What the audit period is
A SOC 2 Type 2 report covers a window of time, sometimes called the observation period. For a first report it is commonly three months. The auditor's question is simple: during those months, did the company do what its policies say?
How the auditor checks
At the end of the period the auditor asks for complete lists of what happened: everyone who was hired, everyone who left, the code changes that were released, any security incidents. From each list they pick samples and ask for evidence that the control was followed in that specific case.
This is why the period can't be left to run by itself. If a new hire in month two never completed security training, that gap exists whether or not anyone noticed at the time.
The proof you need to be producing
- New hires: policies accepted and security training completed within the time your policy sets.
- Departures: access to every system removed within the time your policy sets.
- Laptops: every device, including new ones, encrypted and reporting to the platform.
- Code changes: each change reviewed and approved before release.
- Access reviews: a documented review of who has access to key systems, on the schedule your policy sets.
- Vulnerabilities: findings fixed within your stated timeframes.
- Incidents: anything that happens logged and handled according to your plan.
- Backups: evidence that backups run and can be restored.
- Vendors: reviews of your important vendors kept current.
The weekly routine
- Open the compliance platform and look at every failing test.
- Fix each one or assign it to the person who can, with a due date.
- Check for anyone who joined or left that week and confirm their tasks were done.
- Upload any evidence the platform can't collect automatically.
- Keep a short log of anything that went wrong and how it was resolved.
It is not complicated work. It is work that has to happen every week without fail, which is exactly what gets dropped when it is nobody's main job.
What happens if something is missed
Gaps the auditor finds are written into the report as exceptions, and your customers will read them. One exception does not sink a report, but a pattern of them can. Catching a problem in the week it happens, fixing it and documenting why is far better than discovering it during the audit.
During the audit period we do the weekly checks, chase the open items and keep the evidence in order, then handle every auditor request. See SOC 2 readiness and audit management.
