IT change management workflow (SOC 2 CC8.1)

A SOC 2-ready IT change management workflow: change request, impact assessment, approval, testing, deployment, post-implementation review — with approval signatures captured per gate.

Use this template

Frequently asked questions

What does SOC 2 CC8.1 require for change management?

CC8.1 (changes affecting the system) requires documented procedures for evaluating, approving, testing, and deploying changes — plus evidence that the procedure was followed for sampled changes during the audit window.

How is QueryChart different from a ticketing system like Jira for change management?

Ticketing systems track individual change tickets; they do not document the controlled current version of the change-management process itself.

What is the difference between a standard, a normal and an emergency change?

A standard change is low-risk, frequent and pre-approved against a documented change model, so it needs no individual approval and goes straight to scheduling. A normal change is anything that has to be assessed and approved on its own merits. An emergency change is one where waiting for the next CAB meeting would do more harm than the change itself, so it gets an expedited approval in an emergency CAB.

Use this template

More in Process flowchart templates

Browse all Change management workflow templates