The single biggest driver of a painful SOC 2 fieldwork is not the number of controls. It is whether the evidence already exists in a form the auditor can use, or whether your team has to go and manufacture it after the period has closed.

Reconstructed SOC 2 evidence is always worse than evidence captured as it happened. A screenshot taken during fieldwork shows the state today, not the state in month two of your observation window. An access review performed the week before the request list arrives has a date on it, and that date is visible in the report. The way out is to capture evidence at the moment the control operates, which costs almost nothing, instead of at the moment the auditor asks, which costs weeks.

Populations come before samples

For a Type 2, the auditor tests whether controls operated throughout the period, and to do that they select samples. Before they can select a sample, you must give them a complete population — every instance of the thing, across the whole period.

Common populations include all employees hired during the period, all employees terminated during the period, all users with access to production systems, all changes deployed to production, all security incidents, all new vendors onboarded, and all customer-reported issues meeting your severity threshold.

Completeness is what the auditor will probe, and the question is usually the same: how do you know this list is everything? A ticket export filtered by a label is not complete if people sometimes forget the label. A list of deploys from one pipeline is not complete if there is a second path to production.

Nail this early. If your population is unreliable, everything sampled from it is unreliable too, and no amount of good individual evidence fixes that.

What good evidence has on it

Regardless of control, the auditor is looking for the same attributes. Evidence should show:

  • What happened — the specific action, not a general capability
  • When — a system-generated timestamp inside the period, ideally not one you typed
  • Who — the person who performed it and, separately, the person who approved it
  • Against what — the standard, policy, ticket or request it satisfies

Two failure patterns account for most rework. The first is evidence with no date, or with a date outside the period. The second is evidence where the performer and the approver are the same person, which means the control does not do what your description says it does.

The requests that show up almost every time

Access management. User listings for in-scope systems, showing role or permission level. Access request and approval records for a sample of new joiners. Evidence that access reviews were performed for each required cycle, with the reviewer’s name, the date, and what happened to the accounts flagged for removal. Termination evidence tying a leaver’s last day to the timestamp their access was revoked.

Change management. For a sample of production changes: the ticket describing the change, evidence of code review or approval by someone other than the author, test or CI results, and the deployment record. If you deploy dozens of times a day, agree the sampling approach with the auditor in advance rather than assuming.

Onboarding and offboarding. Background check confirmations where your policy requires them, signed policy acknowledgements, security awareness training completion records, and asset return or wipe records for leavers.

Vulnerability and patch management. Scan results across the period, not just the most recent. Evidence that findings were triaged and remediated within the timeframe your own policy states. Penetration test report and evidence of what you did about the findings.

Incident response. The incident log for the period, and for a sample of incidents: detection time, severity assignment, actions taken, resolution, and any customer notification. Also the tabletop exercise or simulation your policy commits you to, with participants and date.

Risk assessment and vendor management. The completed risk assessment with dates and participants. Vendor inventory with criticality ratings, evidence of due diligence for a sample of new vendors, and evidence you reviewed subservice organization reports where you carved them out.

Business continuity and backups. Backup configuration and evidence of successful restoration testing during the period. The BC/DR test with a date, scope, participants and outcome — including what went wrong and what you changed.

Governance. Approved policies with version and approval dates, board or management meeting evidence where your description says oversight occurs, and organizational structure with defined responsibilities.

How to collect it once

Make the control produce its own record. If access reviews happen in a ticket with a checklist and a sign-off field, the evidence is a by-product of doing the work. If they happen in a spreadsheet someone emails around, evidence collection is a separate project every year.

Export monthly, not at the end. Populations degrade. Ticketing systems get reorganized, people leave, logs roll off retention. A recurring monthly task that exports user listings, change records, incident logs and scan results into a dated folder removes most fieldwork pain for an hour of work a month.

Check your log retention against your period. This catches people out. A twelve-month observation window and ninety days of log retention means nine months of evidence that no longer exists. Confirm retention before your window starts, not during fieldwork.

Name and date everything consistently. Something like 2026-03-31_prod-access-review_signed.pdf beats access review final v2 (1).pdf. When the auditor asks for the Q1 review, you find it in seconds.

Prefer system-generated over hand-made. An export from the tool is stronger than a screenshot, and a screenshot showing the full window with the system clock and the logged-in user is stronger than a cropped one.

Keep an evidence register. A simple table: control, evidence type, where it lives, who owns it, how often it is captured. This survives staff turnover, which the tribal knowledge version does not.

What to do when evidence is missing

Sometimes a control operated and nobody recorded it. Do not fabricate a record — this is the one place where a small shortcut becomes a serious problem, and backdated evidence is both detectable and disqualifying.

Tell the auditor what happened. Offer whatever corroboration genuinely exists: calendar entries, chat history, related tickets. Depending on the control and what other evidence supports it, an auditor may accept alternative evidence, or may conclude the control cannot be tested for that instance. That is a normal outcome and it is survivable. A report with one honest exception and a sensible management response is far better than a report resting on something invented.

What to do next

Pick your three most sampled controls — access reviews, change approvals and terminations are the usual ones — and try to produce a complete population for last quarter right now, without asking anyone for help.

If you cannot, you have found the work that would otherwise land on your team during fieldwork. Fixing it means changing where the control runs, not writing another policy. Assurion is a licensed CPA firm performing SOC 2 examinations, and we would rather tell you about an evidence gap before your observation window starts than after it closes.