SOC 2 Evidence Kit
For a SOC 2 audit, the hard part usually isn't running the controls. It's proving you run them. This kit turns "what do I even upload?" into a concrete list: 25 controls and 76 evidence items, mapped to the SOC 2 Trust Services Criteria and grouped into 8 domains.
Tip: print this page to PDF, or download the CSV and fill in the Status, Owner, and Evidence-link columns as you go.
How to use it
- Work domain by domain. For each control, collect the evidence items listed under it.
- Aim for current artifacts, dated within your audit window and clearly owned.
- Because these controls are crosswalked, most of what you gather here also counts toward ISO 27001, HIPAA, PCI DSS and more. See the crosswalk explorer.
Governance & Risk
Policies, risk management, audit, and oversight that steer the program.
Information security policy
A board-approved information security policy set, reviewed at least annually and communicated to the workforce.
- Approved policy document: The information security policy set with a version, owner, and approval/date.
- Approval record: Leadership sign-off or meeting minutes approving the current version.
- Workforce acknowledgements: Records that staff read and accepted the policy (e.g. onboarding sign-off).
- Annual review note: Evidence the policy was reviewed within the last year.
Risk assessment & treatment
A documented process to identify, analyze, evaluate, and treat information security risks on a defined cadence.
- Risk register: The current register with scored risks, owners, and treatment decisions.
- Risk methodology: The documented process for identifying, scoring, and treating risk.
- Treatment plan: Planned or in-progress mitigations for the highest risks.
- Review cadence: Evidence the register was reviewed/updated on its defined schedule.
Document & records control
Documented information is created, approved, versioned, and controlled; records are retained and protected.
- Document register: A controlled list of documents with versions and owners.
- Revision history: Change history for a controlled document.
Internal audit program
A risk-based internal audit program evaluates conformity and effectiveness at planned intervals.
- Audit schedule: The planned internal-audit programme for the period.
- Audit report: A completed internal audit with findings.
Management review
Leadership reviews management-system performance at planned intervals and drives improvement decisions.
- Management review minutes: Minutes of a leadership review of the management system.
- Actions & decisions: Follow-up actions assigned from the review.
Access Control
Who can reach which systems and data, and how that access is granted and removed.
Access control policy
Rules for granting, reviewing, and revoking access to systems and data based on business need and least privilege.
- Access control policy: Rules for granting, reviewing, and revoking access on least-privilege.
- Role/permission matrix: A mapping of roles to the access each is entitled to.
- Access request approval: A sample request showing documented approval before access was granted.
User provisioning & deprovisioning
Joiner/mover/leaver process to grant, change, and promptly remove access across systems.
- Joiner provisioning record: Onboarding/access-provisioning record for a recent new hire.
- Leaver deprovisioning record: Confirmation access was removed when someone left, dated near their end date.
- Per-system removal check: Evidence accounts are disabled across each in-scope system on departure.
- Role-change update: A mover example showing access adjusted when a role changed.
Multi-factor authentication
MFA enforced for remote access, administrative access, and access to sensitive systems and data.
- MFA enforcement setting: Configuration/screenshot showing MFA required in the identity provider.
- Coverage report: An export listing users and their MFA-enrollment status.
- Admin/privileged MFA: Evidence MFA is enforced on administrative and remote access specifically.
Data Protection & Privacy
Encryption, classification, retention, and individual privacy rights.
Encryption in transit & at rest
Strong cryptography protects sensitive data in transit over public networks and at rest in storage.
- Encryption-in-transit config: TLS settings / certificate showing data is encrypted in transit.
- Encryption-at-rest setting: Storage or database configuration showing at-rest encryption enabled.
- Key management: How encryption keys are stored, rotated, and access-restricted.
Data classification & handling
Information is classified and handled per its sensitivity, with rules for labeling and protection.
- Classification policy: Defined data classes and handling rules for each.
- Labelling in practice: An example of data labelled/handled per its classification.
- Data map / inventory: Where sensitive data lives and how it flows.
Data retention & secure disposal
Data is retained per policy and securely destroyed when no longer needed.
- Retention schedule: Defined retention periods by data type and the disposal method.
- Secure disposal record: Evidence data/media was securely deleted or destroyed when due.
Infrastructure & Operations
Day-to-day security of systems, networks, code, and change.
Logging & monitoring
Security-relevant events are logged, protected, retained, and reviewed for anomalies.
- Logging configuration: Settings showing security-relevant events are logged and retained.
- Alerting rules: Configured alerts for anomalous or security-significant activity.
- Sample alert + triage: An alert that fired with the record of how it was reviewed/actioned.
