The SOC 2 audit period: what you have to prove, and who does it.

Getting ready for SOC 2 is only half of it. During the audit period, someone has to keep producing proof that your controls are being used and that they work.

SOC 2 guide · By Elevated Vibration · Updated October 2026

What the audit period is

A SOC 2 Type 2 report covers a window of time, sometimes called the observation period. For a first report it is commonly three months. The auditor's question is simple: during those months, did the company do what its policies say?

How the auditor checks

At the end of the period the auditor asks for complete lists of what happened: everyone who was hired, everyone who left, the code changes that were released, any security incidents. From each list they pick samples and ask for evidence that the control was followed in that specific case.

This is why the period can't be left to run by itself. If a new hire in month two never completed security training, that gap exists whether or not anyone noticed at the time.

The proof you need to be producing

  • New hires: policies accepted and security training completed within the time your policy sets.
  • Departures: access to every system removed within the time your policy sets.
  • Laptops: every device, including new ones, encrypted and reporting to the platform.
  • Code changes: each change reviewed and approved before release.
  • Access reviews: a documented review of who has access to key systems, on the schedule your policy sets.
  • Vulnerabilities: findings fixed within your stated timeframes.
  • Incidents: anything that happens logged and handled according to your plan.
  • Backups: evidence that backups run and can be restored.
  • Vendors: reviews of your important vendors kept current.

The weekly routine

  1. Open the compliance platform and look at every failing test.
  2. Fix each one or assign it to the person who can, with a due date.
  3. Check for anyone who joined or left that week and confirm their tasks were done.
  4. Upload any evidence the platform can't collect automatically.
  5. Keep a short log of anything that went wrong and how it was resolved.

It is not complicated work. It is work that has to happen every week without fail, which is exactly what gets dropped when it is nobody's main job.

What happens if something is missed

Gaps the auditor finds are written into the report as exceptions, and your customers will read them. One exception does not sink a report, but a pattern of them can. Catching a problem in the week it happens, fixing it and documenting why is far better than discovering it during the audit.

During the audit period we do the weekly checks, chase the open items and keep the evidence in order, then handle every auditor request. See SOC 2 readiness and audit management.

Related articles

How to Run a User Access Review

A practical way to review who has access to what, and to document it for an auditor.

Employee Onboarding and Offboarding Checklist

A repeatable checklist for bringing people in and out, including accounts, equipment and access.

What Vanta Automates for SOC 2, and What It Doesn't

Vanta removes a lot of manual evidence collection. It does not run the project. Here is what still takes people.

Audit period questions

Straight answers.

How long is the SOC 2 audit period?

For a first SOC 2 Type 2 report the audit period is commonly three months. Later reports usually cover twelve months.

Does Vanta collect all the evidence during the audit period?

No. It collects what it can see in connected systems. Tasks done by people, such as access reviews and vendor reviews, have to be carried out and uploaded.

Who is responsible for evidence during the audit period?

Your company is. In practice one person needs to own it, either on your team or an outside partner who manages the audit for you.

In an audit period right now?

We can pick it up midway. Tell us where things stand.

Book a free call