A control-by-control reference for what an auditor will ask to see, and what makes each artifact pass first time.
- SOC 2
- Audit evidence
- Reference
The short answer
Every acceptable artifact is timestamped, attributable, uncropped and dated inside the observation window. Beyond that, evidence differs by control family. The six items at the end of this guide account for most re-evidence requests in first audits.
On this page
What makes a SOC 2 control artifact acceptable
CC1 to CC5, governance and risk
| Control | What to produce | What makes it pass |
|---|---|---|
| CC1.1 integrity and ethics | Code of conduct with acknowledgements | Acknowledgement per person, dated in period |
| CC1.3 structure and authority | Org chart, role definitions | Version dated, showing reporting lines |
| CC1.4 competence | Security training completion records | Per-person completion with dates, not a course link |
| CC2.1 information quality | Log and monitoring configuration | Config view plus a sample of retained output |
| CC3.1 to CC3.3 risk assessment | Risk register, scoring rationale, decisions | Evidence of periodic review, not a static document |
| CC4.1 monitoring activities | Penetration test, internal audit output | Dated inside the window, with remediation tracked |
| CC5.1 to CC5.3 control activities | Policies mapped to controls | Approval record and review date on each policy |
CC6, access control
This family produces more evidence requests than any other, because most of its controls combine a system state with a human decision.
| Control | What to produce | What makes it pass |
|---|---|---|
| CC6.1 logical access | Identity provider config, MFA enforcement, user list | Console view matching the export, not the export alone |
| CC6.2 registration | Provisioning tickets for new joiners | Request, approval and completion linked per person |
| CC6.3 modification and removal | Deprovisioning records for leavers | Timestamps showing removal within your stated window |
| CC6.4 physical access | Data centre attestation or office access records | Cloud provider report is normally acceptable here |
| CC6.6 external threats | Firewall, WAF and network protection config | Evidence it is enforcing, not in monitoring mode |
| CC6.7 transmission and disposal | Encryption in transit config, disposal records | TLS settings plus documented disposal procedure |
| CC6.8 malicious software | Endpoint agent coverage report | Coverage reconciled against total device count |
CC7 to CC9, operations and change
| Control | What to produce | What makes it pass |
|---|---|---|
| CC7.1 vulnerability detection | Scan output across the period | Scans at your stated frequency, no unexplained gaps |
| CC7.2 monitoring for anomalies | Alert configuration and triage records | Records showing somebody reviewed and acted on alerts |
| CC7.3 evaluation of events | Incident records with severity assessment | Assessment reasoning, even for events judged minor |
| CC7.4 incident response | Incident response plan, plus any real incidents | Plan tested or exercised, with a record |
| CC7.5 recovery | Backup configuration and restore test results | A completed restore test, not backup success logs |
| CC8.1 change management | Change records with approvals | Approval separate from the person who made the change |
| CC9.1 risk mitigation | Business continuity plan, insurance | Reviewed and dated within the period |
| CC9.2 vendor management | Vendor register with risk ratings | Sub-processor reports collected and reviewed |
Six SOC 2 controls whose evidence fails most often
Access review with no sign-off
A permissions export shows state. The control is that somebody reviewed it and decided. Record the reviewer and the date.
Penetration test outside the window
A test dated before the period opened does not evidence operation during it. Schedule early in the window.
Inventory that will not reconcile
Device count against headcount is the first thing checked. Reconcile before fieldwork or expect questions.
Approvals living in chat
Retrievable in month one, painful in month nine. Approvals in the change system survive sampling.
Backups with no restore test
Successful backup jobs are not recovery evidence. The restore test is the control.
One snapshot for a whole period
A Type II tests operation over time. A single dated image evidences a single date.
How Osto reduces the pile
The controls that create the most evidence work, access, endpoint coverage, vulnerability detection, change and web protection, all run inside Osto. Because the controls and the compliance mapping share a platform, the artifact is generated by the system enforcing the control rather than reconstructed afterwards from an API read of a separate product.
Governance evidence stays yours. Risk decisions, policy approvals and review sign-offs are human judgments and no platform produces them for you.
See which controls produce clean evidence today
A free assessment maps your controls to their evidence sources and flags the ones that will generate re-evidence requests.
Frequently asked questions
What evidence do I need for SOC 2?
Evidence varies by control, but every artifact needs four properties: a visible system timestamp, attribution showing who produced it and from where, an uncropped view including URL and user context, and a date inside the observation window. Missing any one of the four is the most common reason evidence is returned.
What is the most common SOC 2 evidence mistake?
Submitting a single snapshot as proof that a control operated across an entire period. A Type II examines operation over time, and auditors sample dates across the window. One screenshot demonstrates one moment, not a period.
Do access reviews need manager sign-off?
In practice, yes. An export of current permissions shows state. The control being tested is that somebody with authority reviewed that state and made a decision. Without recorded sign-off, you have evidence of configuration rather than evidence of review.
Does a penetration test have to fall inside the observation window?
It should. A test dated before the window opened generally does not evidence that the control operated during the period under examination. Scheduling the test early in the window, leaving time to remediate and retest, avoids the problem.
Why does my asset inventory keep getting questioned?
Because it usually does not reconcile against another source. If your device management console lists forty five machines and HR lists sixty people, an auditor will ask about the difference. Reconciling the two before fieldwork removes an entire round of questions.
Are approvals in Slack acceptable as evidence?
Sometimes, if the message shows who approved, what was approved and when, and can be produced reliably for sampled dates. The failure mode is that chat approvals are hard to retrieve consistently months later. Approvals recorded in the change system itself are far more durable.
Related reading: SOC 2 controls CC1 to CC9 · SOC 2 evidence collection · SOC 2 readiness checklist
Accuracy note: Control references follow the SOC 2 Trust Services Criteria. Evidence expectations vary by auditor, scope and how each control is implemented. Confirm formats with your auditor during planning. Current to August 2026. Osto helps companies deploy controls and reach audit readiness; attestations are issued by accredited independent auditors.

