SOC2Prep

Collecting SOC 2 evidence without a platform

Below roughly thirty people, a shared drive and a set of recurring calendar entries will carry you through a first Type 2. This is what that setup looks like in practice.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A first SOC 2 Type 2 for a company under about thirty people needs three things and no software: a dated folder structure on a shared drive, a naming convention that puts the date first, and a recurring calendar entry with a named owner for every periodic control. A team of that size typically produces somewhere around 120 evidence items across a twelve month window, which is a few hours a month, not a full-time job.

Under 30 Headcount where a spreadsheet is genuinely enough

2 to 4 hours Evidence work per month at that size

How much evidence are we actually talking about?

The volume is what decides this, and it is smaller than people expect. Most of it clusters in two control families, and both of those produce their evidence as a side effect of work you were doing anyway.

Evidence items by control family over a twelve month window People and access control produce the most items, around 30 and 24 respectively, while backup and policy work produce under a dozen each. 0 15 30 24 12 30 14 24 8 10 Access Change People Vendors Monitor Backup Policy Control family
Illustrative for a 25-person cloud company, security criterion only. The same figures are in the table below.
Evidence items over a 12-month window, illustrative 25-person company
Control familyItemsWhere most of it comes from
People, joiners, leavers, training30Tickets and the training export
Access control and reviews24Quarterly exports per system
Monitoring and vulnerabilities24Monthly scan reports and alert samples
Vendors14The register plus annual reviews
Change management12The pull request history, already there
Policy and governance10Approvals, risk assessment, management review
Backup and resilience8Restore test and continuity exercise
Total for the window122Roughly ten items a month

The folder structure and the naming convention

One folder per control family, one subfolder per period, and a filename that sorts correctly and identifies itself out of context. The date goes first because the auditor will download forty files into one directory and you want them in order.

Folder layout and file naming for a manual evidence set
FolderNaming patternExample
01-access/YYYY-MM-DD_system_artifact2026-04-01_okta_user-export.csv
02-people/YYYY-MM-DD_type_person-initials2026-05-12_offboard_jm.pdf
03-change/YYYY-MM-DD_change-id2026-06-18_pr-2841.pdf
04-monitoring/YYYY-MM-DD_tool_scope2026-07-01_scanner_prod-hosts.pdf
05-vendors/YYYY-MM-DD_vendor_artifact2026-03-09_awscloud_soc2-review.pdf
06-resilience/YYYY-MM-DD_artifact2026-08-22_restore-test.pdf
07-policy/YYYY-MM-DD_policy_vN2026-01-15_access-control_v3.pdf
00-population/YYYY-MM-DD_population_name2026-09-01_population_leavers.csv

The last folder is the one people forget and the one that saves the audit. Populations are what the auditor samples from, and generating them once at the end from memory is how contractors go missing. Generate each population from a query on the same day each month and file it, so the list is a record rather than a reconstruction. The evidence collection page covers why that matters.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The calendar, which is the actual system

The spreadsheet tracks what is owed. The calendar is what makes it happen. One recurring entry per periodic control, assigned to a person by name rather than to a team address, with the filing location in the invite body.

Periodic controls, cadence and owner for a small team
ControlCadenceTypical ownerTime per run
Access review, per systemQuarterlySystem owner60 to 90 minutes
Vulnerability scan and triageMonthlyPlatform engineer30 minutes
HR to identity provider reconciliationMonthlyWhoever owns onboarding15 minutes
Population exportsMonthlyProgram owner20 minutes
Vendor reviewAnnual, staggeredProgram owner2 hours total
Restore testAnnualPlatform engineerHalf a day
Management review of the programQuarterlyExecutive sponsor45 minutes
Policy review and approvalAnnualProgram owner1 day, once
  1. Create the folders and the population folder before the window opens, not after.
  2. Build the tracker: one row per control, with the artifact, the cadence, the owner and the folder path. The evidence tracker generates this from your criteria and window if you would rather not start from an empty sheet.
  3. Put every periodic row in the calendar with a named person on it.
  4. Capture evidence at the moment the control runs, never in a catch-up session.
  5. Review the tracker monthly and chase what is missing while it can still be produced honestly.

