SOC 2 evidence tracker builder
The evidence list is the part of a first audit nobody sizes in advance. This builds yours from your criteria, your window and the systems you actually run.
A Type 2 audit tests whether controls operated across a period, so the evidence has to exist for the whole period rather than at the end of it. That one sentence is the difference between a routine audit and a bad quarter, and almost every first-time team learns it two months into a window that already has holes in it.
Answer six questions and you get the list: every item, the cadence it has to be produced on, the artifact that satisfies it, and the populations an auditor will sample from. The list is on the page. The spreadsheet version is the only thing at the end that asks for an address.
On its way
The tracker is written by a person against the answers you gave rather than generated, so allow one working day. If you would rather talk it through, book a time.
Why the populations matter more than the artifacts
Auditors do not review every change or every hire. They ask for the complete population for the period, select a sample from it, and request evidence for each selected item. So the list your population comes from is tested before any individual artifact is.
If your list of terminations misses a contractor and the auditor finds that person another way, the question stops being about one offboarding and becomes whether any of your populations can be relied on. That can expand testing across the engagement. Build every population from a query against a system rather than from memory, save the query, and use the same one each time so the numbers reconcile.
Naming that saves you a meeting
One folder per control, and inside it every file named with the date first in
ISO format, then the system, then what it shows. A file called
2026-04-14-okta-access-review-production.pdf answers an auditor's
first three questions before it is opened. Keep superseded evidence rather than
replacing it, because the audit tests a period and the March version is the one
that matters for March.
Common questions
How many evidence items does a SOC 2 Type 2 need?
A first audit against the security criterion usually produces a request list in the low hundreds of items, though many single artifacts cover several controls. Volume is rarely the problem. Timing is, because items have to exist across the whole period and cannot be produced afterwards for a month that has already passed.
Can we start collecting evidence before the window opens?
You should set up the collection routine before it opens, and evidence produced before the window still counts as evidence that a control exists. What it cannot do is evidence operation during the period. At least one full cycle of every periodic control has to fall inside the window, so a quarterly review done the week before the start date does not count.
Does a compliance platform collect all of this?
No. Platforms cover configuration state and user lists well, which is a real share of the list and the tedious part. What they do not cover is anything involving human judgement: a completed access review with a decision recorded, an approved policy, a vendor assessment, a tabletop, a risk assessment, an incident write-up. That remainder is most of the manual work in a first audit.
What happens if we are missing evidence for one month?
Tell the auditor rather than producing something dated to fill the gap. A missed cycle usually results in an exception noted in the report, which is survivable and which most customers accept alongside a remediation plan. Reconstructing a record after the fact is a different category of problem and it can end the engagement with the firm.
Not sure your evidence would survive sampling
Send your control list and where you are in the window, and we will tell you what an auditor would push back on.
Get matched