{"id":965,"date":"2026-08-23T20:48:09","date_gmt":"2026-08-23T20:48:09","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=965"},"modified":"2026-08-23T20:48:09","modified_gmt":"2026-08-23T20:48:09","slug":"soc-2-evidence-collection-2","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/guides\/soc-2-evidence-collection-2\/","title":{"rendered":"What Compliance Automation Cannot Collect: The SOC 2 Evidence Gap"},"content":{"rendered":"\n<style>\n.og{\n  --navy:#1c267a; --navy-2:#2e3a9e; --navy-3:#141c5c;\n  --indigo:#4657e5; --peri:#97a2ff;\n  --ink:#060818; --ink-2:#373a51; --ink-3:#6b6d80;\n  --page:#f3f4fc; --bg-2:#e6e8f7; --paper:#ffffff; --line:#d9dcf1;\n  --t1:#eaecfd; --t2:#e6e8f7; --t3:#f3f4fc; --t4:#dddff4; --t5:#f0f1fb;\n  font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif;\n  font-size:17px; line-height:1.75; color:var(--ink); max-width:820px; margin:0 auto;\n}\n.og p{margin:0 0 20px}\n.og a{color:var(--navy-2); text-decoration:underline; text-underline-offset:2px}\n.og .dek{font-size:19px; line-height:1.6; margin:0 0 18px}\n.og .pills{display:flex; flex-wrap:wrap; gap:8px; margin:0 0 28px; padding:0; list-style:none}\n.og .pills li{font-size:12.5px; font-weight:600; letter-spacing:.02em; padding:5px 13px;\n  border-radius:999px; background:var(--t1); color:var(--navy)}\n.og .shortans{border-radius:14px; padding:26px 30px; margin:0 0 26px;\n  background:linear-gradient(135deg,#eaecfd 0%,#e6e8f7 100%)}\n.og .shortans h4{margin:0 0 10px; font-size:12.5px; letter-spacing:.11em; text-transform:uppercase;\n  font-weight:700; color:var(--navy)}\n.og .shortans p{margin:0; font-size:18px; line-height:1.65; font-weight:500}\n.og h2{font-size:27px; line-height:1.3; font-weight:700; color:var(--navy);\n  margin:54px 0 14px; padding-bottom:10px; letter-spacing:-.015em; position:relative}\n.og h2::after{content:\"\"; position:absolute; left:0; bottom:0; width:56px; height:3px; border-radius:2px}\n.og h2.s1::after{background:var(--navy)}\n.og h2.s2::after{background:var(--navy-2)}\n.og h2.s3::after{background:var(--indigo)}\n.og h2.s4::after{background:var(--peri)}\n.og h2.s5::after{background:var(--navy-3)}\n.og h2 + .sub{color:var(--ink-2); font-size:16px; margin:0 0 22px}\n.og h3{font-size:19px; font-weight:650; color:var(--navy-2); margin:32px 0 10px}\n.og .toc{border:1px solid var(--line); border-radius:14px; padding:22px 26px; margin:0 0 44px; background:var(--page)}\n.og .toc h4{margin:0 0 12px; font-size:12.5px; letter-spacing:.11em; text-transform:uppercase; font-weight:700; color:var(--navy)}\n.og .toc ol{margin:0; padding:0; list-style:none; counter-reset:t}\n.og .toc li{counter-increment:t; padding:9px 0 9px 34px; border-bottom:1px solid var(--line);\n  font-size:16px; line-height:1.5; position:relative}\n.og .toc li:last-child{border-bottom:none; padding-bottom:0}\n.og .toc li::before{content:counter(t,decimal-leading-zero); position:absolute; left:0; top:11px;\n  font-size:12px; font-weight:700; color:var(--indigo)}\n.og .toc a{color:var(--navy); font-weight:600; text-decoration:none}\n.og .toc a:hover{text-decoration:underline}\n.og .scroll{overflow-x:auto; -webkit-overflow-scrolling:touch; margin:26px 0 30px;\n  border:1px solid var(--line); border-radius:14px; background:var(--paper)}\n.og .scroll svg{display:block; min-width:660px; width:100%; height:auto}\n.og .cap{font-size:13.5px; color:var(--ink-2); text-align:center; margin:-18px 0 30px}\n.og .trio{display:grid; grid-template-columns:repeat(3,1fr); gap:12px; margin:26px 0 30px}\n.og .duo{display:grid; grid-template-columns:repeat(2,1fr); gap:12px; margin:26px 0 30px}\n.og .cd{border-radius:12px; padding:20px 22px}\n.og .cd.a{background:var(--t1)} .og .cd.b{background:var(--t2)} .og .cd.c{background:var(--t3)}\n.og .cd.d{background:var(--t4)} .og .cd.e{background:var(--t5)}\n.og .cd .code{display:block; font-size:11.5px; font-weight:700; letter-spacing:.07em;\n  text-transform:uppercase; color:var(--indigo); margin-bottom:7px}\n.og .cd h5{margin:0 0 7px; font-size:16.5px; font-weight:650; color:var(--navy); line-height:1.35}\n.og .cd p{margin:0; font-size:15px; line-height:1.6}\n.og .note{border:1px solid var(--navy); border-radius:12px; padding:20px 24px; margin:28px 0; background:var(--paper)}\n.og .note p{margin:0; font-size:16.5px; line-height:1.65}\n.og .note strong{color:var(--navy)}\n.og table{width:100%; border-collapse:separate; border-spacing:0; margin:26px 0 32px; font-size:15.5px;\n  border:1px solid var(--line); border-radius:12px; overflow:hidden}\n.og th{background:var(--navy); color:#fff; text-align:left; padding:14px 16px; font-weight:700;\n  font-size:13px; line-height:1.4; letter-spacing:.055em; text-transform:uppercase}\n.og td{border:0; border-top:1px solid var(--line); padding:13px 16px; vertical-align:top; line-height:1.6}\n.og tbody tr:first-child td{border-top:0}\n.og tbody tr:nth-child(even){background:var(--t3)}\n.og tbody td:first-child{font-weight:600; color:var(--navy)}\n.og tbody tr:nth-child(even){background:var(--page)}\n.og .steps{margin:26px 0 30px; padding:0; list-style:none; counter-reset:s}\n.og .steps li{counter-increment:s; position:relative; padding:14px 18px 14px 56px; margin-bottom:8px;\n  border-radius:11px; background:var(--page); font-size:16px; line-height:1.55}\n.og .steps li::before{content:counter(s); position:absolute; left:16px; top:14px; width:26px; height:26px;\n  border-radius:50%; background:var(--navy); color:#fff; font-size:13px; font-weight:700;\n  display:flex; align-items:center; justify-content:center}\n.og .steps span{display:block; font-size:14px; color:var(--ink-2); margin-top:3px}\n.og details{border:1px solid var(--line); border-radius:11px; padding:15px 20px; margin-bottom:9px; background:var(--paper)}\n.og details[open]{border-color:var(--peri)}\n.og summary{font-weight:650; color:var(--navy); cursor:pointer; font-size:16.5px; line-height:1.5}\n.og details p{margin:12px 0 0; font-size:16px; line-height:1.7}\n.og .cta{border-radius:16px; padding:38px 34px; margin:52px 0 30px; text-align:center;\n  background:linear-gradient(135deg,#141c5c 0%,#4657e5 100%)}\n.og .cta h3{color:#fff; margin:0 0 10px; font-size:25px; line-height:1.3}\n.og .cta p{color:#d5d8f5; margin:0 0 24px; font-size:16.5px; line-height:1.6}\n.og .cta .btns{display:flex; gap:12px; justify-content:center; flex-wrap:wrap}\n.og .cta a{display:inline-block; padding:14px 30px; border-radius:9px; font-weight:650; font-size:16px; text-decoration:none}\n.og .cta a.p{background:#ffffff}\n.og .cta a.p span{color:#1c267a !important}\n.og .cta a.s{border:1px solid rgba(255,255,255,.6)}\n.og .cta a.s span{color:#ffffff !important}\n.og .foot{border-top:1px solid var(--line); padding-top:20px; margin-top:42px; font-size:14.5px;\n  color:var(--ink-2); line-height:1.7}\n@media(max-width:680px){\n  .og{font-size:16px}\n  .og h2{font-size:22px} .og .dek{font-size:17px} .og .shortans p{font-size:16.5px}\n  .og .trio,.og .duo{grid-template-columns:1fr}\n  .og .shortans{padding:20px 22px} .og .toc{padding:18px 20px} .og .cta{padding:28px 20px}\n  .og table{font-size:14px} .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">Your compliance platform reads APIs. Your auditor asks for things that do not live in one. That mismatch is where first audits slow down.<\/p>\n\n<ul class=\"pills\"><li>SOC 2<\/li><li>Audit evidence<\/li><li>Compliance automation<\/li><\/ul>\n\n<div class=\"shortans\">\n  <h4>The short answer<\/h4>\n  <p>Compliance platforms collect evidence from systems with an API. They cannot collect manager sign-offs, permissions inside custom apps, console views that verify an export, or the reasoning behind a risk decision. Those sit in the three control families auditors flag most often.<\/p>\n<\/div>\n\n<p>This is not a flaw in any one product. It is what happens when a tool reads configuration data rather than watching work happen.<\/p>\n\n<div class=\"toc\">\n  <h4>On this page<\/h4>\n  <ol>\n    <li><a href=\"#split\">What SOC 2 evidence collection can and cannot reach<\/a><\/li>\n    <li><a href=\"#sampling\">Why auditor sampling sets the real deadline<\/a><\/li>\n    <li><a href=\"#three\">The three control families where gaps cluster<\/a><\/li>\n    <li><a href=\"#ipe\">Why an export alone is not enough<\/a><\/li>\n    <li><a href=\"#close\">Five SOC 2 evidence collection moves before fieldwork<\/a><\/li>\n    <li><a href=\"#osto\">How Osto approaches this<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 class=\"s1\" id=\"split\">What SOC 2 evidence collection can and cannot reach<\/h2>\n\n<p>Split your evidence into two columns and the picture gets clear quickly. One column arrives on its own. The other is yours to produce, every time.