Collecting SOC 2 evidence without a platform
Below roughly thirty people, a shared drive and a set of recurring calendar entries will carry you through a first Type 2. This is what that setup looks like in practice.
A first SOC 2 Type 2 for a company under about thirty people needs three things and no software: a dated folder structure on a shared drive, a naming convention that puts the date first, and a recurring calendar entry with a named owner for every periodic control. A team of that size typically produces somewhere around 120 evidence items across a twelve month window, which is a few hours a month, not a full-time job.
Under 30 Headcount where a spreadsheet is genuinely enough
2 to 4 hours Evidence work per month at that size
How much evidence are we actually talking about?
The volume is what decides this, and it is smaller than people expect. Most of it clusters in two control families, and both of those produce their evidence as a side effect of work you were doing anyway.
| Control family | Items | Where most of it comes from |
|---|---|---|
| People, joiners, leavers, training | 30 | Tickets and the training export |
| Access control and reviews | 24 | Quarterly exports per system |
| Monitoring and vulnerabilities | 24 | Monthly scan reports and alert samples |
| Vendors | 14 | The register plus annual reviews |
| Change management | 12 | The pull request history, already there |
| Policy and governance | 10 | Approvals, risk assessment, management review |
| Backup and resilience | 8 | Restore test and continuity exercise |
| Total for the window | 122 | Roughly ten items a month |
The folder structure and the naming convention
One folder per control family, one subfolder per period, and a filename that sorts correctly and identifies itself out of context. The date goes first because the auditor will download forty files into one directory and you want them in order.
| Folder | Naming pattern | Example |
|---|---|---|
| 01-access/ | YYYY-MM-DD_system_artifact | 2026-04-01_okta_user-export.csv |
| 02-people/ | YYYY-MM-DD_type_person-initials | 2026-05-12_offboard_jm.pdf |
| 03-change/ | YYYY-MM-DD_change-id | 2026-06-18_pr-2841.pdf |
| 04-monitoring/ | YYYY-MM-DD_tool_scope | 2026-07-01_scanner_prod-hosts.pdf |
| 05-vendors/ | YYYY-MM-DD_vendor_artifact | 2026-03-09_awscloud_soc2-review.pdf |
| 06-resilience/ | YYYY-MM-DD_artifact | 2026-08-22_restore-test.pdf |
| 07-policy/ | YYYY-MM-DD_policy_vN | 2026-01-15_access-control_v3.pdf |
| 00-population/ | YYYY-MM-DD_population_name | 2026-09-01_population_leavers.csv |
The last folder is the one people forget and the one that saves the audit. Populations are what the auditor samples from, and generating them once at the end from memory is how contractors go missing. Generate each population from a query on the same day each month and file it, so the list is a record rather than a reconstruction. The evidence collection page covers why that matters.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The calendar, which is the actual system
The spreadsheet tracks what is owed. The calendar is what makes it happen. One recurring entry per periodic control, assigned to a person by name rather than to a team address, with the filing location in the invite body.
| Control | Cadence | Typical owner | Time per run |
|---|---|---|---|
| Access review, per system | Quarterly | System owner | 60 to 90 minutes |
| Vulnerability scan and triage | Monthly | Platform engineer | 30 minutes |
| HR to identity provider reconciliation | Monthly | Whoever owns onboarding | 15 minutes |
| Population exports | Monthly | Program owner | 20 minutes |
| Vendor review | Annual, staggered | Program owner | 2 hours total |
| Restore test | Annual | Platform engineer | Half a day |
| Management review of the program | Quarterly | Executive sponsor | 45 minutes |
| Policy review and approval | Annual | Program owner | 1 day, once |
- Create the folders and the population folder before the window opens, not after.
- Build the tracker: one row per control, with the artifact, the cadence, the owner and the folder path. The evidence tracker generates this from your criteria and window if you would rather not start from an empty sheet.
- Put every periodic row in the calendar with a named person on it.
- Capture evidence at the moment the control runs, never in a catch-up session.