When does this stop working, and who does it fail?

The setup above fails on four things, and headcount is only a proxy for them. It fails when the population lists can no longer be produced by one person running a handful of queries, which is usually somewhere between forty and sixty staff. It fails when you take on a second framework, because maintaining two mappings by hand is worse work than paying for it. It fails when a customer contract commits you to continuous monitoring rather than periodic evidence. And it fails when the person who built the folders leaves, because nothing in the system is enforced by anything except their habits.

It also fails earlier than thirty people if your vendor evidence is complicated. A Canadian company sending personal information to processors outside the country carries accountability for it under PIPEDA regardless of where the data sits, and if you are transferring personal information out of Quebec, Law 25 wants a privacy impact assessment before you do. That turns the vendor register from a list into a set of assessments with review dates, and it is the one folder that benefits from tooling sooner than the rest.

When you cross those lines, the platforms are worth their price: Vanta, Drata and Sprinto all automate the collection and the monitoring, and none of them will make your scope decisions, write your system description or fix a control you do not have. Expect $8,000 to $30,000 CAD a year depending on headcount and modules. Buying one at twelve people usually means paying for evidence collection you could have done in two hours a month, and learning less about your own controls in the process.

The folder structure above is not the only way to do this at no cost. A free compliance workspace gives you the same evidence register with the control mapping already done, which removes the two failure modes on this page: the population folder nobody created, and the tracker that lives in one person's habits. TrazTech, which operates this site, runs one called traztech Workspace. It checks AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira on a daily schedule and files the result against the control it proves, so the folders above carry everything those seven do not reach. What it has no answer for is endpoint and HR evidence, which is where a paid platform earns the money. Readiness without a paid platform compares the three options artifact by artifact.

Why does manually collected evidence get rejected?

Not because it was manual. Auditors accept manual evidence constantly. It gets rejected for four specific defects that tooling happens to prevent.

  • Screenshots with no date in frame. The cost of manual collection is that you have to remember to include the clock. Prefer an export every time the system offers one.
  • Files whose names do not say what they are. A folder of items called screenshot-4.png forces the auditor to ask about each one, and every question is a delay.
  • Populations assembled at the end. A leaver list typed from memory in month eleven is the defect that costs the most, because it puts every other population in doubt.
  • Evidence with no owner. A control assigned to the team is a control assigned to nobody, and it is the reason the gap always appears in the months where everyone was busy.

Set this up in an afternoon

0 of 7 done ·

The checklist is the control list this structure files against, and the access review evidence page covers the single control that produces the most manual work in the folders above. Doing the whole preparation this way, not only the evidence, is costed on SOC 2 prep with no compliance budget.

Get through a SOC 2 without buying a platform

Plenty of companies pass a first Type II on spreadsheets and a shared drive. Send your scope and compare readiness firms that will work the way you already do.

Get matched

Common questions

Will an auditor take us less seriously without a platform?

No. Auditors work from a request list and care whether the evidence is complete, dated and attributable. A tidy shared drive with consistent naming is faster for them to work through than a platform export nobody has curated.

What is the real cost of doing it manually?

Two to four hours a month of one person's time for a company under thirty people, concentrated at quarter ends when access reviews run. That is materially cheaper than $8,000 to $30,000 CAD a year, and the tradeoff flips once the same work takes a day a week.

Can we start manually and move to a platform later?

Yes, and it is the usual path. Migrating means re-uploading historical evidence, which is tedious but not difficult, and the folder structure maps reasonably well onto how the platforms organize things. Doing year one manually also means you understand your own controls before a tool starts reporting on them.

Does a spreadsheet work for a Type 1?

Easily. A Type 1 tests design at a point in time, so there is no window of recurring evidence to keep up with. The manual approach is only ever strained by the repetition a Type 2 demands.

Who should own the shared drive?

One named person with the authority to chase people, normally whoever owns the program. Shared ownership across three people produces a drive where nobody knows what is missing, which is the failure this whole structure exists to prevent.