<\/p>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 306\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Evidence a compliance platform collects automatically against evidence produced by hand\">\n<rect x=\"16\" y=\"14\" width=\"364\" height=\"252\" rx=\"12\" fill=\"#f3f4fc\"\/>\n<path d=\"M16.0 26 a12 12 0 0 1 12 -12 h340 a12 12 0 0 1 12 12 v40 h-364.0 Z\" fill=\"#1c267a\"\/>\n<text x=\"198\" y=\"40\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#ffffff\">Collected for you<\/text>\n<text x=\"198\" y=\"58\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#c9cdf2\">any system with an API<\/text>\n<rect x=\"400\" y=\"14\" width=\"364\" height=\"252\" rx=\"12\" fill=\"#f3f4fc\"\/>\n<path d=\"M400.0 26 a12 12 0 0 1 12 -12 h340 a12 12 0 0 1 12 12 v40 h-364.0 Z\" fill=\"#2e3a9e\"\/>\n<text x=\"582\" y=\"40\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#ffffff\">Produced by hand<\/text>\n<text x=\"582\" y=\"58\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#c9cdf2\">no API exposes it<\/text>\n<rect x=\"36\" y=\"86\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M40.5 94.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"64\" y=\"98\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Cloud configuration state<\/text>\n<rect x=\"36\" y=\"113\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M40.5 121.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"64\" y=\"125\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Identity provider and MFA<\/text>\n<rect x=\"36\" y=\"140\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M40.5 148.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"64\" y=\"152\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Repository and CI activity<\/text>\n<rect x=\"36\" y=\"167\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M40.5 175.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"64\" y=\"179\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Vulnerability scanner output<\/text>\n<rect x=\"36\" y=\"194\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M40.5 202.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"64\" y=\"206\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Endpoint agent deployment<\/text>\n<rect x=\"36\" y=\"221\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M40.5 229.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"64\" y=\"233\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Cloud audit logs<\/text>\n<rect x=\"420\" y=\"86\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M425.6 91.6 l5.8 5.8 M431.4 91.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"448\" y=\"98\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Manager sign-off on reviews<\/text>\n<rect x=\"420\" y=\"113\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M425.6 118.6 l5.8 5.8 M431.4 118.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"448\" y=\"125\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Custom admin permissions<\/text>\n<rect x=\"420\" y=\"140\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M425.6 145.6 l5.8 5.8 M431.4 145.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"448\" y=\"152\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Internal and legacy tools<\/text>\n<rect x=\"420\" y=\"167\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M425.6 172.6 l5.8 5.8 M431.4 172.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"448\" y=\"179\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Console view behind an export<\/text>\n<rect x=\"420\" y=\"194\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M425.6 199.6 l5.8 5.8 M431.4 199.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"448\" y=\"206\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Data classification calls<\/text>\n<rect x=\"420\" y=\"221\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M425.6 226.6 l5.8 5.8 M431.4 226.