SOC 2 CC9.2 · ISO 27001 A.5.22

Vendor Monitoring Evidence

Continuous vendor monitoring evidence for CC9.2 and A.5.22, documented and exportable. 7,000+ vendors watched around the clock.

What's in the report

Every evidence report is structured to answer the questions auditors actually ask. Here is a real one, filled with sample data.

Watermarked PDF · fictional “Sample Company” data · no signup

Vendor Monitoring Report

Q1 2026 Monitoring Period

Alert Delivery Proof

Proof your team was actually notified for each incident. The evidence auditors ask for, and the part a status page can't give them.

IncidentChannelRecipientStatusLatency
Stripe · Payments APIEmailoncall@samplecompany.comDelivered2 min
Stripe · Payments APISlack#incidentsDelivered2 min
GitHub · ActionsEmailoncall@samplecompany.comDelivered3 min
GitHub · ActionsPagerDutyPlatform on-callDelivered3 min
Cloudflare · CDN / CacheWebhookhooks.samplecompany.comDelivered4 min

Summary

5

Services Monitored

99.97%

Average Uptime

3

Total Incidents

Per-Service Uptime

VendorComponentUptimeIncidents
AWSCriticalAmazon EC2 (US-East-1)100.0%0
StripeCriticalPayments API99.96%1
GitHubHighGitHub Actions99.90%1
CloudflareHighCDN / Cache99.98%1
SlackMediumMessaging100.0%0

Incident Timeline

Jan 22, 2026CloudflareCDN / CachePartial Outage28 min
Feb 11, 2026StripePayments APIPartial Outage47 min
Mar 6, 2026GitHubGitHub ActionsMajor Outage2h 11min

Monitoring Methodology

Vendor statuses are polled from official status pages and API health endpoints at 5-30 minute intervals. Incidents are logged with start time, end time, affected components, and severity. Uptime is calculated as the percentage of checks returning operational status over the reporting period. This report is generated automatically by Statusfield and reflects observed status data only.

Export as PDF
Share secure link

Your auditor asks: “How do you monitor third-party vendors?”

Most teams give one of these answers. Auditors increasingly ask for ongoing monitoring, not point-in-time spreadsheets.

We check their status pages manually

We have a spreadsheet we update monthly

We trust our vendors to tell us when something's wrong

There's a better answer.

Continuous, automated monitoring with evidence you can hand directly to your auditor.

Continuous vendor monitoring with one-click SOC 2 & ISO evidence

Statusfield watches your vendor stack around the clock and generates a documented monitoring trail on demand.

24/7 Monitoring

Status checks every 5-30 minutes across 7,000+ vendors and tens of thousands of individual components. We check the API, not just the homepage banner. Automated, around the clock, with no manual spot-checks.

Monitoring Evidence

One-click evidence for SOC 2 CC9.2 & ISO 27001 A.5.22: uptime %, incident logs, and monitoring methodology.

Instant Alerts

Email, Slack, Discord, and webhook notifications the moment a vendor goes down.

SOC 2 Framework

What does CC9.2 actually require?

CC9.2 is the Vendor and Business Partner Management control within the Common Criteria of the SOC 2 framework. It requires organizations to:

  • Identify and assess risks from third-party vendors and business partners
  • Establish monitoring activities to track the performance and availability of critical vendors
  • Maintain documented evidence of ongoing vendor monitoring for auditor review
  • Define processes for responding to vendor service disruptions that affect your own availability commitments

SOC 2 CC9.2: Vendor & Business Partner Risk

The entity assesses and manages risks associated with vendors and business partners. For an availability-focused audit, that means knowing your critical vendors, monitoring their performance, and keeping documented evidence that you did.

Summary of SOC 2 CC9.2 (Vendor & Business Partner Management)

How Statusfield maps to CC9.2

CC9.2 Requirement

Identify critical third-party vendors

Statusfield

Build a monitored vendor list from 7,000+ services across infrastructure, payments, communications, and more.

CC9.2 Requirement

Establish ongoing monitoring

Statusfield

Automated status checks run every 5-30 minutes, 24/7, without manual intervention.

CC9.2 Requirement

Document monitoring evidence

Statusfield

Generate a point-in-time monitoring report for any date range with uptime data, incident logs, and methodology.

CC9.2 Requirement

Respond to vendor disruptions

Statusfield

Instant multi-channel alerts ensure your team knows the moment a vendor is affected.

ISO 27001 Framework

The same evidence covers ISO 27001 A.5.22

Annex A 5.22 (Supplier Service Monitoring) requires organizations to regularly monitor, review and manage changes to supplier service delivery. Auditors look for:

  • A supplier inventory covering the services your business depends on
  • Ongoing performance evaluation of supplier service delivery
  • Incident management with records of supplier service disruptions
  • Communication channels that alert your team when a supplier degrades

How Statusfield maps to A.5.22

A.5.22 Requirement

Supplier inventory

Statusfield

Build a monitored supplier list from 7,000+ services across infrastructure, payments, communications, and more.

A.5.22 Requirement

Ongoing performance evaluation

Statusfield

Automated uptime and status checks run every 5-30 minutes, 24/7, with per-supplier history.

A.5.22 Requirement

Records of supplier disruptions

Statusfield

Every supplier disruption is logged with severity, start time, resolution, and affected components.

A.5.22 Requirement

Communication channels

Statusfield

Instant email, Slack, Discord, and webhook alerts the moment a supplier degrades.

