{"id":997,"date":"2026-08-24T17:29:15","date_gmt":"2026-08-24T17:29:15","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=997"},"modified":"2026-08-24T17:29:15","modified_gmt":"2026-08-24T17:29:15","slug":"soc-2-controls-evidence","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/guides\/soc-2-controls-evidence\/","title":{"rendered":"SOC 2 Evidence by Control: What Auditors Actually Ask For"},"content":{"rendered":"\n<style>\n.og{\n  --navy:#1c267a; --navy-2:#2e3a9e; --navy-3:#141c5c;\n  --indigo:#4657e5; --peri:#97a2ff;\n  --ink:#060818; --ink-2:#373a51; --ink-3:#6b6d80;\n  --page:#f3f4fc; --bg-2:#e6e8f7; --paper:#ffffff; --line:#d9dcf1;\n  --t1:#eaecfd; --t2:#e6e8f7; --t3:#f3f4fc; --t4:#dddff4; --t5:#f0f1fb;\n  font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif;\n  font-size:17px; line-height:1.75; color:var(--ink); max-width:820px; margin:0 auto;\n}\n.og p{margin:0 0 20px}\n.og a{color:var(--navy-2); text-decoration:underline; text-underline-offset:2px}\n.og .dek{font-size:19px; line-height:1.6; margin:0 0 18px}\n.og .pills{display:flex; flex-wrap:wrap; gap:8px; margin:0 0 28px; padding:0; list-style:none}\n.og .pills li{font-size:12.5px; font-weight:600; letter-spacing:.02em; padding:5px 13px;\n  border-radius:999px; background:var(--t1); color:var(--navy)}\n.og .shortans{border-radius:14px; padding:26px 30px; margin:0 0 26px;\n  background:linear-gradient(135deg,#eaecfd 0%,#e6e8f7 100%)}\n.og .shortans h4{margin:0 0 10px; font-size:12.5px; letter-spacing:.11em; text-transform:uppercase;\n  font-weight:700; color:var(--navy)}\n.og .shortans p{margin:0; font-size:18px; line-height:1.65; font-weight:500}\n.og h2{font-size:27px; line-height:1.3; font-weight:700; color:var(--navy);\n  margin:54px 0 14px; padding-bottom:10px; letter-spacing:-.015em; position:relative}\n.og h2::after{content:\"\"; position:absolute; left:0; bottom:0; width:56px; height:3px; border-radius:2px}\n.og h2.s1::after{background:var(--navy)}\n.og h2.s2::after{background:var(--navy-2)}\n.og h2.s3::after{background:var(--indigo)}\n.og h2.s4::after{background:var(--peri)}\n.og h2.s5::after{background:var(--navy-3)}\n.og h2 + .sub{color:var(--ink-2); font-size:16px; margin:0 0 22px}\n.og h3{font-size:19px; font-weight:650; color:var(--navy-2); margin:32px 0 10px}\n.og .toc{border:1px solid var(--line); border-radius:14px; padding:22px 26px; margin:0 0 44px; background:var(--page)}\n.og .toc h4{margin:0 0 12px; font-size:12.5px; letter-spacing:.11em; text-transform:uppercase; font-weight:700; color:var(--navy)}\n.og .toc ol{margin:0; padding:0; list-style:none; counter-reset:t}\n.og .toc li{counter-increment:t; padding:9px 0 9px 34px; border-bottom:1px solid var(--line);\n  font-size:16px; line-height:1.5; position:relative}\n.og .toc li:last-child{border-bottom:none; padding-bottom:0}\n.og .toc li::before{content:counter(t,decimal-leading-zero); position:absolute; left:0; top:11px;\n  font-size:12px; font-weight:700; color:var(--indigo)}\n.og .toc a{color:var(--navy); font-weight:600; text-decoration:none}\n.og .toc a:hover{text-decoration:underline}\n.og .scroll{overflow-x:auto; -webkit-overflow-scrolling:touch; margin:26px 0 30px;\n  border:1px solid var(--line); border-radius:14px; background:var(--paper)}\n.og .scroll svg{display:block; min-width:660px; width:100%; height:auto}\n.og .cap{font-size:13.5px; color:var(--ink-2); text-align:center; margin:-18px 0 30px}\n.og .trio{display:grid; grid-template-columns:repeat(3,1fr); gap:12px; margin:26px 0 30px}\n.og .duo{display:grid; grid-template-columns:repeat(2,1fr); gap:12px; margin:26px 0 30px}\n.og .cd{border-radius:12px; padding:20px 22px}\n.og .cd.a{background:var(--t1)} .og .cd.b{background:var(--t2)} .og .cd.c{background:var(--t3)}\n.og .cd.d{background:var(--t4)} .og .cd.e{background:var(--t5)}\n.og .cd .code{display:block; font-size:11.5px; font-weight:700; letter-spacing:.07em;\n  text-transform:uppercase; color:var(--indigo); margin-bottom:7px}\n.og .cd h5{margin:0 0 7px; font-size:16.5px; font-weight:650; color:var(--navy); line-height:1.35}\n.og .cd p{margin:0; font-size:15px; line-height:1.6}\n.og .note{border:1px solid var(--navy); border-radius:12px; padding:20px 24px; margin:28px 0; background:var(--paper)}\n.og .note p{margin:0; font-size:16.5px; line-height:1.65}\n.og .note strong{color:var(--navy)}\n.og table{width:100%; border-collapse:separate; border-spacing:0; margin:26px 0 32px; font-size:15.5px;\n  border:1px solid var(--line); border-radius:12px; overflow:hidden}\n.og th{background:var(--navy); color:#fff; text-align:left; padding:14px 16px; font-weight:700;\n  font-size:13px; line-height:1.4; letter-spacing:.055em; text-transform:uppercase}\n.og td{border:0; border-top:1px solid var(--line); padding:13px 16px; vertical-align:top; line-height:1.6}\n.og tbody tr:first-child td{border-top:0}\n.og tbody tr:nth-child(even){background:var(--t3)}\n.og tbody td:first-child{font-weight:600; color:var(--navy)}\n.og tbody tr:nth-child(even){background:var(--page)}\n.og .steps{margin:26px 0 30px; padding:0; list-style:none; counter-reset:s}\n.og .steps li{counter-increment:s; position:relative; padding:14px 18px 14px 56px; margin-bottom:8px;\n  border-radius:11px; background:var(--page); font-size:16px; line-height:1.55}\n.og .steps li::before{content:counter(s); position:absolute; left:16px; top:14px; width:26px; height:26px;\n  border-radius:50%; background:var(--navy); color:#fff; font-size:13px; font-weight:700;\n  display:flex; align-items:center; justify-content:center}\n.og .steps span{display:block; font-size:14px; color:var(--ink-2); margin-top:3px}\n.og details{border:1px solid var(--line); border-radius:11px; padding:15px 20px; margin-bottom:9px; background:var(--paper)}\n.og details[open]{border-color:var(--peri)}\n.og summary{font-weight:650; color:var(--navy); cursor:pointer; font-size:16.5px; line-height:1.5}\n.og details p{margin:12px 0 0; font-size:16px; line-height:1.7}\n.og .cta{border-radius:16px; padding:38px 34px; margin:52px 0 30px; text-align:center;\n  background:linear-gradient(135deg,#141c5c 0%,#4657e5 100%)}\n.og .cta h3{color:#fff; margin:0 0 10px; font-size:25px; line-height:1.3}\n.og .cta p{color:#d5d8f5; margin:0 0 24px; font-size:16.5px; line-height:1.6}\n.og .cta .btns{display:flex; gap:12px; justify-content:center; flex-wrap:wrap}\n.og .cta a{display:inline-block; padding:14px 30px; border-radius:9px; font-weight:650; font-size:16px; text-decoration:none}\n.og .cta a.p{background:#ffffff}\n.og .cta a.p span{color:#1c267a !important}\n.og .cta a.s{border:1px solid rgba(255,255,255,.6)}\n.og .cta a.s span{color:#ffffff !important}\n.og .foot{border-top:1px solid var(--line); padding-top:20px; margin-top:42px; font-size:14.5px;\n  color:var(--ink-2); line-height:1.7}\n@media(max-width:680px){\n  .og{font-size:16px}\n  .og h2{font-size:22px} .og .dek{font-size:17px} .og .shortans p{font-size:16.5px}\n  .og .trio,.og .duo{grid-template-columns:1fr}\n  .og .shortans{padding:20px 22px} .og .toc{padding:18px 20px} .og .cta{padding:28px 20px}\n  .og table{font-size:14px} .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">A control-by-control reference for what an auditor will ask to see, and what makes each artifact pass first time.<\/p>\n\n<ul class=\"pills\"><li>SOC 2<\/li><li>Audit evidence<\/li><li>Reference<\/li><\/ul>\n\n<div class=\"shortans\">\n  <h4>The short answer<\/h4>\n  <p>Every acceptable artifact is timestamped, attributable, uncropped and dated inside the observation window. Beyond that, evidence differs by control family. The six items at the end of this guide account for most re-evidence requests in first audits.