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"448\" y=\"233\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Risk reasoning and approvals<\/text>\n<rect x=\"16\" y=\"280\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#2e3a9e\"\/>\n<path d=\"M20.5 288.8 l2.7 2.8 l5.3 -5.6\" stroke=\"#ffffff\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<text x=\"41\" y=\"292\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">arrives automatically<\/text>\n<rect x=\"166\" y=\"280\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M171.8 285.6 l5.8 5.8 M177.6 285.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"191\" y=\"292\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">you assemble it each time<\/text>\n<\/svg>\n<\/div>\n<p class=\"cap\">The right column is where fieldwork slows down.<\/p>\n\n<h2 class=\"s2\" id=\"sampling\">Why auditor sampling sets the real deadline<\/h2>\n\n<p>A Type II examines an observation window, commonly twelve months. Auditors do not review every day of it. They sample, typically 25 to 40 dates per control, and ask for evidence covering each one. A sampled date with nothing behind it becomes a finding.<\/p>\n\n<p>Which is why quarterly collection quietly fails. Four dates against thirty requests is not a coverage strategy.<\/p>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Quarterly evidence collection compared with continuous collection against thirty sampled dates\">\n<text x=\"16\" y=\"28\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">One control, 12-month window, 30 dates sampled<\/text>\n<text x=\"16\" y=\"66\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#373a51\">Quarterly collection<\/text>\n<rect x=\"16\" y=\"78\" width=\"748\" height=\"20\" rx=\"4\" fill=\"#e6e8f7\"\/>\n<rect x=\"50\" y=\"78\" width=\"10\" height=\"20\" rx=\"2\" fill=\"#141c5c\"\/>\n<rect x=\"236\" y=\"78\" width=\"10\" height=\"20\" rx=\"2\" fill=\"#141c5c\"\/>\n<rect x=\"422\" y=\"78\" width=\"10\" height=\"20\" rx=\"2\" fill=\"#141c5c\"\/>\n<rect x=\"608\" y=\"78\" width=\"10\" height=\"20\" rx=\"2\" fill=\"#141c5c\"\/>\n<text x=\"16\" y=\"120\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">4 dates covered. 26 requests you cannot answer.<\/text>\n<text x=\"16\" y=\"166\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#373a51\">Continuous collection<\/text>\n<rect x=\"16\" y=\"178\" width=\"748\" height=\"20\" rx=\"4\" fill=\"#4657e5\"\/>\n<text x=\"16\" y=\"220\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Every date covered. The sampler cannot find a gap.<\/text>\n<\/svg>\n<\/div>\n<p class=\"cap\">The genuine case for automation, and it only holds for controls an API can reach.<\/p>\n\n<div class=\"note\">\n  <p><strong>Both things are true.<\/strong> Continuous collection beats quarterly screenshots decisively, and it covers roughly half your evidence. The half it misses is the half auditors flag most often.<\/p>\n<\/div>\n\n<h2 class=\"s3\" id=\"three\">The three control families where gaps cluster<\/h2>\n\n<p>Across SOC 2 engagements, the same three areas come up again and again.<\/p>\n\n<div class=\"trio\">\n  <div class=\"cd a\"><span class=\"code\">CC6.1 to CC6.3<\/span><h5>Access provisioning<\/h5>\n    <p>The API shows who has access right now. Auditors want quarterly reviews carrying manager sign-off, plus proof the export matches the live console.<\/p><\/div>\n  <div class=\"cd b\"><span class=\"code\">CC8.1<\/span><h5>Change management<\/h5>\n    <p>Commits and merges are easy. The approval judgment behind them is not, and neither are changes made outside the pipeline.<\/p><\/div>\n  <div class=\"cd d\"><span class=\"code\">CC3.1 to CC3.3<\/span><h5>Risk assessment<\/h5>\n    <p>There is no API for reasoning. Your register, scoring rationale and decisions are documents somebody writes.<\/p><\/div>\n<\/div>\n\n<h3>Where each control actually lives<\/h3>\n\n<table>\n  <thead><tr><th>Control<\/th><th>System of record<\/th><th>What the API misses<\/th><\/tr><\/thead>\n  <tbody>\n    <tr><td>CC6.1 logical access<\/td><td>Identity provider<\/td><td>Review sign-off, custom app permissions<\/td><\/tr>\n    <tr><td>CC6.6, CC6.7 vulnerability<\/td><td>Scanner<\/td><td>Remediation decisions, accepted-risk rationale<\/td><\/tr>\n    <tr><td>CC7.1 monitoring<\/td><td>Log aggregation or cloud audit log<\/td><td>Alert triage and what a human concluded<\/td><\/tr>\n    <tr><td>CC8.1 change management<\/td><td>CI\/CD and Git host<\/td><td>Approval judgment, out-of-pipeline changes<\/td><\/tr>\n    <tr><td>Asset inventory<\/td><td>Device management and cloud accounts<\/td><td>Classification context, headcount reconciliation<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 class=\"s4\" id=\"ipe\">Why an export alone is not enough<\/h2>\n\n<p>Information Provided by the Entity is the reason. Auditors will not take a spreadsheet at face value, because you generated it. They want the source behind it.