How Much Evidence Does a SOC 2 Audit Require? | Lazarus Alliance

How Much Evidence Does a
SOC 2 Audit Require?

Volume, Quality, and What Examiners Actually Need

Based on N = 75 completed examinations  •  January 2025 – June 2026  •  Updated August 2026

~1,450
Average Artifacts
Submitted
400–4,200
Observed
Range
88%
Needed Additional
Evidence (66 of 75)
Quality >
Quantity
What Actually
Matters
Quick Answer
Across N = 75 completed SOC 2 examinations, organizations submitted an average of ~1,450 discrete artifacts (range roughly 400–4,200). Volume alone is a weak predictor of success. Examiners care far more about relevance, completeness, context, and mapping to Trust Services Criteria than about raw file count. 88% (66 of 75) of examinations still required at least one round of additional evidence after the initial package.

1. What Counts as “Evidence” in SOC 2?

Evidence is any artifact that demonstrates a control is designed (Type 1) or designed and operating effectively (Type 2) for the in-scope system. Typical categories include:

  • System description and boundary documentation
  • Policies and procedures
  • Access reviews, provisioning/deprovisioning tickets, and privileged account inventories
  • Change tickets, approvals, and testing records
  • Log samples and alert review records
  • Vulnerability scan results and remediation tickets
  • Risk assessments and vendor due-diligence / SOC reports
  • Incident response and continuity test results
  • Training records and organizational charts
  • Screenshots and system exports (with context)

Examiners evaluate whether evidence is sufficient, recent, attributable to the in-scope system, and mapped to the applicable Trust Services Criteria.

2. Observed Evidence Volume (N = 75)

MetricValueNotes
Average discrete artifacts submitted~1,450N = 75
Observed range~400 – 4,200Wide variation by scope, type, and maturity
Examinations requiring additional evidence88% (66 of 75)At least one clarification cycle
Most common additional requestsAccess reviews, change tickets, log samples, vendor SOC reports, system description updatesAfter initial package review

Additional Evidence Required (N = 75)

3. Volume vs. Quality

Raw file count is a poor success metric. In the dataset:

  • Some focused Security-only packages with fewer than 800 high-quality, criteria-mapped artifacts moved through examination efficiently.
  • Larger packages (3,000+ files) sometimes generated more clarification requests when artifacts lacked context, dates, or clear criteria mapping.

What examiners consistently preferred:

  • Criteria-tagged evidence (each artifact linked to one or more Trust Services Criteria)
  • Timestamps and system identifiers on screenshots and exports
  • Clear ownership and “last reviewed” dates on policies and reviews
  • Operational proof (tickets, logs, review records) alongside policy statements
  • Accurate, current system descriptions aligned to the live environment
  • For Type 2: samples that cover the full observation period

4. Most Common Evidence Deficiencies

  1. Screenshots without context or timestamps — missing system name, date, or configuration path
  2. Policies without operational proof — documented procedures that could not be demonstrated in practice
  3. Incomplete Type 2 samples — observation-period coverage gaps for access, change, or logging
  4. System description drift — description that no longer matches the implemented system or boundary
  5. Missing vendor SOC reports — critical subservice organizations without current reports or documented review
  6. Incomplete access reviews — reviews not performed on the stated cadence or missing privileged accounts
  7. Change tickets without testing evidence — approvals present but testing or post-implementation validation missing

5. How Type and Maturity Affect Evidence Volume

SegmentShare of N = 75Evidence Tendency
Type 273% (55)Higher volume — observation-period samples required
Type 127% (20)Lower volume — point-in-time design evidence
First-time42% (32)More clarification cycles; system description often immature
Renewal58% (43)More complete packages; refined evidence processes

Type 2 examinations demand sustained operational evidence across the observation period. First-time examinations more often required additional evidence cycles because system descriptions and sampling approaches were still being refined.

6. Practical Guidance for Evidence Packaging

  1. Map first, collect second. Create a criteria-to-evidence matrix before bulk collection.
  2. Require context on every artifact. System name, date, owner, and criteria reference.
  3. Prefer operational proof over policy alone. Tickets, logs, and review records close findings faster.
  4. Keep the system description living. Update it when the environment changes.
  5. For Type 2, plan sampling across the full observation period — not only the weeks before fieldwork.
  6. Obtain critical vendor SOC reports early.
  7. Expect clarification. 88% of examinations needed at least one additional evidence cycle. Plan for it.

7. Related Benchmark Metrics (N = 75)

  • Typical formal fieldwork: 6–10 weeks
  • Examinations with ≥1 exception: 71% (53 of 75)
  • Most common exception areas: access control, change management, logging/monitoring

Full context: 2026 SOC 2 Audit Benchmark Report (Lazarus Alliance).

8. Authors & How to Cite

Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Delaware CPA firm principal; A2LA-accredited FedRAMP 3PAO; Authorized CMMC C3PAO; PCI DSS QSA.

How to Cite
Peters, M. D. (2026). How Much Evidence Does a SOC 2 Audit Require? Lazarus Alliance, Inc. Data drawn from the 2026 SOC 2 Audit Benchmark Report (N = 75).

9. About Lazarus Alliance

Lazarus Alliance is a Delaware CPA firm providing SOC 2 examinations, an A2LA-accredited FedRAMP 3PAO, an authorized CMMC C3PAO (CPN 10251), a PCI DSS QSA, and a veteran-owned small business headquartered in Scottsdale, Arizona.

Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580  •  [email protected]
https://lazarusalliance.com

© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Figures are observational aggregates from anonymized examinations and do not guarantee individual outcomes.

Data Source

This analysis is based on the 2026 SOC 2 Audit Benchmark Report, Lazarus Alliance's aggregate analysis of 75 completed formal SOC 2 audit engagements conducted between January 2025 and June 2026.

Additional Analysis

  1. How Long Does a SOC 2 Audit Take?
  2. 7 Most Common SOC 2 Audit Exceptions
  3. How Much Evidence Does a SOC 2 Audit Require?
  4. SOC 2 Type 1 vs Type 2: What Our Audit Data Shows
  5. First SOC 2 Audit vs. Renewal: What the Data Shows
  6. Scope & Complexity

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.