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <h4>On this page<\/h4>\n  <ol>\n    <li><a href=\"#props\">What makes a SOC 2 control artifact acceptable<\/a><\/li>\n    <li><a href=\"#cc1\">CC1 to CC5, governance and risk<\/a><\/li>\n    <li><a href=\"#cc6\">CC6, access control<\/a><\/li>\n    <li><a href=\"#cc7\">CC7 to CC9, operations and change<\/a><\/li>\n    <li><a href=\"#fail\">Six SOC 2 controls whose evidence fails most often<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 class=\"s1\" id=\"props\">What makes a SOC 2 control artifact acceptable<\/h2>\n\n<div class=\"scroll\">\n<svg viewBox=\"0 0 780 232\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Four required properties of audit evidence shown as equal panels: timestamped, attributable, uncropped and within the observation period\">\n<text x=\"16\" y=\"28\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">Four properties that make an artifact acceptable<\/text>\n<rect x=\"16\" y=\"50\" width=\"176\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"104\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">Timestamped<\/text>\n<text x=\"104\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">System date and<\/text>\n<text x=\"104\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">time visible in frame<\/text>\n<rect x=\"206\" y=\"50\" width=\"176\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"295\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">Attributable<\/text>\n<text x=\"295\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">Shows who produced<\/text>\n<text x=\"295\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">it and from where<\/text>\n<rect x=\"397\" y=\"50\" width=\"176\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"485\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">Uncropped<\/text>\n<text x=\"485\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">Full window including<\/text>\n<text x=\"485\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">URL and user context<\/text>\n<rect x=\"588\" y=\"50\" width=\"176\" height=\"118\" rx=\"12\" fill=\"#e6e8f7\"\/>\n<text x=\"676\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#1c267a\">In period<\/text>\n<text x=\"676\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">Dated inside the<\/text>\n<text x=\"676\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"12\" fill=\"#373a51\">observation window<\/text>\n<rect x=\"16\" y=\"182\" width=\"748\" height=\"44\" rx=\"12\" fill=\"#dddff4\"\/>\n<rect x=\"34\" y=\"197\" width=\"17\" height=\"17\" rx=\"5\" fill=\"#ffffff\" stroke=\"#97a2ff\" stroke-width=\"1.5\"\/>\n<path d=\"M39.6 202.6 l5.8 5.8 M45.4 202.6 l-5.8 5.8\" stroke=\"#4657e5\" stroke-width=\"2\" fill=\"none\" stroke-linecap=\"round\"\/>\n<text x=\"62\" y=\"209\" font-family=\"Inter,-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif\" font-size=\"13\" fill=\"#060818\">Miss any one of the four and the artifact comes back as a request for re-evidence<\/text>\n<\/svg>\n<\/div>\n\n<h2 class=\"s2\" id=\"cc1\">CC1 to CC5, governance and risk<\/h2>\n\n<table>\n  <thead><tr><th>Control<\/th><th>What to produce<\/th><th>What makes it pass<\/th><\/tr><\/thead>\n  <tbody>\n    <tr><td>CC1.1 integrity and ethics<\/td><td>Code of conduct with acknowledgements<\/td><td>Acknowledgement per person, dated in period<\/td><\/tr>\n    <tr><td>CC1.3 structure and authority<\/td><td>Org chart, role definitions<\/td><td>Version dated, showing reporting lines<\/td><\/tr>\n    <tr><td>CC1.4 competence<\/td><td>Security training completion records<\/td><td>Per-person completion with dates, not a course link<\/td><\/tr>\n    <tr><td>CC2.1 information quality<\/td><td>Log and monitoring configuration<\/td><td>Config view plus a sample of retained output<\/td><\/tr>\n    <tr><td>CC3.1 to CC3.3 risk assessment<\/td><td>Risk register, scoring rationale, decisions<\/td><td>Evidence of periodic review, not a static document<\/td><\/tr>\n    <tr><td>CC4.1 monitoring activities<\/td><td>Penetration test, internal audit output<\/td><td>Dated inside the window, with remediation tracked<\/td><\/tr>\n    <tr><td>CC5.1 to CC5.3 control activities<\/td><td>Policies mapped to controls<\/td><td>Approval record and review date on each policy<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 class=\"s3\" id=\"cc6\">CC6, access control<\/h2>\n\n<p>This family produces more evidence requests than any other, because most of its controls combine a system state with a human decision.