<\/p>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 216\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"An API export showing forty five devices against an HR system showing sixty employees, prompting an auditor request for console evidence\">\n<rect x=\"14\" y=\"20\" width=\"190\" height=\"84\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"109\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" fill=\"#373a51\">API export says<\/text>\n<text x=\"109\" y=\"84\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"27\" font-weight=\"700\" fill=\"#1c267a\">45 laptops<\/text>\n<rect x=\"14\" y=\"116\" width=\"190\" height=\"84\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"109\" y=\"144\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12.5\" fill=\"#373a51\">HR system says<\/text>\n<text x=\"109\" y=\"180\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"27\" font-weight=\"700\" fill=\"#1c267a\">60 people<\/text>\n<path d=\"M212 110 L248 110\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M246 105 L254 110 L246 115 Z\" fill=\"#4657e5\"\/>\n<rect x=\"264\" y=\"20\" width=\"236\" height=\"180\" rx=\"12\" fill=\"#eaecfd\"\/>\n<text x=\"382\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">Auditor flags it<\/text>\n<text x=\"382\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">15 devices unaccounted for<\/text>\n<text x=\"382\" y=\"116\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Asks to see the live device<\/text>\n<text x=\"382\" y=\"140\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">console, not the export<\/text>\n<path d=\"M508 110 L544 110\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\"\/>\n<path d=\"M542 105 L550 110 L542 115 Z\" fill=\"#4657e5\"\/>\n<rect x=\"560\" y=\"20\" width=\"206\" height=\"180\" rx=\"12\" fill=\"#dddff4\"\/>\n<text x=\"663\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">The gap<\/text>\n<text x=\"663\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">The platform reads the<\/text>\n<text x=\"663\" y=\"116\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">API, not the interface.<\/text>\n<text x=\"663\" y=\"140\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">You take the screenshot.<\/text>\n<\/svg>\n<\/div>\n\n<p>Classification works the same way. An API confirms a storage bucket exists and how it is configured. It cannot show the bucket is classified correctly in your documentation, because that mapping is a decision rather than a config field.<\/p>\n\n<div class=\"note\">\n  <p><strong>Ask this in any vendor demo:<\/strong> show me continuous evidence collection for CC6.1 from our identity provider, with no screenshots and no manual export. If the answer involves a browser tab or a CSV upload, you are looking at a control tracker rather than evidence automation. Both are useful. They are not the same purchase.<\/p>\n<\/div>\n\n<h2 class=\"s5\" id=\"close\">Five SOC 2 evidence collection moves before fieldwork<\/h2>\n\n<p>None of these need a new vendor.<\/p>\n\n<ol class=\"steps\">\n  <li>Map every control to its system of record<span>Then mark which are API-reachable and which are not<\/span><\/li>\n  <li>List the controls containing a human decision<span>Sign-offs, approvals, classifications, alert triage<\/span><\/li>\n  <li>Move manual evidence from quarterly to monthly<span>Sampling punishes a four-date year<\/span><\/li>\n  <li>Capture metadata on every manual artifact<span>System date and time, full URL, logged-in user, uncropped view<\/span><\/li>\n  <li>Agree evidence formats with your auditor during planning<span>The answer changes your workload, so get it early<\/span><\/li>\n<\/ol>\n\n<p>Item four trips up more teams than the rest combined. Manual evidence is accepted when it is verifiable. A cropped screenshot with no timestamp is not evidence, whoever produced it.