The SOC 2 audit process, from readiness through report delivery
A phase-by-phase map of the engagement, with the decisions and failure modes that change cost or timing.
1. Readiness and scoping
Management defines the system and assurance objective, maps controls, and remediates gaps. The prospective auditor clarifies criteria, report type, period, dependencies, and evidence expectations without operating management’s controls.
2. Engagement and request planning
The parties confirm scope, responsibilities, fees, timing, secure evidence exchange, sampling approach, and availability. Ask how late scope changes, retesting, subsidiaries, additional criteria, and delayed evidence affect fees.
3. Observation period
For Type II, controls operate over the defined period. Teams retain recurring artifacts and exceptions as they occur. Evidence should reflect real operation; reconstructing a perfect record later weakens reliability and can hide control failures that management should address.
4. Fieldwork and testing
The auditor selects samples, inspects evidence, interviews owners, observes procedures, and may reperform aspects of controls. Requests often require population completeness before sampling. Track requests centrally and preserve the original artifact plus explanatory context.
5. Exceptions and management response
An exception is evaluated in context: control objective, frequency, population, severity, compensating controls, and remediation. It does not automatically mean the entire report fails. Do not pressure owners to conceal it; document cause, impact, correction, and prevention.
6. Draft, representation, and issuance
Management reviews the system description and results, supplies required representations, and resolves factual errors. Establish who can receive the final report, how NDA requests are handled, and how bridge letters or subsequent-period questions will be managed.
7. Operate after issuance
The report is a period-specific assurance artifact, not permanent certification. Preserve the control cadence, monitor changes to the system description and commitments, retain exceptions, and schedule the next examination before customer diligence creates an emergency. Track major architecture changes, acquisitions, new locations, subprocessors, and criteria because they may alter future scope. Give sales and customer-success teams approved language so they do not overstate what the report covers.