Most first-time SOC 2 candidates assume the audit is mainly about the policy documents: write them, upload them to the auditor's portal, done. That's the Type I mindset, and it's wrong for Type II. A Type II audit checks whether your controls actually operated consistently over the entire observation period — usually three to twelve months — which means the evidence auditors want is proof of practice, not proof of paperwork.
Type I vs Type II, and why it matters for preparation
A Type I report answers "were your controls designed appropriately as of this date?" A Type II report answers "did those controls actually operate effectively throughout this window?" The practical consequence: if your access review policy says "reviewed quarterly" but you only did it once in a nine-month window, that's a Type II exception even though the policy itself was fine. Auditors are sampling your actual operational history, not your intentions.
This is why the observation period shouldn't start the day you finish writing policies. It should start once those policies are genuinely being followed — starting the clock too early just guarantees gaps in the early months of your own evidence.
What auditors actually request as evidence
Beyond the policy documents themselves, expect requests for artifacts that prove the policy was followed in practice:
- Access control: access review logs or exports showing who reviewed what and when, onboarding and offboarding tickets with timestamps, MFA enforcement configuration screenshots.
- Incident response: a log of security incidents during the period — including minor ones — with evidence they were triaged and closed per the documented process. Auditors are often more reassured by a company that logged and handled small incidents than one that reports zero incidents over a year.
- Change management: deployment or change logs showing approval before production changes, and evidence that emergency changes were retroactively approved per policy.
- Vendor risk: security questionnaires or SOC 2/ISO 27001 evidence collected from critical vendors, and records of the risk tiering decision.
- Background checks and training: records of employee background checks (where applicable) and security awareness training completion.
- Business continuity: evidence of backup testing or a documented tabletop exercise, not just the plan itself.
Common gaps that cause exceptions
Auditors don't expect perfection, but they do expect consistency with what your own policy says. The most frequent findings aren't dramatic security failures — they're process gaps:
- An access review that was skipped or ran late for one quarter within the observation window.
- A terminated employee whose access was revoked outside the timeframe your Access Control Policy commits to (commonly 24 hours).
- An incident visible in logs or tickets that was never formally logged in the incident tracker.
- A policy that references a review cadence the company didn't actually follow — this is why it's worth setting a cadence you can realistically sustain rather than the most impressive-sounding one.
- Change management evidence that only covers some deployments, because changes made outside the primary deployment pipeline weren't tracked the same way.
How to prepare in the months before the window starts
- Assign a clear, named owner for each control area — access reviews, incident response, vendor assessments — before the observation period begins, so there's no ambiguity about who's responsible when the auditor asks.
- Run an internal dry-run of your access review and incident logging process at least once before the real observation period starts, to surface gaps in your tooling or process while there's still time to fix them.
- Pick a review cadence in your policies that matches what your team can actually sustain given current headcount — an annual review commitment you'll consistently hit beats a quarterly one you'll miss.
- Centralize evidence collection as you go rather than reconstructing it at audit time; screenshots and exports are far easier to produce in the moment than six months later.
Every control area above starts with a documented policy that names an owner and a cadence.
Generate your SOC 2 policies