Uptime is calculated as the percentage of checks returning operational status over the reporting period. This report is generated automatically by Statusfield and reflects observed status data only.
From setup to review
Build a record you can explain
Decide what you need to observe before the review period starts. The report organizes your monitoring evidence; your team supplies the risk decisions and response notes around it.
01
Define the monitored scope
Select the vendors and components your controls cover. Record their importance and link the vendor documents your team reviewed.
02
Collect and check the record
Configure alerts, keep monitoring running, and review coverage gaps. Preserve incident tickets separately: a delivered alert does not prove a human responded.
03
Export the covered period
Once your workspace has been monitoring for at least 30 days, select a reporting period within your retained history. Export a PDF or share a read-only report link with the reviewer.
Planning your evidence collection? Use the vendor-monitoring evidence walkthrough.
Monitor vendors. Keep records. Share a report.
Collect records while monitoring runs. Export a report for the period covered.
24/7 Monitoring
Automated status checks across 7,000+ vendors, with cadence adapted to demand and provider conditions. Record reported problems and recovery, including components where supported.
Monitoring Evidence
Export vendor uptime, incident history, alert deliveries, and the monitoring method.
Instant Alerts
Send alerts to your team when a check detects a reported status change.
Use monitoring records in your SOC 2 review
Monitoring records can support vendor risk reviews. Discuss these parts of your process with your auditor:
- Identify and assess risks from third-party vendors and business partners
- Establish monitoring activities to track the performance and availability of critical vendors
- Maintain documented evidence of ongoing vendor monitoring for auditor review
- Define processes for responding to vendor service disruptions that affect your own availability commitments
SOC 2 CC9.2: Vendor & Business Partner Risk
Vendor risk management includes more than uptime. Monitoring records show what you observed; your auditor decides how they support your controls.
How Statusfield maps to CC9.2
CC9.2 Requirement
Identify critical third-party vendors
Statusfield
Build a monitored vendor list from 7,000+ services across infrastructure, payments, communications, and more.
CC9.2 Requirement
Establish ongoing monitoring
Statusfield
Automated status checks run on an adaptive schedule based on demand and provider conditions.
CC9.2 Requirement
Document monitoring evidence
Statusfield
Export uptime, incidents, and the monitoring method for a covered date range.
CC9.2 Requirement
Respond to vendor disruptions
Statusfield
Alert your team when a check detects a reported vendor problem.
Use the same records for ISO 27001 review
Reports also offer A.5.22 framing for supplier monitoring review. Keep records of:
- A supplier inventory covering the services your business depends on
- Ongoing performance evaluation of supplier service delivery
- Incident management with records of supplier service disruptions
- Communication channels that alert your team when a supplier degrades
How Statusfield maps to A.5.22
A.5.22 Requirement
Supplier inventory
Statusfield
Build a monitored supplier list from 7,000+ services across infrastructure, payments, communications, and more.
A.5.22 Requirement
Ongoing performance evaluation
Statusfield
Automated status checks provide per-supplier history, with cadence adapted to demand and provider conditions.
A.5.22 Requirement
Records of supplier disruptions
Statusfield
Recorded incidents include severity, timing, and affected components when available.
A.5.22 Requirement
Communication channels
Statusfield
Send reported status changes to your team’s alert channels.
Choose ISO 27001 framing when generating the report. Your auditor can review the same uptime, incidents, and monitoring method.
What Statusfield covers, and what it doesn't
Statusfield collects monitoring records. Your audit program still needs vendor reviews, documents, and other controls.
Statusfield covers
- Continuous vendor uptime and incident monitoring
- Timestamped incident log with severity and duration
- Recorded alert deliveries and delivery times
- Vendor inventory with business-impact tiering
- Exportable monitoring reports for your audit period
You still need
- Collecting your vendors' own SOC 2 reports or certificates
- Documented review and sign-off of those reports
- Vendor due diligence before you onboard a new provider
- Contract and DPA tracking for each vendor
- Offboarding and access removal when you drop a vendor
- The rest of your audit (policies, access reviews, etc.)
Already using Vanta or Drata? Statusfield slots in as your continuous monitoring evidence, alongside their document workflows.
Statusfield is not an auditor or a certification body
Statusfield provides monitoring records. It does not audit or certify your business. Your auditor decides how those records support your controls.
When a vendor won't share their SOC 2 report
A monitoring report does not replace a vendor’s SOC 2 report. If the vendor will not share one, discuss the gap and next steps with your auditor.
First
Ask for available documentation
Request the report and check the vendor’s trust center for other security documents.
Then
Gather records for review
Bring available security documents, contract terms, and monitoring records to your review.
Finally
Record the exception
Record what is missing, who owns the review, and when to revisit it. Agree on the response with your audit team.
Where Statusfield fits: it provides observed status history and alert delivery records for the period you monitored. These records do not assess the vendor’s internal security controls.
Read the full walkthrough, including the exception-record templateMonitoring evidence is available on the Team plan
Export the monitoring history you have collected as a PDF or shareable report.
Team
- PDF evidence export for your audit file
- Shareable auditor link, no Statusfield account required
- 90 monitors
- Email, Slack, Discord, webhooks
- Automated checks with adaptive polling
- Component-level monitoring
- Incident history (1-year retention)
Try Team free for 30 days* — no card needed.
Reports become available 30 days after your workspace starts monitoring.
* Free trial for first-time customers.
Frequently asked questions
- How do you monitor third-party vendors for SOC 2?
- Choose the vendors you use. Statusfield records observed status changes and alert deliveries. Export those records for your auditor to review alongside your vendor risk assessment and other controls.
- What can I check in the sample report?
- Download the sample PDF without an account. It uses fictional Sample Company data to show the report format: vendor inventory, monitoring coverage, recorded incidents, alert delivery records, and methodology. It is not a customer result or a certification.
- Can I generate a report as soon as I sign up?
- Your workspace needs at least 30 days of monitoring history before reports become available. Reports are a Team-plan feature and cover the data actually retained. Starting today does not create evidence for a period before you monitored the vendors.
- Does an alert delivery record prove someone responded?
- No. A delivery record documents the notification and its delivery outcome. Keep your tickets, investigation notes, and response decisions alongside the monitoring report to document what your team did.
- Does the vendor monitoring report work for ISO 27001?
- Reports can use ISO 27001 A.5.22 framing. They contain the same monitoring records, for your auditor to assess alongside your supplier management process. The report alone does not establish compliance.
- Does Statusfield replace a compliance platform like Vanta or Drata?
- No. Statusfield supplies monitoring records. Keep your compliance platform for vendor documents, contracts, policies, and the rest of your audit work. Your auditor decides what evidence your controls need.
- How do I share the report with an auditor?
- Export a PDF or create a read-only report link. The recipient does not need a Statusfield account. Anyone with that link can view its report, so share it only with the intended recipients.