SOC 2 CC9.2 · ISO 27001 A.5.22

Bring the monitoring record to your audit review

See which vendors you monitored, what changed, and which alerts were delivered. Preview the report before you start collecting evidence for your own review.

Start collecting my evidence

Sample PDF: fictional data, no account required. Your own reports need the Team plan and a workspace that started monitoring at least 30 days ago.

What's in the report

Follow the sample from vendor coverage to an incident and its notification records. The data is fictional; the downloadable PDF uses the same report format available in the product.

Watermarked PDF · fictional “Sample Company” data · no signup

Vendor Monitoring Report

Q1 2026 Monitoring Period

Alert Delivery Proof

See which alerts were delivered, when, and through which channel.

IncidentChannelRecipientStatusLatency
Stripe · Payments APIEmailoncall@samplecompany.comDelivered2 min
Stripe · Payments APISlack#incidentsDelivered2 min
GitHub · ActionsEmailoncall@samplecompany.comDelivered3 min
GitHub · ActionsPagerDutyPlatform on-callDelivered3 min
Cloudflare · CDN / CacheWebhookhooks.samplecompany.comDelivered4 min

Summary

5

Services Monitored

99.97%

Average Uptime

3

Total Incidents

Per-Service Uptime

VendorComponentUptimeIncidents
AWSCriticalAmazon EC2 (US-East-1)100.0%0
StripeCriticalPayments API99.96%1
GitHubHighGitHub Actions99.90%1
CloudflareHighCDN / Cache99.98%1
SlackMediumMessaging100.0%0

Incident Timeline

Jan 22, 2026CloudflareCDN / CachePartial Outage28 min
Feb 11, 2026StripePayments APIPartial Outage47 min
Mar 6, 2026GitHubGitHub ActionsMajor Outage2h 11min

Monitoring Methodology

Vendor statuses are polled from official status pages and API health endpoints. Polling cadence adapts to demand and provider conditions. Incidents are logged with start time, end time, affected components, and severity. Uptime is calculated as the percentage of checks returning operational status over the reporting period. This report is generated automatically by Statusfield and reflects observed status data only.

Export as PDF
Share secure link

From setup to review

Build a record you can explain

Decide what you need to observe before the review period starts. The report organizes your monitoring evidence; your team supplies the risk decisions and response notes around it.

  1. 01

    Define the monitored scope

    Select the vendors and components your controls cover. Record their importance and link the vendor documents your team reviewed.

  2. 02

    Collect and check the record

    Configure alerts, keep monitoring running, and review coverage gaps. Preserve incident tickets separately: a delivered alert does not prove a human responded.

  3. 03

    Export the covered period

    Once your workspace has been monitoring for at least 30 days, select a reporting period within your retained history. Export a PDF or share a read-only report link with the reviewer.

Planning your evidence collection? Use the vendor-monitoring evidence walkthrough.

Monitor vendors. Keep records. Share a report.

Collect records while monitoring runs. Export a report for the period covered.

24/7 Monitoring

Automated status checks across 7,000+ vendors, with cadence adapted to demand and provider conditions. Record reported problems and recovery, including components where supported.

Monitoring Evidence

Export vendor uptime, incident history, alert deliveries, and the monitoring method.

Instant Alerts

Send alerts to your team when a check detects a reported status change.

SOC 2 Framework

Use monitoring records in your SOC 2 review

Monitoring records can support vendor risk reviews. Discuss these parts of your process with your auditor:

  • Identify and assess risks from third-party vendors and business partners
  • Establish monitoring activities to track the performance and availability of critical vendors
  • Maintain documented evidence of ongoing vendor monitoring for auditor review
  • Define processes for responding to vendor service disruptions that affect your own availability commitments

SOC 2 CC9.2: Vendor & Business Partner Risk

Vendor risk management includes more than uptime. Monitoring records show what you observed; your auditor decides how they support your controls.

Monitoring records are one input to vendor risk review

How Statusfield maps to CC9.2

CC9.2 Requirement

Identify critical third-party vendors

Statusfield

Build a monitored vendor list from 7,000+ services across infrastructure, payments, communications, and more.

CC9.2 Requirement

Establish ongoing monitoring

Statusfield

Automated status checks run on an adaptive schedule based on demand and provider conditions.

CC9.2 Requirement

Document monitoring evidence

Statusfield

Export uptime, incidents, and the monitoring method for a covered date range.

CC9.2 Requirement

Respond to vendor disruptions

Statusfield

Alert your team when a check detects a reported vendor problem.

