What evidence do SOC 2 auditors ask for?
SOC 2 auditors ask for evidence that your controls actually operated: access and MFA settings, onboarding and offboarding records, access reviews, change-management tickets, vulnerability scans, backup and incident logs, vendor reviews, and signed policies covering the period.
The full answer
Evidence proves that a control did what your policy says, not just that a policy exists. Under the AICPA's SSAE No. 18 attestation standards, a SOC 2 report is an opinion on your controls, so auditors sample real artifacts rather than take your word for it. The exact list depends on which Trust Services Criteria you scoped, but common requests are consistent.
Expect to hand over identity and access evidence — user lists, MFA configuration, role permissions, and periodic access reviews — plus HR records showing onboarding, offboarding, and security-awareness training. On the engineering side, auditors want change-management tickets, code-review or approval records, and infrastructure configurations.
They also request operational evidence: vulnerability scan or penetration-test results, patching records, backup and restore tests, encryption settings, logging and monitoring output, and incident records if any occurred. Governance items include your written policies, risk assessment, and vendor or subservice-organization reviews.
How the evidence is gathered differs by report type. A Type 1 captures the state at a point in time, while a Type 2 requires samples across the whole observation window, usually three to twelve months. GRC platforms such as Vanta, Drata, and Secureframe automate much of this, and auditors with confirmed integrations pull evidence directly from the platform — reducing screenshots and back-and-forth during fieldwork.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Can a two-person startup get SOC 2?
Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.
Do I need a penetration test for SOC 2?
Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.
Does SOC 2 cover remote work and BYOD?
Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.
Does SOC 2 require MFA?
Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.
Does SOC 2 require a vendor management program?
Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.
Does SOC 2 require annual security training?
Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.
Sources: AICPA SSAE No. 18 attestation standards; AICPA Trust Services Criteria (2017, rev. 2022). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.