Preparing for a SOC 2 audit is essentially a documentation and evidence gathering challenge. When the audit begins, your CPA firm will provide a Document Request List (DRL) specifying the configuration settings, reports, screenshots, and logs they need to test.

To prevent surprises, you should organize your evidence files around the AICPA Trust Services Criteria (TSC) early. Here is a comprehensive evidence checklist showing what CPAs look for during a SOC 2 audit.


1. CC1 – CC5: Common Criteria (Security)

Security is the mandatory baseline criteria for all SOC 2 audits, covering control environment, risk assessment, information systems, control activities, and monitoring.

Access Control Evidence

  • MFA Configurations: Screenshots from your cloud console (e.g., AWS, GCP, Azure), identity provider (Okta, Entra ID), and source control (GitHub) showing MFA is globally enforced.
  • Access Reviews: Signed check-off sheets or Jira tickets showing manager review of active users quarterly, verifying role-based least privilege.
  • Terminated Personnel: Offboarding checklist showing access deactivated within 24 hours of HR termination logs.

Change Management Evidence

  • Pull Request Approvals: A sample of merged PRs showing at least one peer approval (separate from the author) and successful build pipeline test logs.
  • Pipeline Controls: Configuration screenshots proving developers cannot push code directly to production branches without passing automated checks. (The design of your software pipeline must be formally documented in your SOC 2 System Description Section 3).

Security Operations & Governance

  • Vulnerability Scans: Monthly reports from tools like Nessus, Snyk, or AWS Inspector, proving critical findings are addressed in policy timelines (e.g. 30 days).
  • Risk Assessments: A copy of your annual organizational risk register with computed risk levels and mitigation strategies.
  • Training Logs: Course completion CSV logs showing all employees completed annual security awareness training.

2. CC6: Availability Criteria (Optional)

If scoped, the Availability criteria evaluates how your organization maintains system capacity, handles environmental threats, and recovers from failures.

  • Daily Backups: Logs showing automated daily backups of production databases are running, encrypted, and stored offsite.
  • Backup Restore Drill: Meeting notes or sandbox logs showing a successful backup restoration test was performed within the last 12 months.
  • Disaster Recovery Plan: Documented DR plan alongside tabletop exercise results signed off by leadership annually.
  • System Metrics: Uptime monitoring dashboard reports (e.g., Datadog, Pingdom) showing historical service availability levels.

3. CC7: Confidentiality Criteria (Optional)

Confidentiality governs how sensitive data (such as proprietary intellectual property or customer PII) is identified, classified, and protected.

  • Data Classification Policy: Formal document defining data classes (e.g. Public, Internal, Confidential) and their allowed storage locations.
  • Data Encryption: System configurations proving data is encrypted at rest (e.g., AWS EBS encryption) and in transit (e.g., TLS 1.3 enforced for APIs).
  • Non-Disclosure Agreements (NDAs): A sample of signed NDAs from customers, employees, and suppliers.

Summary of Core Evidence Types

Evidence CategoryExample Files RequiredAudit Frequency
System SettingsCloud console screenshots, IAM configurationsPoint-in-time / Historical
Operational ReviewsQuarterly user list approvals, board meeting minutesRecurring quarterly / annually
Pipeline ArtifactsMerged PRs, automated test runs, approval stampsSample selections (10–25)
HR RecordsBackground check checks, training completion logsSelected samples

Strategic CTA for Compliance Teams

Gathering evidence manually is time-consuming, which is why proper scoping, milestone planning, and readiness checks are so valuable. Understanding your boundaries (see our SOC 2 Audit Timeline Guide for a complete breakdown of phases) ensures you only collect files that are actually in scope.

Learn how we help you map controls and organize your audit readiness: Expert Insights SOC 2 Compliance Services.