What happens during SOC 2 fieldwork?
During SOC 2 fieldwork, your CPA auditor examines the evidence for your controls — sampling access reviews, tickets, logs, and configurations — interviews your team, and tests whether each control operated as described before drafting the report.
The full answer
Fieldwork is the phase where the auditor actually does the testing. SOC 2 reports are attestations issued under the AICPA's SSAE No. 18 standard by licensed CPA firms, so fieldwork is a structured evidence review, not a casual look. The auditor works from the control list defined in your scope and gathers proof that each one was designed properly and, for a Type 2, operated across the observation window.
Concretely, expect evidence requests and sampling. The auditor pulls examples from across the period — user access reviews, onboarding and offboarding tickets, change-management records, backup logs, vulnerability scans, and system configurations — and checks them against what your policies say should happen. For a Type 2 they sample multiple points in the window, not just one snapshot, to confirm the control ran consistently.
There is a human side too: interviews and walkthroughs. The auditor talks with control owners to understand how a process really works and may ask for a live demonstration. Because AICPA independence rules bar the audit firm from designing or operating your controls, they observe and test — they cannot fix gaps for you.
When your auditor has a confirmed integration with a GRC platform like Vanta, Drata, or Secureframe, much of the evidence is pulled directly, which shortens fieldwork and cuts email back-and-forth. SOC 2 audits booked through the AuditNex network start at $2,500 promotionally and average about $5,000 per the 2026 rate card; to see fixed-scope pricing before you commit, request a quote based on your specific control set.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Can I speed up a SOC 2 audit?
Yes, partly. You can compress readiness and fieldwork with a GRC platform, a Type 1 or 3-month Type 2 first, and fast evidence responses — but a Type 2 observation window still has to run its full length.
Can a SOC 2 Type 2 observation period be 3 months?
Yes. Three months is the shortest observation window most auditors will accept for a SOC 2 Type 2, so a 3-month period is valid and common for a first report. Longer windows give buyers more assurance.
Do SOC 2 audits happen on-site or remotely?
Almost always remotely. Most SOC 2 audits are conducted entirely over video calls, screen shares, and secure evidence uploads, since the evidence is digital. On-site visits are rare and usually only relevant if you run your own physical data centers.
How long does a SOC 2 audit take?
A SOC 2 Type 1 usually takes one to three months end to end, while a Type 2 adds an observation window of three to twelve months. Readiness prep, not the audit itself, is often the longest phase.
How long does the SOC 2 report take after fieldwork ends?
Most SOC 2 reports are drafted and delivered within a few weeks of fieldwork ending, though timing varies by firm and how quickly you clear any open evidence items. There is no AICPA-set deadline for delivery.
How many internal hours does a SOC 2 audit take my team?
There is no official figure. Most internal effort is front-loaded during readiness, not the audit itself. Expect a designated owner to spend meaningful part-time hours over the prep window, plus lighter time answering auditor questions during fieldwork.
Sources: AICPA SSAE No. 18 attestation standards; AICPA independence rules for attestation engagements; AuditNex network rate card (2026). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.