18 min read · Updated July 2026
SOC 2 Type II evidence checklist
A control-by-control list of what auditors actually accept — organized by the 2017 Trust Services Criteria points of focus. Everything below is what we ship in Lumiaxiom's SOC 2 evidence pack, based on hundreds of Type II fieldwork engagements.
How auditors think about evidence
- Population + sample. Auditors want the full population of events (e.g., every new hire), then sample from it.
- Timing across the period. Evidence must span the audit window (usually 6–12 months). One artifact at year-end doesn't cut it.
- Independence. The person performing the control shouldn't be the person reviewing it.
- Tamper-resistance. A screenshot is weaker than a system-generated report; a hash-chained ledger is strongest.
Common Criteria — Control Environment (CC1)
Signed board charter, quarterly minutes, code of conduct acknowledgements.
Signed offer letters, completed background check reports, competency review records.
Documented job descriptions, annual performance reviews, disciplinary policy.
Communication & Information (CC2)
Published information security policy, acceptable use policy, distribution log with signed acknowledgements.
Trust portal, published security page, incident notification workflow.
Risk Assessment (CC3)
Risk register with scoring methodology, quarterly review evidence.
Fraud risk memo, segregation-of-duties mapping.
Ticketed change requests, risk-impact assessment for material changes.
Monitoring (CC4)
Continuous control monitoring reports, evidence of remediation.
Ticketing system evidence, escalation policy, exception log.
Control Activities (CC5)
SDLC policy, change management tickets, deployment logs.
Logical & Physical Access (CC6)
IAM policy, MFA enforcement report, RBAC role catalog.
Signed access request tickets, joiner-mover-leaver logs.
Quarterly access review completion certificates with sign-off.
TLS configuration report (e.g., SSL Labs A+), cert inventory.
KMS configuration, disk-encryption evidence.
EDR coverage report, patch compliance dashboard.
System Operations (CC7)
Scan results (SAST/DAST/dependency), remediation SLA metrics.
SIEM alert catalog, sample tuned rules, on-call runbook.
IR plan, tabletop exercise report, closed-incident post-mortems.
Backup test evidence, RTO/RPO documented, DR test report.
Change Management (CC8)
PR review policy, merge protections, evidence of peer review.
Risk Mitigation (CC9) + Vendor Management
Vendor inventory, tiered assessment questionnaires, SOC 2 reviews on file.
Common failure modes
- Missing access reviews. Quarterly is table stakes — auditors will sample every quarter, not just the most recent.
- Screenshot-only vendor reviews. Store the vendor's actual SOC 2 report, DPA, and risk tier.
- Untested DR. A DR runbook without a completed test in the audit window is a qualifier.
- MFA gaps. Even one privileged account without MFA fails CC6.1 sampling.
- Post-mortem-less incidents. Every P1/P2 needs a documented root-cause and corrective action.
Ship SOC 2 evidence continuously
Lumiaxiom's Evidence Vault collects, hashes, and chains every artifact above automatically.