Evidence collection is where most SOC 2 audits slow down or fail. Not because organizations lack controls — because they can't prove the controls worked across the full observation period. This guide covers what counts as evidence, what each Trust Services Criterion asks for, and where the process breaks down.
Evidence is anything that demonstrates a control was designed correctly and, for Type II engagements, that it operated continuously across the audit period. It takes five main forms:
Written documents describing what your organization does — acceptable use policy, access control policy, incident response plan, vendor management policy. Auditors want the current, ratified version with an effective date.
Point-in-time screenshots or exports proving a control is configured correctly — MFA enabled, password complexity set, encryption at rest confirmed. Timestamps matter; undated screenshots often get rejected.
Access logs, audit trails, change management records. These prove that controls worked over the audit period, not just at a single snapshot. Log completeness and retention period are frequently challenged.
Background check completions, security training acknowledgements, signed confidentiality agreements. Often overlooked until the auditor asks and HR has to reconstruct them from scattered inboxes.
Evidence that risk assessments were conducted, vendor reviews happened, or security exceptions were formally approved. The artifact is usually a document with a date and named approvers.
This is the distinction that determines how much evidence you need to collect and for how long.
Auditor attests that your controls are designed correctly as of a specific date. Evidence is a snapshot — one set of screenshots, policies, and configurations from a single point. Faster to complete (1–3 months), but customers and enterprise procurement increasingly require Type II.
Auditor attests that your controls operated effectively across a defined period — typically 6 or 12 months. Evidence must span the full window, not just the end of it. This means recurring collection: access reviews, log pulls, and training completions at regular intervals throughout the period.
You only include the criteria that apply to your service. The Common Criteria are always in scope. Availability, Confidentiality, Processing Integrity, and Privacy are optional — but frequently required by your customers.
The largest category — 42 criteria covering logical and physical access, system operations, change management, and risk mitigation. Required in every SOC 2 engagement. Typical evidence includes access review exports, MFA screenshots, vulnerability scan reports, and change approval records.
Required if your customers depend on your service being up. Typical evidence includes SLA documentation, uptime monitoring reports, incident response runbooks, and backup verification logs.
Required when you handle data that's classified as confidential under contract or regulation. Typical evidence includes data classification policies, encryption configs, and NDA records with vendors.
Required for services where accuracy and completeness of processing matters — payments, healthcare data, financial reporting. Evidence typically includes input validation controls, reconciliation procedures, and error-handling logs.
Required when you collect personal information. Typical evidence includes a privacy notice, consent records, data subject request procedures, and retention and deletion logs.
Most SOC 2 delays aren't about missing controls. They're about not being able to prove what you already do.
Files scattered across email, Slack, and Dropbox
No single list of what's been collected vs. what's still outstanding. Auditors ask for something you're sure you have — then spend two hours finding it.
Evidence collected once, not across the full period
SOC 2 Type II requires evidence spanning the observation window, not a single snapshot. A policy screenshot from month one doesn't prove the control operated through month six.
No chain of custody
Auditors want to know who attested that this evidence reflects a real control, not just who uploaded a file. An email with a PDF attached provides neither.
Control owners don't know what's expected
The person who owns a control is rarely the person managing the audit. Without a clear request — what's needed, in what format, by when — evidence arrives late and wrong.
One request per control owner — dispatched by email, no account required. They upload directly; you see who hasn't.
Every upload carries a timestamped attestation from the person who owns the control, captured automatically at submission.
Evidence maps to its framework requirements as you upload — TracesOn suggests every other criterion the same artifact likely satisfies across SOC 2 and ISO 27001, and you confirm before it counts.
The audit room keeps a complete, append-only record of every submission, review, and status change — the chain of custody your auditor will ask for.
Related guides