SOC 2 Evidence Checklist

Digital download

SOC 2 Evidence Checklist

Companies preparing for a first SOC 2 Type I or Type II who need to know exactly which artifacts the auditor will request, control by control.

$27
Buy now โ€” $27

Secure checkout via Stripe.

What’s included

  • Evidence list organised by the 5 Trust Services Criteria and every Common Criteria point (CC1-CC9)
  • For each control: the artifact name, where it usually lives, and who owns it
  • Type I vs Type II columns so you know what needs a sample period
  • Evidence-request tracker to run the audit from

How it works

1

Buy and download

2

Assign an owner to each row

3

Collect artifacts into one folder structure (provided)

4

Hand the tracker to your auditor at kickoff

What you receive

SOC 2 evidence checklist (PDF)
Evidence folder structure
Auditor request tracker

Questions

Does this cover all five TSCs?

Yes: Security, Availability, Processing Integrity, Confidentiality and Privacy, with Security marked as the mandatory baseline.

Is it Type I or Type II?

Both. Each row is flagged for what a Type II sample period adds.

Quantum Audit Engine prepares organisations for audits and assessments. Certifications, attestations and audit reports are issued only by independent auditors, assessors or accredited certification bodies. Nothing on this page is legal advice.
Buy now โ€” $27

Secure checkout via Stripe.