- Log retention setting: Evidence logs are kept for the required period.
Vulnerability management
Regular scanning, prioritization, and remediation of vulnerabilities across systems and applications.
- Scanner enabled: Configuration showing vulnerability scanning is running across in-scope assets.
- Findings by severity: A scan export showing findings triaged by severity and their status.
- Remediation evidence: Before/after or a ticket showing a finding was fixed within SLA.
- Penetration test report: A recent third-party pen-test report and remediation of its findings.
Malware protection
Anti-malware controls prevent, detect, and respond to malicious software on endpoints and servers.
- Endpoint protection deployed: Console/export showing anti-malware is installed and active on endpoints.
- Coverage report: A list of devices confirming protection is enrolled and up to date.
- Detection handling: A sample detection and how it was quarantined/resolved.
Change management
Changes to systems and software are requested, reviewed, tested, approved, and tracked.
- Change process: The documented workflow for authorizing, testing, and approving changes.
- Sample change with approval: A production change showing review/approval before release.
- Peer review / CI checks: Pull-request review or pipeline gates enforcing the process.
Asset inventory
An inventory of hardware, software, and information assets with assigned owners.
- Asset inventory: A current list of in-scope devices/systems with owners.
- Endpoint enrollment: Evidence devices are managed/tracked (MDM or equivalent).
- Reconciliation: Evidence the inventory is periodically checked for accuracy.
Secure software development
Secure coding, review, and testing practices across the development lifecycle.
- Secure development policy: Secure-SDLC standards developers follow.
- Code review evidence: Pull-request reviews / branch protections enforcing review.
- Pipeline security checks: SAST/dependency/secret scanning wired into CI.
Network security controls
Firewalls/segmentation and network controls restrict traffic to and from sensitive environments.
- Network controls config: Firewall/security-group rules restricting traffic to what’s needed.
- Segmentation: Evidence sensitive environments are isolated from general access.
- Rule review: A periodic review of network/firewall rules.
Resilience & Continuity
Backups, continuity, and incident response for when things go wrong.
Backups
Regular, tested backups of critical data and systems with defined retention.
- Backup configuration: Settings showing what is backed up and on what schedule.
- Successful backup log: Recent job history confirming backups completed.
- Restore test: Evidence a restore was performed and verified.
Business continuity & disaster recovery
BC/DR plans with defined RTO/RPO, tested periodically, to restore service after disruption.
- BC/DR plan: The documented continuity and disaster-recovery plan with roles and RTO/RPO.
- Plan test / tabletop: Results of a recent BC/DR exercise or failover test.
- Review record: Evidence the plan was reviewed/updated on its cadence.
Incident response
A documented, tested plan to detect, triage, contain, remediate, and communicate security incidents.
- Incident response plan: The documented plan with severities, roles, and notification steps.
- IR exercise: A tabletop or simulation with dated results and follow-ups.
- Incident record: A handled incident (or "no incidents" attestation) with the post-incident review.
Third-party Risk
Oversight of the vendors and suppliers you depend on.
Third-party / vendor risk management
Due diligence, contractual safeguards, and ongoing monitoring of vendors that handle your data.
- Vendor inventory: A list of third parties with data access and their risk tier.
- Vendor risk review: A completed assessment/questionnaire for a key vendor.
- Vendor reports on file: A vendor's SOC 2 / ISO cert or security summary collected on review.
People & Culture
Training, HR security, competence, and workforce practices.
Security awareness training
Ongoing security awareness training for all personnel, with completion tracking.
- Training completion report: Records showing staff completed security-awareness training.
- Course content: The material/curriculum covered.
- Phishing simulation: Results of a simulated phishing exercise, if run.
Personnel security (HR)
Background screening, confidentiality agreements, and onboarding/offboarding security steps.
- Background check record: Evidence pre-employment screening was performed where allowed.
- Signed acknowledgements: Confidentiality/acceptable-use agreements signed by staff.
- Onboarding checklist: A completed onboarding record covering security steps.
Physical & Environmental
Facilities, physical security, and environmental commitments.
Physical security
Physical access to facilities and equipment holding sensitive data is restricted and monitored.
- Physical security policy: Rules for facility access and protecting physical assets.
- Access controls: Badge/visitor logs or entry-control configuration.
- Provider attestation: For cloud-hosted orgs, the data-center provider’s physical-security report.
SOC 2® and the Trust Services Criteria are references to AICPA material by name and criteria number only; Keel is not affiliated with or endorsed by the AICPA. Control descriptions and evidence guidance are Keel's own, and describe generic artifact types, not any organization's data. This kit is guidance, not an audit or a guarantee of a passing report.