<\/p>\n\n<table>\n  <thead><tr><th>Control<\/th><th>What to produce<\/th><th>What makes it pass<\/th><\/tr><\/thead>\n  <tbody>\n    <tr><td>CC6.1 logical access<\/td><td>Identity provider config, MFA enforcement, user list<\/td><td>Console view matching the export, not the export alone<\/td><\/tr>\n    <tr><td>CC6.2 registration<\/td><td>Provisioning tickets for new joiners<\/td><td>Request, approval and completion linked per person<\/td><\/tr>\n    <tr><td>CC6.3 modification and removal<\/td><td>Deprovisioning records for leavers<\/td><td>Timestamps showing removal within your stated window<\/td><\/tr>\n    <tr><td>CC6.4 physical access<\/td><td>Data centre attestation or office access records<\/td><td>Cloud provider report is normally acceptable here<\/td><\/tr>\n    <tr><td>CC6.6 external threats<\/td><td>Firewall, WAF and network protection config<\/td><td>Evidence it is enforcing, not in monitoring mode<\/td><\/tr>\n    <tr><td>CC6.7 transmission and disposal<\/td><td>Encryption in transit config, disposal records<\/td><td>TLS settings plus documented disposal procedure<\/td><\/tr>\n    <tr><td>CC6.8 malicious software<\/td><td>Endpoint agent coverage report<\/td><td>Coverage reconciled against total device count<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 class=\"s4\" id=\"cc7\">CC7 to CC9, operations and change<\/h2>\n\n<table>\n  <thead><tr><th>Control<\/th><th>What to produce<\/th><th>What makes it pass<\/th><\/tr><\/thead>\n  <tbody>\n    <tr><td>CC7.1 vulnerability detection<\/td><td>Scan output across the period<\/td><td>Scans at your stated frequency, no unexplained gaps<\/td><\/tr>\n    <tr><td>CC7.2 monitoring for anomalies<\/td><td>Alert configuration and triage records<\/td><td>Records showing somebody reviewed and acted on alerts<\/td><\/tr>\n    <tr><td>CC7.3 evaluation of events<\/td><td>Incident records with severity assessment<\/td><td>Assessment reasoning, even for events judged minor<\/td><\/tr>\n    <tr><td>CC7.4 incident response<\/td><td>Incident response plan, plus any real incidents<\/td><td>Plan tested or exercised, with a record<\/td><\/tr>\n    <tr><td>CC7.5 recovery<\/td><td>Backup configuration and restore test results<\/td><td>A completed restore test, not backup success logs<\/td><\/tr>\n    <tr><td>CC8.1 change management<\/td><td>Change records with approvals<\/td><td>Approval separate from the person who made the change<\/td><\/tr>\n    <tr><td>CC9.1 risk mitigation<\/td><td>Business continuity plan, insurance<\/td><td>Reviewed and dated within the period<\/td><\/tr>\n    <tr><td>CC9.2 vendor management<\/td><td>Vendor register with risk ratings<\/td><td>Sub-processor reports collected and reviewed<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 class=\"s5\" id=\"fail\">Six SOC 2 controls whose evidence fails most often<\/h2>\n\n<div class=\"trio\">\n  <div class=\"cd a\"><h5>Access review with no sign-off<\/h5><p>A permissions export shows state. The control is that somebody reviewed it and decided. Record the reviewer and the date.<\/p><\/div>\n  <div class=\"cd b\"><h5>Penetration test outside the window<\/h5><p>A test dated before the period opened does not evidence operation during it. Schedule early in the window.<\/p><\/div>\n  <div class=\"cd d\"><h5>Inventory that will not reconcile<\/h5><p>Device count against headcount is the first thing checked. Reconcile before fieldwork or expect questions.<\/p><\/div>\n<\/div>\n<div class=\"trio\">\n  <div class=\"cd c\"><h5>Approvals living in chat<\/h5><p>Retrievable in month one, painful in month nine. Approvals in the change system survive sampling.