<\/p>\n\n<div class=\"duo\">\n  <div class=\"cd c\"><h5>Where automation genuinely wins<\/h5>\n    <p>Across a twelve-month window under sampling, daily automated collection beats quarterly manual work outright. Teams commonly report saving 100 to 200 hours on a first cycle. That is the correct reason to buy.<\/p><\/div>\n  <div class=\"cd e\"><h5>Where you may not need it yet<\/h5>\n    <p>Below roughly five engineers, manual is sometimes faster than integrating a platform. Break-even arrives when systems in scope exceed what one person can hold in their head.<\/p><\/div>\n<\/div>\n\n<h2 class=\"s1\" id=\"osto\">How Osto approaches this<\/h2>\n\n<p>The gap exists because controls and evidence sit in different places. A platform reading your tooling through an API is always one step removed from what the tooling did.<\/p>\n\n<p>Osto runs the controls and the compliance mapping in the same platform. Endpoint and device control, code security, cloud posture and web protection all report into one place, so more of the evidence trail is native rather than reconstructed from an API read of someone else&#8217;s product. Cross-module correlation covers ground that separate API reads cannot join up.<\/p>\n\n<p>That closes part of the gap, not all of it. Controls turning on a human decision, the sign-offs and classifications and accepted risks, remain yours to document no matter what you buy.<\/p>\n\n<div class=\"cta\">\n  <h3>See which of your controls actually produce evidence<\/h3>\n  <p>A free assessment maps your controls to their systems of record and shows which ones leave a trail an auditor can sample.<\/p>\n  <div class=\"btns\">\n    <a class=\"p\" href=\"https:\/\/www.osto.one\/contact\"><span>Get a free security assessment<\/span><\/a>\n    <a class=\"s\" href=\"https:\/\/www.osto.one\/book-demo\"><span>Book a platform walkthrough<\/span><\/a>\n  <\/div>\n<\/div>\n\n<h2 class=\"s2\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What evidence can compliance automation not collect?<\/summary>\n  <p>Anything without an API. Manager sign-off on access reviews, permissions inside custom or legacy applications, console views that corroborate an export, data classification decisions, risk assessment reasoning, and approval judgment on changes. Infrastructure and identity configuration are well covered. Application-level and decision-based evidence are not.<\/p>\n<\/details>\n<details>\n  <summary>Why do SOC 2 auditors still ask for screenshots?<\/summary>\n  <p>Because of Information Provided by the Entity requirements. An export you generated is not self-verifying, so auditors often want to see the live console showing the same values. They also need visual evidence for controls inside applications that have no API to query.<\/p>\n<\/details>\n<details>\n  <summary>How many dates does an auditor sample in a SOC 2 Type II?<\/summary>\n  <p>Commonly 25 to 40 dates per control across the observation window, usually twelve months. The auditor picks the dates, not you, so quarterly evidence will miss most of them. Any sampled date without evidence is a finding.<\/p>\n<\/details>\n<details>\n  <summary>Which SOC 2 controls have the most evidence gaps?<\/summary>\n  <p>Access provisioning and deprovisioning (CC6.1 to CC6.3), change management (CC8.1), and risk assessment (CC3.1 to CC3.3). Each combines API-readable state with a human decision or an interface view that no API exposes.<\/p>\n<\/details>\n<details>\n  <summary>Does a compliance platform make me audit-ready?<\/summary>\n  <p>It means part of your evidence is collected continuously. Readiness also needs the non-API evidence, the controls genuinely operating, and agreement with your auditor on formats. A dashboard showing green describes what the platform can see, not your full audit position.<\/p>\n<\/details>\n<details>\n  <summary>Is manual evidence acceptable to SOC 2 auditors?<\/summary>\n  <p>Yes, when it carries the metadata that makes it verifiable: system date and time, the full URL, the logged-in user context, and an uncropped view. What fails is cropped, undated evidence, and a single snapshot offered as proof of a control operating across a whole period.