Most first-time SOC 2 candidates assume the audit is mainly about the policy documents: write them, upload them to the auditor's portal, done. That's the Type I mindset, and it's wrong for Type II. A Type II audit checks whether your controls actually operated consistently over the entire observation period — usually three to twelve months — which means the evidence auditors want is proof of practice, not proof of paperwork.

Type I vs Type II, and why it matters for preparation

A Type I report answers "were your controls designed appropriately as of this date?" A Type II report answers "did those controls actually operate effectively throughout this window?" The practical consequence: if your access review policy says "reviewed quarterly" but you only did it once in a nine-month window, that's a Type II exception even though the policy itself was fine. Auditors are sampling your actual operational history, not your intentions.

This is why the observation period shouldn't start the day you finish writing policies. It should start once those policies are genuinely being followed — starting the clock too early just guarantees gaps in the early months of your own evidence.

What auditors actually request as evidence

Beyond the policy documents themselves, expect requests for artifacts that prove the policy was followed in practice:

Common gaps that cause exceptions

Auditors don't expect perfection, but they do expect consistency with what your own policy says. The most frequent findings aren't dramatic security failures — they're process gaps:

How to prepare in the months before the window starts

Every control area above starts with a documented policy that names an owner and a cadence.

Generate your SOC 2 policies