SOC 2 Evidence by Control: What Auditors Actually Ask For

SOC 2 controls list showing evidence required for each common criteria category

A control-by-control reference for what an auditor will ask to see, and what makes each artifact pass first time.

  • SOC 2
  • Audit evidence
  • Reference

The short answer

Every acceptable artifact is timestamped, attributable, uncropped and dated inside the observation window. Beyond that, evidence differs by control family. The six items at the end of this guide account for most re-evidence requests in first audits.

What makes a SOC 2 control artifact acceptable

Four properties that make an artifact acceptable Timestamped System date and time visible in frame Attributable Shows who produced it and from where Uncropped Full window including URL and user context In period Dated inside the observation window Miss any one of the four and the artifact comes back as a request for re-evidence

CC1 to CC5, governance and risk

ControlWhat to produceWhat makes it pass
CC1.1 integrity and ethicsCode of conduct with acknowledgementsAcknowledgement per person, dated in period
CC1.3 structure and authorityOrg chart, role definitionsVersion dated, showing reporting lines
CC1.4 competenceSecurity training completion recordsPer-person completion with dates, not a course link
CC2.1 information qualityLog and monitoring configurationConfig view plus a sample of retained output
CC3.1 to CC3.3 risk assessmentRisk register, scoring rationale, decisionsEvidence of periodic review, not a static document
CC4.1 monitoring activitiesPenetration test, internal audit outputDated inside the window, with remediation tracked
CC5.1 to CC5.3 control activitiesPolicies mapped to controlsApproval record and review date on each policy

CC6, access control

This family produces more evidence requests than any other, because most of its controls combine a system state with a human decision.

ControlWhat to produceWhat makes it pass
CC6.1 logical accessIdentity provider config, MFA enforcement, user listConsole view matching the export, not the export alone
CC6.2 registrationProvisioning tickets for new joinersRequest, approval and completion linked per person
CC6.3 modification and removalDeprovisioning records for leaversTimestamps showing removal within your stated window
CC6.4 physical accessData centre attestation or office access recordsCloud provider report is normally acceptable here
CC6.6 external threatsFirewall, WAF and network protection configEvidence it is enforcing, not in monitoring mode
CC6.7 transmission and disposalEncryption in transit config, disposal recordsTLS settings plus documented disposal procedure
CC6.8 malicious softwareEndpoint agent coverage reportCoverage reconciled against total device count

CC7 to CC9, operations and change

ControlWhat to produceWhat makes it pass
CC7.1 vulnerability detectionScan output across the periodScans at your stated frequency, no unexplained gaps
CC7.2 monitoring for anomaliesAlert configuration and triage recordsRecords showing somebody reviewed and acted on alerts
CC7.3 evaluation of eventsIncident records with severity assessmentAssessment reasoning, even for events judged minor
CC7.4 incident responseIncident response plan, plus any real incidentsPlan tested or exercised, with a record
CC7.5 recoveryBackup configuration and restore test resultsA completed restore test, not backup success logs
CC8.1 change managementChange records with approvalsApproval separate from the person who made the change
CC9.1 risk mitigationBusiness continuity plan, insuranceReviewed and dated within the period
CC9.2 vendor managementVendor register with risk ratingsSub-processor reports collected and reviewed

Six SOC 2 controls whose evidence fails most often

Access review with no sign-off

A permissions export shows state. The control is that somebody reviewed it and decided. Record the reviewer and the date.

Penetration test outside the window

A test dated before the period opened does not evidence operation during it. Schedule early in the window.

Inventory that will not reconcile

Device count against headcount is the first thing checked. Reconcile before fieldwork or expect questions.

Approvals living in chat

Retrievable in month one, painful in month nine. Approvals in the change system survive sampling.

Backups with no restore test

Successful backup jobs are not recovery evidence. The restore test is the control.

One snapshot for a whole period

A Type II tests operation over time. A single dated image evidences a single date.

How Osto reduces the pile

The controls that create the most evidence work, access, endpoint coverage, vulnerability detection, change and web protection, all run inside Osto. Because the controls and the compliance mapping share a platform, the artifact is generated by the system enforcing the control rather than reconstructed afterwards from an API read of a separate product.

Governance evidence stays yours. Risk decisions, policy approvals and review sign-offs are human judgments and no platform produces them for you.

See which controls produce clean evidence today

A free assessment maps your controls to their evidence sources and flags the ones that will generate re-evidence requests.

Frequently asked questions

What evidence do I need for SOC 2?

Evidence varies by control, but every artifact needs four properties: a visible system timestamp, attribution showing who produced it and from where, an uncropped view including URL and user context, and a date inside the observation window. Missing any one of the four is the most common reason evidence is returned.

What is the most common SOC 2 evidence mistake?

Submitting a single snapshot as proof that a control operated across an entire period. A Type II examines operation over time, and auditors sample dates across the window. One screenshot demonstrates one moment, not a period.

Do access reviews need manager sign-off?

In practice, yes. An export of current permissions shows state. The control being tested is that somebody with authority reviewed that state and made a decision. Without recorded sign-off, you have evidence of configuration rather than evidence of review.

Does a penetration test have to fall inside the observation window?

It should. A test dated before the window opened generally does not evidence that the control operated during the period under examination. Scheduling the test early in the window, leaving time to remediate and retest, avoids the problem.

Why does my asset inventory keep getting questioned?

Because it usually does not reconcile against another source. If your device management console lists forty five machines and HR lists sixty people, an auditor will ask about the difference. Reconciling the two before fieldwork removes an entire round of questions.

Are approvals in Slack acceptable as evidence?

Sometimes, if the message shows who approved, what was approved and when, and can be produced reliably for sampled dates. The failure mode is that chat approvals are hard to retrieve consistently months later. Approvals recorded in the change system itself are far more durable.

Related reading: SOC 2 controls CC1 to CC9 · SOC 2 evidence collection · SOC 2 readiness checklist

Accuracy note: Control references follow the SOC 2 Trust Services Criteria. Evidence expectations vary by auditor, scope and how each control is implemented. Confirm formats with your auditor during planning. Current to August 2026. Osto helps companies deploy controls and reach audit readiness; attestations are issued by accredited independent auditors.