- Review the tracker monthly and chase what is missing while it can still be produced honestly.
When does this stop working, and who does it fail?
The setup above fails on four things, and headcount is only a proxy for them. It fails when the population lists can no longer be produced by one person running a handful of queries, which is usually somewhere between forty and sixty staff. It fails when you take on a second framework, because maintaining two mappings by hand is worse work than paying for it. It fails when a customer contract commits you to continuous monitoring rather than periodic evidence. And it fails when the person who built the folders leaves, because nothing in the system is enforced by anything except their habits.
It also fails earlier than thirty people if your vendor evidence is complicated. A Canadian company sending personal information to processors outside the country carries accountability for it under PIPEDA regardless of where the data sits, and if you are transferring personal information out of Quebec, Law 25 wants a privacy impact assessment before you do. That turns the vendor register from a list into a set of assessments with review dates, and it is the one folder that benefits from tooling sooner than the rest.
When you cross those lines, the platforms are worth their price: Vanta, Drata and Sprinto all automate the collection and the monitoring, and none of them will make your scope decisions, write your system description or fix a control you do not have. Expect $8,000 to $30,000 CAD a year depending on headcount and modules. Buying one at twelve people usually means paying for evidence collection you could have done in two hours a month, and learning less about your own controls in the process.
The folder structure above is not the only way to do this at no cost. A free compliance workspace gives you the same evidence register with the control mapping already done, which removes the two failure modes on this page: the population folder nobody created, and the tracker that lives in one person's habits. TrazTech, which operates this site, runs one called traztech Workspace. It checks AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira on a daily schedule and files the result against the control it proves, so the folders above carry everything those seven do not reach. What it has no answer for is endpoint and HR evidence, which is where a paid platform earns the money. Readiness without a paid platform compares the three options artifact by artifact.
Why does manually collected evidence get rejected?
Not because it was manual. Auditors accept manual evidence constantly. It gets rejected for four specific defects that tooling happens to prevent.
- Screenshots with no date in frame. The cost of manual collection is that you have to remember to include the clock. Prefer an export every time the system offers one.
- Files whose names do not say what they are. A folder of items called screenshot-4.png forces the auditor to ask about each one, and every question is a delay.
- Populations assembled at the end. A leaver list typed from memory in month eleven is the defect that costs the most, because it puts every other population in doubt.
- Evidence with no owner. A control assigned to the team is a control assigned to nobody, and it is the reason the gap always appears in the months where everyone was busy.
Set this up in an afternoon
0 of 7 done ·
The checklist is the control list this structure files against, and the access review evidence page covers the single control that produces the most manual work in the folders above. Doing the whole preparation this way, not only the evidence, is costed on SOC 2 prep with no compliance budget.
Get through a SOC 2 without buying a platform
Plenty of companies pass a first Type II on spreadsheets and a shared drive. Send your scope and compare readiness firms that will work the way you already do.
Get matchedCommon questions
Will an auditor take us less seriously without a platform?
No. Auditors work from a request list and care whether the evidence is complete, dated and attributable. A tidy shared drive with consistent naming is faster for them to work through than a platform export nobody has curated.
What is the real cost of doing it manually?
Two to four hours a month of one person's time for a company under thirty people, concentrated at quarter ends when access reviews run. That is materially cheaper than $8,000 to $30,000 CAD a year, and the tradeoff flips once the same work takes a day a week.
Can we start manually and move to a platform later?
Yes, and it is the usual path. Migrating means re-uploading historical evidence, which is tedious but not difficult, and the folder structure maps reasonably well onto how the platforms organize things. Doing year one manually also means you understand your own controls before a tool starts reporting on them.
Does a spreadsheet work for a Type 1?
Easily. A Type 1 tests design at a point in time, so there is no window of recurring evidence to keep up with. The manual approach is only ever strained by the repetition a Type 2 demands.
Who should own the shared drive?
One named person with the authority to chase people, normally whoever owns the program. Shared ownership across three people produces a drive where nobody knows what is missing, which is the failure this whole structure exists to prevent.