18 min read · Updated July 2026

SOC 2 Type II evidence checklist

A control-by-control list of what auditors actually accept — organized by the 2017 Trust Services Criteria points of focus. Everything below is what we ship in Lumiaxiom's SOC 2 evidence pack, based on hundreds of Type II fieldwork engagements.

How auditors think about evidence

  • Population + sample. Auditors want the full population of events (e.g., every new hire), then sample from it.
  • Timing across the period. Evidence must span the audit window (usually 6–12 months). One artifact at year-end doesn't cut it.
  • Independence. The person performing the control shouldn't be the person reviewing it.
  • Tamper-resistance. A screenshot is weaker than a system-generated report; a hash-chained ledger is strongest.

Common Criteria — Control Environment (CC1)

CC1.1Board oversight & tone-at-the-top

Signed board charter, quarterly minutes, code of conduct acknowledgements.

CC1.4Hiring & background checks

Signed offer letters, completed background check reports, competency review records.

CC1.5Accountability & performance reviews

Documented job descriptions, annual performance reviews, disciplinary policy.

Communication & Information (CC2)

CC2.1Internal information policies

Published information security policy, acceptable use policy, distribution log with signed acknowledgements.

CC2.3External communication

Trust portal, published security page, incident notification workflow.

Risk Assessment (CC3)

CC3.1Documented risk assessment

Risk register with scoring methodology, quarterly review evidence.

CC3.2Fraud risk

Fraud risk memo, segregation-of-duties mapping.

CC3.4Change assessment

Ticketed change requests, risk-impact assessment for material changes.

Monitoring (CC4)

CC4.1Ongoing evaluations

Continuous control monitoring reports, evidence of remediation.

CC4.2Deficiency communication

Ticketing system evidence, escalation policy, exception log.

Control Activities (CC5)

CC5.2Technology general controls

SDLC policy, change management tickets, deployment logs.

Logical & Physical Access (CC6)

CC6.1Logical access controls

IAM policy, MFA enforcement report, RBAC role catalog.

CC6.2New-user provisioning

Signed access request tickets, joiner-mover-leaver logs.

CC6.3Access review

Quarterly access review completion certificates with sign-off.

CC6.6Encryption in transit

TLS configuration report (e.g., SSL Labs A+), cert inventory.

CC6.7Encryption at rest

KMS configuration, disk-encryption evidence.

CC6.8Malicious software prevention

EDR coverage report, patch compliance dashboard.

System Operations (CC7)

CC7.1Vulnerability management

Scan results (SAST/DAST/dependency), remediation SLA metrics.

CC7.2Monitoring & anomaly detection

SIEM alert catalog, sample tuned rules, on-call runbook.

CC7.3Incident response

IR plan, tabletop exercise report, closed-incident post-mortems.

CC7.4Incident recovery

Backup test evidence, RTO/RPO documented, DR test report.

Change Management (CC8)

CC8.1Change authorization

PR review policy, merge protections, evidence of peer review.

Risk Mitigation (CC9) + Vendor Management

CC9.2Vendor risk assessment

Vendor inventory, tiered assessment questionnaires, SOC 2 reviews on file.

Common failure modes

  • Missing access reviews. Quarterly is table stakes — auditors will sample every quarter, not just the most recent.
  • Screenshot-only vendor reviews. Store the vendor's actual SOC 2 report, DPA, and risk tier.
  • Untested DR. A DR runbook without a completed test in the audit window is a qualifier.
  • MFA gaps. Even one privileged account without MFA fails CC6.1 sampling.
  • Post-mortem-less incidents. Every P1/P2 needs a documented root-cause and corrective action.

Ship SOC 2 evidence continuously

Lumiaxiom's Evidence Vault collects, hashes, and chains every artifact above automatically.