Your vendor monitoring report doubles as supplier monitoring evidence. Select the ISO 27001 framing when you generate it and hand your auditor the same uptime data, incident log, and methodology mapped to A.5.22.

What Statusfield covers, and what it doesn't

Vendor management has several parts. We automate the monitoring evidence; your GRC tool or auditor checklist handles the rest.

Statusfield covers

  • Continuous vendor uptime and incident monitoring
  • Timestamped incident log with severity and duration
  • Proof that your team was alerted for each incident
  • Vendor inventory with business-impact tiering
  • Exportable monitoring reports for your audit period

You still need

  • Collecting your vendors' own SOC 2 reports or certificates
  • Documented review and sign-off of those reports
  • Vendor due diligence before you onboard a new provider
  • Contract and DPA tracking for each vendor
  • Offboarding and access removal when you drop a vendor
  • The rest of your audit (policies, access reviews, etc.)

Already using Vanta or Drata? Statusfield slots in as your continuous monitoring evidence, alongside their document workflows.

Statusfield is not an auditor or a certification body

We produce monitoring evidence that can support your SOC 2 or ISO 27001 audit. We do not certify you, audit you, or make you “SOC 2 compliant” — only a licensed CPA firm can issue a SOC 2 attestation, and only an accredited certification body can issue an ISO 27001 certificate. What we give you is one input your auditor evaluates: a continuous, timestamped record of how your vendors performed and when your team was alerted. Whether it satisfies any particular control is your auditor's call, not ours.

When a vendor won't share their SOC 2 report

Some vendors gate their SOC 2 Type II report behind an enterprise plan or refuse to share it at all. That's a documented exception, not a failed audit — as long as you write it down properly.

First

Ask properly, then exhaust the alternatives

Request the report, check the vendor trust center, and ask about a startup or early-stage exception. Many vendors will share an ISO 27001 certificate or pen test summary when they won’t share SOC 2.

Then

Assemble compensating evidence

Security documentation, DPA and subprocessor list, contractual terms, a shared-responsibility mapping — and a continuous, timestamped record of how the vendor has actually behaved.

Finally

Record the exception

The gap, the residual risk, the compensating controls, a named owner, and a re-review date. An undocumented gap is a finding; a documented one is a risk decision.

Where Statusfield fits: one line of that evidence package — timestamped incident and status history for the vendor, running the length of the period you monitored them, plus the records showing your team was alerted. It's also the only line you can't produce retroactively: you can request a DPA in an afternoon, but you can't go back and observe what a vendor's status page said at 03:00 last February. It supports the compensating-controls field of your exception record. It is not a substitute for the vendor's SOC 2 report, and it says nothing about their internal controls such as encryption or access management.

Read the full walkthrough, including the exception-record template

Monitoring evidence is available on the Team plan

Continuous vendor monitoring evidence for SOC 2 and ISO, generated automatically instead of tracked by hand.

Team

$150/mo
  • PDF evidence export for your audit file
  • Shareable auditor link, no Statusfield account required
  • 90 component monitors
  • Email, Slack, Discord, webhooks
  • Automated checks every 5-30 minutes
  • Component-level monitoring
  • Incident history (1-year retention)

Try Team free for 30 days* — no card needed.

Reports unlock after your first 30 days of monitoring history. Auditors need history, not a snapshot.
* Free trial for first-time customers.

Need monitoring evidence on a different plan? Contact us

Frequently asked questions

How do you monitor third-party vendors for SOC 2?
With continuous, automated monitoring instead of point-in-time spreadsheets. Statusfield checks vendor status pages every 5-30 minutes around the clock, logs every outage with severity and duration, and generates documented monitoring reports you can hand directly to your auditor.
What does SOC 2 CC9.2 actually require?
CC9.2 is the Vendor and Business Partner Management control within the Common Criteria of the SOC 2 framework. It requires organizations to identify and assess risks from third-party vendors and business partners, establish monitoring activities to track their performance and availability, maintain documented evidence of ongoing monitoring for auditor review, and define processes for responding to vendor service disruptions.
What is in a vendor monitoring report?
Per-vendor uptime percentages for your audit period, a timestamped incident log with severity and duration, alert delivery records showing your team was notified, and the monitoring methodology. Reports are exportable as PDF or shareable with auditors via a secure link.
Does the vendor monitoring report work for ISO 27001?
Yes. ISO 27001 Annex A 5.22 (Supplier Service Monitoring) requires organizations to regularly monitor, review and manage changes to supplier service delivery. The same vendor monitoring report (uptime data, incident log, alert records, and methodology) can be generated with ISO 27001 framing mapped to A.5.22.
Does Statusfield replace a compliance platform like Vanta or Drata?
No. Statusfield produces the continuous monitoring evidence for vendor uptime and incidents, one part of vendor management. You still need your vendors’ own SOC 2 reports or certificates, contract and DPA tracking, and the rest of your audit program. Statusfield slots in alongside your compliance platform and document workflows.
How do I demonstrate vendor monitoring to an auditor?
Auditors ask for two things: proof you monitor your critical vendors, and proof your team was actually alerted when something went wrong. Statusfield’s vendor monitoring report covers both — the vendors monitored, a timestamped incident log for the period, and alert-delivery records showing who was notified and when. It’s available on the Team plan and can be shared with your auditor via a secure link, no Statusfield account required.

Ready to make your next audit easier?

Set up continuous vendor monitoring in minutes. Generate compliance reports whenever your auditor asks.