SOC 2 guide

SOC 2 evidence collection: what it actually requires

Evidence collection is where most SOC 2 audits slow down or fail. Not because organizations lack controls — because they can't prove the controls worked across the full observation period. This guide covers what counts as evidence, what each Trust Services Criterion asks for, and where the process breaks down.

What counts as SOC 2 evidence

Evidence is anything that demonstrates a control was designed correctly and, for Type II engagements, that it operated continuously across the audit period. It takes five main forms:

Policies & procedures

Written documents describing what your organization does — acceptable use policy, access control policy, incident response plan, vendor management policy. Auditors want the current, ratified version with an effective date.

Configuration screenshots

Point-in-time screenshots or exports proving a control is configured correctly — MFA enabled, password complexity set, encryption at rest confirmed. Timestamps matter; undated screenshots often get rejected.

System-generated logs

Access logs, audit trails, change management records. These prove that controls worked over the audit period, not just at a single snapshot. Log completeness and retention period are frequently challenged.

HR records

Background check completions, security training acknowledgements, signed confidentiality agreements. Often overlooked until the auditor asks and HR has to reconstruct them from scattered inboxes.

Meeting minutes & approvals

Evidence that risk assessments were conducted, vendor reviews happened, or security exceptions were formally approved. The artifact is usually a document with a date and named approvers.

Type I vs Type II: what changes for evidence

This is the distinction that determines how much evidence you need to collect and for how long.

Type I — Point in time

Auditor attests that your controls are designed correctly as of a specific date. Evidence is a snapshot — one set of screenshots, policies, and configurations from a single point. Faster to complete (1–3 months), but customers and enterprise procurement increasingly require Type II.

Type II — Over a period

Auditor attests that your controls operated effectively across a defined period — typically 6 or 12 months. Evidence must span the full window, not just the end of it. This means recurring collection: access reviews, log pulls, and training completions at regular intervals throughout the period.

Evidence by Trust Services Criterion

You only include the criteria that apply to your service. The Common Criteria are always in scope. Availability, Confidentiality, Processing Integrity, and Privacy are optional — but frequently required by your customers.

CCCommon Criteria

The largest category — 42 criteria covering logical and physical access, system operations, change management, and risk mitigation. Required in every SOC 2 engagement. Typical evidence includes access review exports, MFA screenshots, vulnerability scan reports, and change approval records.

AAvailability

Required if your customers depend on your service being up. Typical evidence includes SLA documentation, uptime monitoring reports, incident response runbooks, and backup verification logs.

CConfidentiality

Required when you handle data that's classified as confidential under contract or regulation. Typical evidence includes data classification policies, encryption configs, and NDA records with vendors.

PIProcessing Integrity

Required for services where accuracy and completeness of processing matters — payments, healthcare data, financial reporting. Evidence typically includes input validation controls, reconciliation procedures, and error-handling logs.

PPrivacy

Required when you collect personal information. Typical evidence includes a privacy notice, consent records, data subject request procedures, and retention and deletion logs.

Where evidence collection breaks down

Most SOC 2 delays aren't about missing controls. They're about not being able to prove what you already do.

Files scattered across email, Slack, and Dropbox

No single list of what's been collected vs. what's still outstanding. Auditors ask for something you're sure you have — then spend two hours finding it.

Evidence collected once, not across the full period

SOC 2 Type II requires evidence spanning the observation window, not a single snapshot. A policy screenshot from month one doesn't prove the control operated through month six.

No chain of custody

Auditors want to know who attested that this evidence reflects a real control, not just who uploaded a file. An email with a PDF attached provides neither.

Control owners don't know what's expected

The person who owns a control is rarely the person managing the audit. Without a clear request — what's needed, in what format, by when — evidence arrives late and wrong.

How TracesOn handles evidence collection

One request per control owner — dispatched by email, no account required. They upload directly; you see who hasn't.

Every upload carries a timestamped attestation from the person who owns the control, captured automatically at submission.

Evidence maps to its framework requirements as you upload — TracesOn suggests every other criterion the same artifact likely satisfies across SOC 2 and ISO 27001, and you confirm before it counts.

The audit room keeps a complete, append-only record of every submission, review, and status change — the chain of custody your auditor will ask for.