Skip to main content

SOC 2 Evidence Collection

Required Evidence by Control

CC6.1 - Logical Access ControlsEvidence to collect:
  • Access control matrix (roles and permissions)
  • User access review logs (quarterly)
  • MFA enforcement configuration
  • Screenshot of authentication settings
  • Sample of access provisioning tickets
  • Sample of access deprovisioning tickets (within 24 hours of termination)
  • Failed login attempt logs
  • Privileged access usage logs
Collection Script:

SOC 2 Type II Observation Period

Timeline and Milestones

Key Requirements:
  • Minimum 3-month observation (some auditors require 6-12 months)
  • Continuous operation of controls throughout period
  • Complete evidence trail for all controls
  • No material exceptions or unmitigated findings

Next Steps

Readiness Checklist

Verify audit readiness

Trust Service Criteria

Review control requirements

Back to Overview

Return to SOC 2 overview