PW-SOC2-008 SOC 2 readiness spoke
Evidence pack starter
TL;DR. Start with policies that match how you actually work, identity evidence (MFA, access reviews, joiner-mover-leaver), change and vulnerability tickets, vendor due diligence, and backup/restore tests. Name owners and a weekly pull rhythm—auditors sample systems, not intention.
Starter evidence inventory
- Policy set with owners and review dates.
- IdP MFA screenshots / export; break-glass procedure.
- Quarterly (or monthly) access review artifacts with tickets for removals.
- JML (joiner-mover-leaver) samples.
- Change tickets linking PR → deploy for production.
- Vulnerability scan + remediation samples.
- Vendor inventory + due-diligence notes for material subprocessors.
- Backup configuration + restore test record.
- Security awareness completion report.
- Incident response tabletop notes (even a lightweight one).
Weekly evidence rhythm beats volume
Label folders by control ID and month. Assign a human who checks completeness every week. Auditors would rather see twelve tidy months than a dump of unsorted PDFs the night before fieldwork.
Questions founders ask
How many samples do auditors need?
Enough to support the opinion for the period/point—your auditor sets the request list.
Are screenshots enough?
Often as part of a set; pair with tickets, configs, and exports where possible.
Who stores the pack?
A durable shared drive or GRC system with access control—not a laptop folder.
Sources
Cost and timeline figures on this site are educational planning ranges, not quotes from AICPA, CSA, Shared Assessments, or any auditor.
- primary SOC 2 — SOC for Service Organizations: Trust Services Criteria — AICPA & CIMA — Official SOC 2 topic landing; defines SOC 2 as examination of controls relevant to TSC categories.
- practitioner ProofWindow educational planning ranges — ProofWindow Editorial — Internal: cost/timeline bands are editorial planning language, not a surveyed dataset. Label Unknown for hard dollars; never attribute invented figures to AICPA/CSA/SA.