SOC 2 Evidence Collection Checklist
Evidence requests are where most SOC 2 examinations lose time, not because the controls don't exist, but because nobody organized proof of them until the auditor asked. Collect this as you go, not the week the observation window closes.
Security (mandatory for every SOC 2)
- Access provisioning and de-provisioning tickets, tied to HR start and end dates
- Quarterly access reviews with documented sign-off, not just a spreadsheet export
- MFA enforcement configuration and evidence it's actually applied to admin accounts
- Change management tickets, request through deployment, for every production change in the window
- Vulnerability scan results with remediation timestamps, not just the raw scan
- Monitoring and alerting configuration, plus a sample of alerts that actually triggered
- Vendor risk assessments for any sub-processor touching customer data
- Security awareness training completion records for the full workforce
If Availability is in scope
- Uptime monitoring records and incident logs for the observation window
- Backup and disaster recovery test results, not just the backup schedule
- Capacity planning documentation showing you monitor before you hit limits
If Confidentiality or Privacy is in scope
- Data classification policy and evidence it's actually applied to real data
- Encryption configuration for data at rest and in transit
- Data retention and secure deletion records
The habit that matters more than the list
A checklist tells you what to collect. What actually determines whether your Type II goes smoothly is when you collect it. Evidence gathered continuously, as controls operate, survives auditor scrutiny. Evidence reconstructed after the fact, no matter how accurate, reads differently to someone trained to spot it. If nothing else, pick one thing from this list today and start collecting it now, not at week ten of a twelve-week window.
Want this collected automatically?
See how GRXForce keeps SOC 2 evidence flowing continuously instead of scrambling at the end.