<\/p>\n<\/details>\n\n<div class=\"foot\">\n  <p><strong>Related reading:<\/strong> <a href=\"https:\/\/www.osto.one\/blog\/soc-2-readiness-checklist\/\">SOC 2 readiness checklist<\/a> &middot; <a href=\"https:\/\/www.osto.one\/blog\/soc-2-evidence-collection\/\">SOC 2 evidence collection<\/a> &middot; <a href=\"https:\/\/www.osto.one\/blog\/soc-2-controls-cc1-cc9\/\">SOC 2 controls CC1 to CC9<\/a> &middot; <a href=\"https:\/\/www.osto.one\/blog\/soc-2-type-1-vs-type-2\/\">SOC 2 Type 1 vs Type 2<\/a><\/p>\n  <p><strong>Accuracy note:<\/strong> Control references follow the SOC 2 Trust Services Criteria. Sampling ranges, commonly cited gap areas and evidence-format expectations reflect published audit and industry analysis current to August 2026, and vary by audit firm, scope and control implementation. Confirm requirements with your own auditor during planning. Osto helps companies deploy controls and reach audit readiness; SOC 2 attestations are issued by accredited independent auditors.<\/p>\n<\/div>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n \"@context\": \"https:\/\/schema.org\",\n \"@type\": \"FAQPage\",\n \"mainEntity\": [\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What evidence can compliance automation not collect?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Anything without an API. Manager sign-off on access reviews, permissions inside custom or legacy applications, console views that corroborate an export, data classification decisions, risk assessment reasoning, and approval judgment on changes. Infrastructure and identity configuration are well covered. Application-level and decision-based evidence are not.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Why do SOC 2 auditors still ask for screenshots?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Because of Information Provided by the Entity requirements. An export you generated is not self-verifying, so auditors often want to see the live console showing the same values. They also need visual evidence for controls inside applications that have no API to query.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"How many dates does an auditor sample in a SOC 2 Type II?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Commonly 25 to 40 dates per control across the observation window, usually twelve months. The auditor picks the dates, not you, so quarterly evidence will miss most of them. Any sampled date without evidence is a finding.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Which SOC 2 controls have the most evidence gaps?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Access provisioning and deprovisioning (CC6.1 to CC6.3), change management (CC8.1), and risk assessment (CC3.1 to CC3.3). Each combines API-readable state with a human decision or an interface view that no API exposes.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Does a compliance platform make me audit-ready?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"It means part of your evidence is collected continuously. Readiness also needs the non-API evidence, the controls genuinely operating, and agreement with your auditor on formats. A dashboard showing green describes what the platform can see, not your full audit position.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Is manual evidence acceptable to SOC 2 auditors?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Yes, when it carries the metadata that makes it verifiable: system date and time, the full URL, the logged-in user context, and an uncropped view. What fails is cropped, undated evidence, and a single snapshot offered as proof of a control operating across a whole period.\"\n   }\n  }\n ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>Your compliance platform reads APIs. Your auditor asks for things that do not live in one. That mismatch is where\u2026<\/p>\n","protected":false},"author":8,"featured_media":966,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[211],"tags":[269],"class_list":["post-965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guides","tag-soc-2-evidence-collection"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=965"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/965\/revisions"}],"predecessor-version":[{"id":967,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/965\/revisions\/967"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/966"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}