Checklist

Evidence expected by a SOC 2 auditor

Type I vs Type II: what to prepare and over what period.

Type I (as of a point in time)

  • System description
  • Written policies and procedures
  • Evidence that controls exist

Type II (over a period, 6-12 months)

  • Access logs + quarterly reviews
  • Evidence of MFA enabled on all accounts
  • Change tickets + approvals
  • Monitoring alerts + responses
  • Backup restoration tests
  • Security training + attestations

Use this resource in BeeLink

Create your organization and import this template into your compliance workspace in one click.

Create an account