HomeBlog › SOC 2 Evidence List: What Auditors Actually Ask For (With Examples)

SOC 2 evidence list: what auditors actually ask for (with examples)

Published 2026-08-20 · 9 min read · BALTUM

The SOC 2 criteria tell you what must be true; the evidence request list tells you how to prove it. Below is the list most CPA firms send, grouped by area, with notes on what actually satisfies the auditor. Use it to check your readiness before the observation period starts, because evidence you cannot produce for month one cannot be created later.

Governance and policies

  • Information security policy set, approved and dated, with version history.
  • Evidence that staff acknowledged the policies (signed forms or platform exports with dates).
  • Organisation chart, security roles and a management meeting where security was discussed (minutes count).
  • Annual risk assessment with identified risks, owners and treatment decisions.

What does not count: a policy template downloaded last week with no approval date and no reader acknowledgements.

Access control

  • User access list for every in-scope system, exported on a known date (identity provider, cloud console, production database, code repository).
  • MFA enforcement settings, not a statement that "everyone uses MFA".
  • Onboarding and offboarding tickets for a sample of joiners and leavers, with timestamps showing access removed within your policy's deadline.
  • Quarterly access review sign-off: who reviewed, what was removed.
  • Privileged access: list of admins and justification.

Change management and software development

  • Branch protection and required-review settings in your repository.
  • A sample of merged pull requests showing peer review before deployment.
  • CI/CD pipeline configuration showing tests and approvals.
  • Separation between development, staging and production, with evidence that developers cannot deploy unreviewed code to production.

Infrastructure, logging and monitoring

  • Cloud architecture diagram and asset inventory.
  • Encryption at rest and in transit settings (storage, databases, TLS configuration).
  • Centralised logging with retention period, and alerts with a sample of alerts being handled.
  • Vulnerability scanning reports and proof that critical findings were fixed within the policy deadline.
  • Penetration test report from the last 12 months and the remediation tracker.
  • Backup configuration and a documented restore test.

Vendors and subservice organisations

  • Vendor register with risk rating and data accessed.
  • SOC 2 or ISO 27001 reports collected from critical vendors, reviewed and signed off.
  • Contracts or DPAs with security clauses for vendors handling customer data.
  • Decision on carve-out vs inclusive method for your cloud provider, reflected in the system description.

People

  • Background checks (where lawful in your country) or a documented alternative.
  • Security awareness training completion records for all staff in the period.
  • Job descriptions for security roles and signed confidentiality agreements.
  • Performance or disciplinary process references in HR policy.

Incidents and business continuity

  • Incident response plan and at least one tabletop exercise or a real incident post-mortem in the period.
  • Incident register, even if empty, showing the process exists.
  • Business continuity and disaster recovery plan with recovery objectives and a test.
  • Customer communication procedure for security events.

How evidence is sampled in a Type 2

For a Type 2 the auditor does not look at everything. For a control that runs daily they will sample 20–40 instances across the period; for monthly controls, every instance; for quarterly ones, all of them plus proof of timing. The practical consequence: the control must run on schedule throughout the observation period. One missed quarterly access review is an exception in the report.

How BALTUM organises this

During readiness we turn this list into a tracker per control, with an owner, a frequency and a place where evidence lands automatically (identity provider exports, repository settings, ticketing system). By the time the CPA firm sends its request list, most items are already there. The examination itself is performed by an independent, licensed CPA firm; our job is to make sure nothing on this list surprises you. Start with our readiness checklist or ask for a quote.