How Much Evidence Does a
SOC 2 Audit Require?
Table of Contents
ToggleVolume, Quality, and What Examiners Actually Need
Based on N = 75 completed examinations • January 2025 – June 2026 • Updated August 2026
Submitted
Range
Evidence (66 of 75)
Quantity
Matters
1. What Counts as “Evidence” in SOC 2?
Evidence is any artifact that demonstrates a control is designed (Type 1) or designed and operating effectively (Type 2) for the in-scope system. Typical categories include:
- System description and boundary documentation
- Policies and procedures
- Access reviews, provisioning/deprovisioning tickets, and privileged account inventories
- Change tickets, approvals, and testing records
- Log samples and alert review records
- Vulnerability scan results and remediation tickets
- Risk assessments and vendor due-diligence / SOC reports
- Incident response and continuity test results
- Training records and organizational charts
- Screenshots and system exports (with context)
Examiners evaluate whether evidence is sufficient, recent, attributable to the in-scope system, and mapped to the applicable Trust Services Criteria.
2. Observed Evidence Volume (N = 75)
| Metric | Value | Notes |
|---|---|---|
| Average discrete artifacts submitted | ~1,450 | N = 75 |
| Observed range | ~400 – 4,200 | Wide variation by scope, type, and maturity |
| Examinations requiring additional evidence | 88% (66 of 75) | At least one clarification cycle |
| Most common additional requests | Access reviews, change tickets, log samples, vendor SOC reports, system description updates | After initial package review |
Additional Evidence Required (N = 75)
3. Volume vs. Quality
Raw file count is a poor success metric. In the dataset:
- Some focused Security-only packages with fewer than 800 high-quality, criteria-mapped artifacts moved through examination efficiently.
- Larger packages (3,000+ files) sometimes generated more clarification requests when artifacts lacked context, dates, or clear criteria mapping.
What examiners consistently preferred:
- Criteria-tagged evidence (each artifact linked to one or more Trust Services Criteria)
- Timestamps and system identifiers on screenshots and exports
- Clear ownership and “last reviewed” dates on policies and reviews
- Operational proof (tickets, logs, review records) alongside policy statements
- Accurate, current system descriptions aligned to the live environment
- For Type 2: samples that cover the full observation period
4. Most Common Evidence Deficiencies
- Screenshots without context or timestamps — missing system name, date, or configuration path
- Policies without operational proof — documented procedures that could not be demonstrated in practice
- Incomplete Type 2 samples — observation-period coverage gaps for access, change, or logging
- System description drift — description that no longer matches the implemented system or boundary
- Missing vendor SOC reports — critical subservice organizations without current reports or documented review
- Incomplete access reviews — reviews not performed on the stated cadence or missing privileged accounts
- Change tickets without testing evidence — approvals present but testing or post-implementation validation missing
5. How Type and Maturity Affect Evidence Volume
| Segment | Share of N = 75 | Evidence Tendency |
|---|---|---|
| Type 2 | 73% (55) | Higher volume — observation-period samples required |
| Type 1 | 27% (20) | Lower volume — point-in-time design evidence |
| First-time | 42% (32) | More clarification cycles; system description often immature |
| Renewal | 58% (43) | More complete packages; refined evidence processes |
Type 2 examinations demand sustained operational evidence across the observation period. First-time examinations more often required additional evidence cycles because system descriptions and sampling approaches were still being refined.
6. Practical Guidance for Evidence Packaging
- Map first, collect second. Create a criteria-to-evidence matrix before bulk collection.
- Require context on every artifact. System name, date, owner, and criteria reference.
- Prefer operational proof over policy alone. Tickets, logs, and review records close findings faster.
- Keep the system description living. Update it when the environment changes.
- For Type 2, plan sampling across the full observation period — not only the weeks before fieldwork.
- Obtain critical vendor SOC reports early.
- Expect clarification. 88% of examinations needed at least one additional evidence cycle. Plan for it.
7. Related Benchmark Metrics (N = 75)
- Typical formal fieldwork: 6–10 weeks
- Examinations with ≥1 exception: 71% (53 of 75)
- Most common exception areas: access control, change management, logging/monitoring
Full context: 2026 SOC 2 Audit Benchmark Report (Lazarus Alliance).
8. Authors & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Delaware CPA firm principal; A2LA-accredited FedRAMP 3PAO; Authorized CMMC C3PAO; PCI DSS QSA.
How to Cite
Peters, M. D. (2026). How Much Evidence Does a SOC 2 Audit Require? Lazarus Alliance, Inc. Data drawn from the 2026 SOC 2 Audit Benchmark Report (N = 75).
9. About Lazarus Alliance
Lazarus Alliance is a Delaware CPA firm providing SOC 2 examinations, an A2LA-accredited FedRAMP 3PAO, an authorized CMMC C3PAO (CPN 10251), a PCI DSS QSA, and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Figures are observational aggregates from anonymized examinations and do not guarantee individual outcomes.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Data Source
This analysis is based on the 2026 SOC 2 Audit Benchmark Report, Lazarus Alliance's aggregate analysis of 75 completed formal SOC 2 audit engagements conducted between January 2025 and June 2026.
Additional Analysis
- How Long Does a SOC 2 Audit Take?
- 7 Most Common SOC 2 Audit Exceptions
- How Much Evidence Does a SOC 2 Audit Require?
- SOC 2 Type 1 vs Type 2: What Our Audit Data Shows
- First SOC 2 Audit vs. Renewal: What the Data Shows
- Scope & Complexity
Talk with one of our experts
Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.
We're here to answer any questions you may have.
