SOC 2

What evidence is required for SOC 2?

SOC 2 evidence is the proof that your controls operate: security policies, access-control and access-review records, change-management tickets, monitoring and logging output, vendor-management records, incident-response records, and onboarding/offboarding and training records, each tied to the control it supports and kept fresh across the audit period.

Evidence is organized by control

There is no single fixed list; auditors ask for evidence that each of your in-scope controls is designed and operating. In practice that spans policies, records of recurring activities (like access reviews and backups), tickets, and system output.

Typical evidence categories

Approved security policies; access provisioning and periodic access-review records; change-management tickets and approvals; monitoring, logging, and alerting output; vendor due-diligence and review records; incident-response records; and joiner-mover-leaver and security-training records.

Freshness matters for Type II

Because Type II covers a period, evidence must reflect that period. Recurring evidence (quarterly reviews, for example) needs to exist for each cycle, and stale artifacts may not be accepted.

FAQ

Is there an official SOC 2 evidence checklist?

No fixed universal list. Evidence is whatever proves your specific in-scope controls operate against the Trust Services Criteria you selected. A readiness assessment maps controls to the evidence each one needs.

How do I keep SOC 2 evidence current?

Collect it as work happens, tie each artifact to its control, and track expiry so recurring evidence is refreshed on schedule rather than recreated before the audit.

Related

What is evidence collection? → How do I prepare for SOC 2? → SOC 2 evidence kit →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free