<\/p><\/div>\n  <div class=\"cd e\"><h5>Backups with no restore test<\/h5><p>Successful backup jobs are not recovery evidence. The restore test is the control.<\/p><\/div>\n  <div class=\"cd a\"><h5>One snapshot for a whole period<\/h5><p>A Type II tests operation over time. A single dated image evidences a single date.<\/p><\/div>\n<\/div>\n\n<h2 class=\"s1\">How Osto reduces the pile<\/h2>\n\n<p>The controls that create the most evidence work, access, endpoint coverage, vulnerability detection, change and web protection, all run inside Osto. Because the controls and the compliance mapping share a platform, the artifact is generated by the system enforcing the control rather than reconstructed afterwards from an API read of a separate product.<\/p>\n\n<p>Governance evidence stays yours. Risk decisions, policy approvals and review sign-offs are human judgments and no platform produces them for you.<\/p>\n\n<div class=\"cta\">\n  <h3>See which controls produce clean evidence today<\/h3>\n  <p>A free assessment maps your controls to their evidence sources and flags the ones that will generate re-evidence requests.<\/p>\n  <div class=\"btns\">\n    <a class=\"p\" href=\"https:\/\/www.osto.one\/contact\"><span>Get a free security assessment<\/span><\/a>\n    <a class=\"s\" href=\"https:\/\/www.osto.one\/book-demo\"><span>Book a platform walkthrough<\/span><\/a>\n  <\/div>\n<\/div>\n\n<h2 class=\"s2\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What evidence do I need for SOC 2?<\/summary>\n  <p>Evidence varies by control, but every artifact needs four properties: a visible system timestamp, attribution showing who produced it and from where, an uncropped view including URL and user context, and a date inside the observation window. Missing any one of the four is the most common reason evidence is returned.<\/p>\n<\/details>\n<details>\n  <summary>What is the most common SOC 2 evidence mistake?<\/summary>\n  <p>Submitting a single snapshot as proof that a control operated across an entire period. A Type II examines operation over time, and auditors sample dates across the window. One screenshot demonstrates one moment, not a period.<\/p>\n<\/details>\n<details>\n  <summary>Do access reviews need manager sign-off?<\/summary>\n  <p>In practice, yes. An export of current permissions shows state. The control being tested is that somebody with authority reviewed that state and made a decision. Without recorded sign-off, you have evidence of configuration rather than evidence of review.<\/p>\n<\/details>\n<details>\n  <summary>Does a penetration test have to fall inside the observation window?<\/summary>\n  <p>It should. A test dated before the window opened generally does not evidence that the control operated during the period under examination. Scheduling the test early in the window, leaving time to remediate and retest, avoids the problem.<\/p>\n<\/details>\n<details>\n  <summary>Why does my asset inventory keep getting questioned?<\/summary>\n  <p>Because it usually does not reconcile against another source. If your device management console lists forty five machines and HR lists sixty people, an auditor will ask about the difference. Reconciling the two before fieldwork removes an entire round of questions.<\/p>\n<\/details>\n<details>\n  <summary>Are approvals in Slack acceptable as evidence?<\/summary>\n  <p>Sometimes, if the message shows who approved, what was approved and when, and can be produced reliably for sampled dates. The failure mode is that chat approvals are hard to retrieve consistently months later. Approvals recorded in the change system itself are far more durable.