ISO 27001 Framework

Use the same records for ISO 27001 review

Reports also offer A.5.22 framing for supplier monitoring review. Keep records of:

  • A supplier inventory covering the services your business depends on
  • Ongoing performance evaluation of supplier service delivery
  • Incident management with records of supplier service disruptions
  • Communication channels that alert your team when a supplier degrades

How Statusfield maps to A.5.22

A.5.22 Requirement

Supplier inventory

Statusfield

Build a monitored supplier list from 7,000+ services across infrastructure, payments, communications, and more.

A.5.22 Requirement

Ongoing performance evaluation

Statusfield

Automated status checks provide per-supplier history, with cadence adapted to demand and provider conditions.

A.5.22 Requirement

Records of supplier disruptions

Statusfield

Recorded incidents include severity, timing, and affected components when available.

A.5.22 Requirement

Communication channels

Statusfield

Send reported status changes to your team’s alert channels.

Choose ISO 27001 framing when generating the report. Your auditor can review the same uptime, incidents, and monitoring method.

What Statusfield covers, and what it doesn't

Statusfield collects monitoring records. Your audit program still needs vendor reviews, documents, and other controls.

Statusfield covers

  • Continuous vendor uptime and incident monitoring
  • Timestamped incident log with severity and duration
  • Recorded alert deliveries and delivery times
  • Vendor inventory with business-impact tiering
  • Exportable monitoring reports for your audit period

You still need

  • Collecting your vendors' own SOC 2 reports or certificates
  • Documented review and sign-off of those reports
  • Vendor due diligence before you onboard a new provider
  • Contract and DPA tracking for each vendor
  • Offboarding and access removal when you drop a vendor
  • The rest of your audit (policies, access reviews, etc.)

Already using Vanta or Drata? Statusfield slots in as your continuous monitoring evidence, alongside their document workflows.

Statusfield is not an auditor or a certification body

Statusfield provides monitoring records. It does not audit or certify your business. Your auditor decides how those records support your controls.

When a vendor won't share their SOC 2 report

A monitoring report does not replace a vendor’s SOC 2 report. If the vendor will not share one, discuss the gap and next steps with your auditor.

First

Ask for available documentation

Request the report and check the vendor’s trust center for other security documents.

Then

Gather records for review

Bring available security documents, contract terms, and monitoring records to your review.

Finally

Record the exception

Record what is missing, who owns the review, and when to revisit it. Agree on the response with your audit team.

Where Statusfield fits: it provides observed status history and alert delivery records for the period you monitored. These records do not assess the vendor’s internal security controls.

Read the full walkthrough, including the exception-record template

Monitoring evidence is available on the Team plan

Export the monitoring history you have collected as a PDF or shareable report.

Team

$150/mo
  • PDF evidence export for your audit file
  • Shareable auditor link, no Statusfield account required
  • 90 monitors
  • Email, Slack, Discord, webhooks
  • Automated checks with adaptive polling
  • Component-level monitoring
  • Incident history (1-year retention)

Try Team free for 30 days* — no card needed.

Reports become available 30 days after your workspace starts monitoring.
* Free trial for first-time customers.

Need monitoring evidence on a different plan? Contact us

Frequently asked questions

How do you monitor third-party vendors for SOC 2?
Choose the vendors you use. Statusfield records observed status changes and alert deliveries. Export those records for your auditor to review alongside your vendor risk assessment and other controls.
What can I check in the sample report?
Download the sample PDF without an account. It uses fictional Sample Company data to show the report format: vendor inventory, monitoring coverage, recorded incidents, alert delivery records, and methodology. It is not a customer result or a certification.
Can I generate a report as soon as I sign up?
Your workspace needs at least 30 days of monitoring history before reports become available. Reports are a Team-plan feature and cover the data actually retained. Starting today does not create evidence for a period before you monitored the vendors.
Does an alert delivery record prove someone responded?
No. A delivery record documents the notification and its delivery outcome. Keep your tickets, investigation notes, and response decisions alongside the monitoring report to document what your team did.
Does the vendor monitoring report work for ISO 27001?
Reports can use ISO 27001 A.5.22 framing. They contain the same monitoring records, for your auditor to assess alongside your supplier management process. The report alone does not establish compliance.
Does Statusfield replace a compliance platform like Vanta or Drata?
No. Statusfield supplies monitoring records. Keep your compliance platform for vendor documents, contracts, policies, and the rest of your audit work. Your auditor decides what evidence your controls need.
How do I share the report with an auditor?
Export a PDF or create a read-only report link. The recipient does not need a Statusfield account. Anyone with that link can view its report, so share it only with the intended recipients.

Start the record before you need the report

Start collecting vendor monitoring records. Reports become available after 30 days of history on the Team plan.