Checklist
Evidence expected by a SOC 2 auditor
Type I vs Type II: what to prepare and over what period.
Type I (as of a point in time)
- System description
- Written policies and procedures
- Evidence that controls exist
Type II (over a period, 6-12 months)
- Access logs + quarterly reviews
- Evidence of MFA enabled on all accounts
- Change tickets + approvals
- Monitoring alerts + responses
- Backup restoration tests
- Security training + attestations
Use this resource in BeeLink
Create your organization and import this template into your compliance workspace in one click.
Create an account