<\/p>\n<\/details>\n\n<div class=\"foot\">\n  <p><strong>Related reading:<\/strong> <a href=\"https:\/\/www.osto.one\/blog\/soc-2-controls-cc1-cc9\/\">SOC 2 controls CC1 to CC9<\/a> &middot; <a href=\"https:\/\/www.osto.one\/blog\/soc-2-evidence-collection\/\">SOC 2 evidence collection<\/a> &middot; <a href=\"https:\/\/www.osto.one\/blog\/soc-2-readiness-checklist\/\">SOC 2 readiness checklist<\/a><\/p>\n  <p><strong>Accuracy note:<\/strong> Control references follow the SOC 2 Trust Services Criteria. Evidence expectations vary by auditor, scope and how each control is implemented. Confirm formats with your auditor during planning. Current to August 2026. Osto helps companies deploy controls and reach audit readiness; attestations are issued by accredited independent auditors.<\/p>\n<\/div>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n \"@context\": \"https:\/\/schema.org\",\n \"@type\": \"FAQPage\",\n \"mainEntity\": [\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What evidence do I need for SOC 2?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Evidence varies by control, but every artifact needs four properties: a visible system timestamp, attribution showing who produced it and from where, an uncropped view including URL and user context, and a date inside the observation window. Missing any one of the four is the most common reason evidence is returned.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What is the most common SOC 2 evidence mistake?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Submitting a single snapshot as proof that a control operated across an entire period. A Type II examines operation over time, and auditors sample dates across the window. One screenshot demonstrates one moment, not a period.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Do access reviews need manager sign-off?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"In practice, yes. An export of current permissions shows state. The control being tested is that somebody with authority reviewed that state and made a decision. Without recorded sign-off, you have evidence of configuration rather than evidence of review.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Does a penetration test have to fall inside the observation window?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"It should. A test dated before the window opened generally does not evidence that the control operated during the period under examination. Scheduling the test early in the window, leaving time to remediate and retest, avoids the problem.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Why does my asset inventory keep getting questioned?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Because it usually does not reconcile against another source. If your device management console lists forty five machines and HR lists sixty people, an auditor will ask about the difference. Reconciling the two before fieldwork removes an entire round of questions.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Are approvals in Slack acceptable as evidence?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Sometimes, if the message shows who approved, what was approved and when, and can be produced reliably for sampled dates. The failure mode is that chat approvals are hard to retrieve consistently months later. Approvals recorded in the change system itself are far more durable.\"\n   }\n  }\n ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>A control-by-control reference for what an auditor will ask to see, and what makes each artifact pass first time. SOC\u2026<\/p>\n","protected":false},"author":8,"featured_media":998,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[211],"tags":[449,448,446,447],"class_list":["post-997","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guides","tag-cc6-controls","tag-soc-2-audit-checklist","tag-soc-2-controls-list","tag-soc-2-trust-services-criteria"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=997"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/997\/revisions"}],"predecessor-version":[{"id":999,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/997\/revisions\/999"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/998"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}