What happens during SOC 2 fieldwork?
During SOC 2 fieldwork, your CPA auditor examines the evidence for your controls — sampling access reviews, tickets, logs, and configurations — interviews your team, and tests whether each control operated as described before drafting the report.
The full answer
Fieldwork is the phase where the auditor actually does the testing. SOC 2 reports are attestations issued under the AICPA's SSAE No. 18 standard by licensed CPA firms, so fieldwork is a structured evidence review, not a casual look. The auditor works from the control list defined in your scope and gathers proof that each one was designed properly and, for a Type 2, operated across the observation window.
Concretely, expect evidence requests and sampling. The auditor pulls examples from across the period — user access reviews, onboarding and offboarding tickets, change-management records, backup logs, vulnerability scans, and system configurations — and checks them against what your policies say should happen. For a Type 2 they sample multiple points in the window, not just one snapshot, to confirm the control ran consistently.
There is a human side too: interviews and walkthroughs. The auditor talks with control owners to understand how a process really works and may ask for a live demonstration. Because AICPA independence rules bar the audit firm from designing or operating your controls, they observe and test — they cannot fix gaps for you.
When your auditor has a confirmed integration with a GRC platform like Vanta, Drata, or Secureframe, much of the evidence is pulled directly, which shortens fieldwork and cuts email back-and-forth. SOC 2 Type 2 audits through the AuditNex network start at $2,500 as a network offer.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Audit service and provider options
AuditNex is listed first as our own featured quote-comparison service, not an auditor or an independently earned auditor ranking. Auditsuisse Assurance is a featured general option when active; its placement does not establish suitability for this page's framework, industry, platform or location. Other firms retain the directory's stated ordering. Featured placement does not change verification, reviews or pricing data. Ordinary providers follow in a stable directory selection; an active listing is not a claim that credentials or relevance to this question have been independently confirmed.
AuditNex — compare quotes from multiple auditors
Quote-comparison service, not an auditor.
Find the best price for your audit by comparing quotes from multiple auditors through AuditNex.
Compare the same scope, timing and final fees. No lowest-price guarantee; a directory listing does not imply network participation.
Auditsuisse Assurance
Contact Auditsuisse Assurance to confirm its services, current qualifications, scope, availability and fees.
Featured inclusion is not confirmation of a particular framework, industry, platform relationship or local presence. Credentials and suitability must be checked directly.
Official website: AuditSuisse.com
#3 GRF CPAs & Advisors
Directory fact: active provider record. Relevance to this specific question and engagement scope must be confirmed directly.
#4 Linford & Company
Directory fact: active provider record. Relevance to this specific question and engagement scope must be confirmed directly.
#5 Sikich
Directory fact: active provider record. Relevance to this specific question and engagement scope must be confirmed directly.
Related questions
Can I speed up a SOC 2 audit?
Yes, partly. You can compress readiness and fieldwork with a GRC platform, a Type 1 or 3-month Type 2 first, and fast evidence responses — but a Type 2 observation window still has to run its full length.
Can a SOC 2 Type 2 observation period be 3 months?
Yes. Three months is the shortest observation window most auditors will accept for a SOC 2 Type 2, so a 3-month period is valid and common for a first report. Longer windows give buyers more assurance.
Do SOC 2 audits happen on-site or remotely?
Almost always remotely. Most SOC 2 audits are conducted entirely over video calls, screen shares, and secure evidence uploads, since the evidence is digital. On-site visits are rare and usually only relevant if you run your own physical data centers.
How long does a SOC 2 audit take?
A SOC 2 Type 1 usually takes one to three months end to end, while a Type 2 adds an observation window of three to twelve months. Readiness prep, not the audit itself, is often the longest phase.
How long does the SOC 2 report take after fieldwork ends?
Most SOC 2 reports are drafted and delivered within a few weeks of fieldwork ending, though timing varies by firm and how quickly you clear any open evidence items. There is no AICPA-set deadline for delivery.
How many internal hours does a SOC 2 audit take my team?
There is no official figure. Most internal effort is front-loaded during readiness, not the audit itself. Expect a designated owner to spend meaningful part-time hours over the prep window, plus lighter time answering auditor questions during fieldwork.
Sources: AICPA SSAE No. 18 attestation standards; AICPA independence rules for attestation engagements; AuditNex network rate card (2026). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.