The SOC 2 Audit Checklist

Compliance / SOC 2 / Audit Checklist
Compliance & Audit Readiness

The SOC 2 Audit Checklist

The policies you need in writing, the evidence types an auditor will actually sample, and the mistakes that turn a routine audit day into a stressful one.

Schedule a Consultation →

Documentation

Policies You Need in Writing

Auditors expect these as living documents with a named owner and a review date, not a one-time template download.

Information security policy
Access control policy
Change management policy
Incident response plan
Vendor / third-party risk management policy
Risk assessment methodology and register
Business continuity / disaster recovery plan
Security awareness training policy
Data classification and handling policy
Acceptable use policy
Proof, Not Paper

Evidence Types Auditors Actually Sample

A policy states intent. Evidence proves the control ran. Type II auditors sample the latter, drawn from real dates inside the observation window.

Access review recordsQuarterly (or defined-cadence) user access certifications with sign-off.
Change ticketsApproval, testing, and deployment records for a sample of production changes.
Security logs and alertsEvidence of active monitoring and documented response to flagged events.
Vulnerability scan resultsScan cadence, findings, and remediation timelines against defined SLAs.
Onboarding / offboarding recordsTimely account provisioning and, critically, timely deprovisioning on termination.
Vendor risk assessmentsDocumented review of subprocessors and critical vendors before and during the relationship.
Training completion recordsSecurity awareness training completion by employee, tied to onboarding and an annual cadence.
Backup and recovery test resultsEvidence that backups were not just taken, but successfully restored on a test basis.
Learn From Others’ Mistakes

Common Audit-Day Pitfalls

The policy exists, but nobody followed it

A beautifully written access-review policy with zero completed reviews on file is worse than no policy — it proves the control was known and skipped, not merely undocumented.

Evidence assembled retroactively

Type II evidence has to be generated during the observation window as a byproduct of real operations. Backdating a spreadsheet the week before fieldwork is exactly the kind of exception auditors are trained to catch.

Offboarding lag

A terminated employee whose access wasn’t revoked for days or weeks is one of the single most common exceptions auditors find, because it’s easy to check and easy to miss operationally.

Nobody owns the evidence trail

If no single person is responsible for collecting and organizing evidence as it’s generated, audit-day scrambling to reconstruct six months of history is the predictable result.

Scope creep mid-engagement

New systems, new vendors, or a new product line added after the observation window opens without updating the control inventory creates an evidence gap for anything added late.

Treating SOC 2 as a one-time project

Controls that run hard for the observation window and lapse right after produce a clean report and a much harder renewal audit next year.

Most of these gaps surface earliest in a SOC 2 readiness assessment — well before an auditor is in the room. See how that process works.

Don’t Let Audit Day Be the First Time You Find Out

Armorstack builds the evidence trail into daily operations, so audit day is a formality instead of a fire drill.