{
  "node_id": "soc2-cc2-communication-information",
  "title": "AICPA SOC 2 Common Criteria CC2 - Communication and Information (COSO Principles 13-15)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "CC2 is the Communication and Information series of the SOC 2 Common Criteria (COSO Principles 13-15). It requires the entity to obtain or generate and use relevant, quality information to support internal control, to internally communicate information including control objectives and responsibilities, and to communicate with external parties about matters affecting internal control. The three criteria are CC2.1-CC2.3.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 5
}