SOC 2

A control-owner plan for producing complete, traceable evidence through a Type 2 reporting period, without inventing work at the end.

Build the calendar from the control register

For every control in scope, record its purpose, owner, frequency or trigger, evidence source, complete population, reviewer, and exception path. The calendar should follow the actual way the service operates. A release approval is event-driven; an access review may be periodic; an incident record arises when an incident occurs. Do not create a monthly checkbox for a control that only makes sense when a change happens.

Before a Type 2 period, walk through each control with the person who performs it. Where does the event start? Which system holds the decision? Does a timestamp show the right sequence? Could an independent reviewer identify the population from which a sample would be selected? These questions reveal gaps that a policy inventory will miss. Confirm the agreed criteria and examination plan with the independent CPA firm.

Use four operating lanes

First, track identity and access: joiner, mover, leaver events, privileged access, and periodic reviews. Second, track engineering: changes, testing, approvals, emergency fixes, and deployment records. Third, track resilience and response: monitoring alerts, incidents, vulnerability handling, backup or recovery exercises where applicable. Fourth, track governance: risk decisions, supplier reviews, training, management oversight, and corrective actions. These are planning lanes, not a prescribed SOC 2 control list; the relevant controls depend on the scoped system and criteria.

For each lane, specify what constitutes a completed record. A ticket number alone may be insufficient if the approval, outcome, or exception is held elsewhere. A screenshot without a date or system context may be hard to evaluate. Prefer a durable source record with identifiers and links to supporting material. Restrict access to sensitive evidence and agree a secure handoff method with the CPA firm.

Reconcile monthly, not only at year end

At a regular cadence, compare the expected events to the records captured. Did every production release in the population follow the documented path? Were all scheduled reviews completed? Were exceptions closed or explicitly accepted by an authorized owner? If the service had no event of a particular type, retain the source that supports that conclusion rather than manufacturing a sample. Escalate missing or late evidence promptly.

Separate a control failure from a filing gap. A control may have operated but its record was lost; alternatively, a complete folder may hide an approval that happened after deployment. Record what actually happened, assess impact, correct the process, and let the CPA firm evaluate the effect on its opinion. Avoid retroactively signing a review to make the calendar look complete.

Reuse evidence with ISO 27001 carefully

An ISO/IEC 27001 ISMS may already produce risk reviews, supplier oversight, internal audit records, and corrective actions. Those records can support a SOC 2 program when the same assets, control owner, period, and assertion are involved. A crosswalk should record those four fields and explain any gap. A corporate ISMS review does not automatically prove that a specific SaaS release control operated for the SOC 2 system.

Use the calendar as an operational view for owners and as a completeness check for the eventual report. It is not a promise of an unqualified opinion. The independent CPA firm determines the examination procedures and evaluates exceptions. The practical objective is reliable control operation that customers can understand and the organization can sustain.

Put it into practice

  • Assign a named owner, trigger, evidence source, and exception route to each scoped control.
  • Confirm the full event population before selecting sample records.
  • Review missing records and deviations during the period, with truthful remediation records.
  • Crosswalk ISO/IEC 27001 evidence only where assets, owners, periods, and assertions overlap.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources