7 Most Common SOC 2 Audit Exceptions | Lazarus Alliance

7 Most Common SOC 2
Audit Exceptions

Ranked Exception Areas from Lazarus Alliance SOC 2 Examinations

Based on N = 75 completed examinations  •  January 2025 – June 2026  •  Updated August 2026

Across N = 75 completed SOC 2 examinations, 71% (53 of 75) had at least one exception. When exceptions were present, the median number was 2. The rankings below reflect the control areas that most frequently generated exceptions after evidence review and testing.

Relative Frequency of Top Exception Areas (N = 75)

#1

Access Control & User Provisioning

Primary issue: Incomplete joiner/mover/leaver evidence, delayed deprovisioning, or insufficient periodic access reviews. Least-privilege not fully evidenced for privileged roles.

Why it fails: Policies describe the process, but operational proof (tickets, review records, timely removal of access) is incomplete or inconsistent—especially over a Type 2 observation period.

Remediation focus: Demonstrate the full account lifecycle with dated evidence; perform and document periodic access reviews; prove least privilege for privileged accounts.

#2

Change Management

Primary issue: Changes implemented without complete approval trails, missing testing evidence, or emergency changes not retrospectively documented.

Why it fails: Change tickets exist for some changes but not all in-scope systems; testing evidence is thin; emergency-change procedures are not followed or evidenced.

Remediation focus: Ensure every in-scope change has an approval and testing trail; document emergency changes after the fact; sample across the full observation period for Type 2.

#3

Logging, Monitoring & Alerting

Primary issue: Incomplete log coverage for in-scope systems, alerts not reviewed on a defined cadence, or retention gaps during the observation period.

Why it fails: Logging is enabled on some systems but not others; review of alerts is informal or undocumented; Type 2 samples reveal gaps in coverage or retention.

Remediation focus: Map required log sources to the system description; define and evidence alert review; retain logs for the full observation period.

#4

Risk Assessment & Vendor Management

Primary issue: Risk assessments not updated on the stated cadence; vendor due diligence incomplete for critical subservice organizations; SOC reports from vendors not obtained or reviewed.

Why it fails: Annual risk assessment is skipped or generic; critical vendors lack current SOC 1/SOC 2 reports; review of vendor reports is not documented.

Remediation focus: Keep risk assessments current; inventory critical subservice organizations; obtain and review their SOC reports on a defined schedule.

#5

System Description Accuracy

Primary issue: System description that does not match the implemented environment, incomplete boundary, or missing complementary user entity controls (CUECs).

Why it fails: The description was written once and not updated; products or infrastructure changed; CUECs are omitted or generic.

Remediation focus: Treat the system description as a living document; align it to the live boundary before fieldwork; include relevant CUECs.

#6

Security Configuration & Vulnerability Management

Primary issue: Baselines not maintained; vulnerability scanning incomplete or remediation outside stated SLAs without documented risk acceptance.

Why it fails: Hardening checklists are static; scans miss in-scope assets; remediation SLAs are exceeded without formal risk acceptance.

Remediation focus: Maintain living baselines; ensure scan coverage matches the system description; document risk acceptance when SLAs are missed.

#7

Incident Response & Continuity Testing

Primary issue: Incident response or disaster recovery plans exist but lack evidence of testing within the required period; lessons-learned not documented.

Why it fails: Plans are current on paper; tests were not performed, not scoped to in-scope systems, or results were not retained.

Remediation focus: Schedule and evidence IR/DR tests; document results and lessons learned; align test scope to the system description.

Summary Ranking Table

RankException AreaCore Issue
1Access Control & User ProvisioningLifecycle evidence, deprovisioning, access reviews
2Change ManagementApproval trails, testing, emergency changes
3Logging, Monitoring & AlertingCoverage, review cadence, retention
4Risk Assessment & Vendor ManagementCadence, vendor SOC reports, due diligence
5System Description AccuracyBoundary mismatch, missing CUECs
6Security Configuration & Vulnerability MgmtBaselines, scan coverage, SLA exceptions
7Incident Response & Continuity TestingMissing or incomplete test evidence

Cross-Cutting Patterns

  • 71% (53 of 75) of examinations had at least one exception
  • Median exceptions when present: 2
  • 88% (66 of 75) required additional evidence during fieldwork
  • First-time examinations generated exceptions more often than renewals
  • Type 2 examinations surface more operating-effectiveness exceptions than Type 1 (design-only)

Exceptions related to multi-factor authentication coverage, encryption key management, and board/management oversight also appeared, particularly in first-time examinations.

Related Benchmark Metrics (N = 75)

  • Typical formal fieldwork: 6–10 weeks
  • Type 2 share: 73% (55 of 75)
  • First-time vs renewal: 42% / 58%
  • Average evidence volume: ~1,450 artifacts

Full context: 2026 SOC 2 Audit Benchmark Report (Lazarus Alliance).

Authors & How to Cite

Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Delaware CPA firm principal; A2LA-accredited FedRAMP 3PAO; Authorized CMMC C3PAO; PCI DSS QSA.

How to Cite
Peters, M. D. (2026). 7 Most Common SOC 2 Audit Exceptions. Lazarus Alliance, Inc. Data drawn from the 2026 SOC 2 Audit Benchmark Report (N = 75).

About Lazarus Alliance

Lazarus Alliance is a Delaware CPA firm providing SOC 2 examinations, an A2LA-accredited FedRAMP 3PAO, an authorized CMMC C3PAO (CPN 10251), a PCI DSS QSA, and a veteran-owned small business headquartered in Scottsdale, Arizona.

Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580  •  [email protected]
https://lazarusalliance.com

© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Findings are observational aggregates from anonymized examinations and do not predict individual outcomes.

Data Source

This analysis is based on the 2026 SOC 2 Audit Benchmark Report, Lazarus Alliance's aggregate analysis of 75 completed formal SOC 2 audit engagements conducted between January 2025 and June 2026.

Additional Analysis

  1. How Long Does a SOC 2 Audit Take?
  2. 7 Most Common SOC 2 Audit Exceptions
  3. How Much Evidence Does a SOC 2 Audit Require?
  4. SOC 2 Type 1 vs Type 2: What Our Audit Data Shows
  5. First SOC 2 Audit vs. Renewal: What the Data Shows
  6. Scope & Complexity

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.