How many evidence items your SOC 2 audit will ask for
An audit firm sends one list and everything stops until it is answered. This estimates how long that list will be, which control areas carry most of it, and where the work actually lands.
The first concrete thing a SOC 2 audit produces is a list. It arrives as a spreadsheet, one row per item, and each row wants a document, a screenshot, an export or a sample. Teams budget for the audit fee and then lose three weeks to the list, because nobody told them how long it would be or who would answer it.
This estimates the item count from the things that actually drive it: headcount, the number of places evidence has to be pulled from, the report type, and the criteria you elected. It returns a banded total, a breakdown by control area, and the three areas that will take most of your time. The estimate renders on this page and nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
The model this uses
The baseline is a small first Type 1 covering Security only, which lands at roughly eighty items spread across eight control areas. That is the shape of a first Type 1 at a small Canadian software company: a request list in the mid-eighties, most of it concentrated in access, policy and operations. From there the model applies the multipliers below.
| Driver | Effect | Why |
|---|---|---|
| Type 2 instead of Type 1 | Up by a third to a half | Operation over a period means samples, and a sample is several items where design was one |
| Window length | Up modestly with the period | Sample sizes rise with the population, and a twelve month period has more quarters to evidence |
| Headcount | Up across four areas | Onboarding, offboarding, training and access review samples all start from a person list |
| Systems in scope | Up across three areas | Access and configuration evidence is pulled once per system, not once per company |
| Elective categories | Up by category | Availability adds recovery testing, Privacy adds the largest block of any single election |
What the model deliberately does not do is reduce the count because you use a compliance platform. A platform changes who does the work and how long each item takes. The auditor still asks for the same evidence.
Who actually answers the list
The request is one document and it is never one person's job. Access reviews and system configuration come from engineering. Onboarding, offboarding, training and background checks come from whoever runs people operations. Policies, vendor reviews and risk assessments come from whoever owns the program. Board and management oversight evidence comes from the executive team, and it is the category most likely to be missing because nobody wrote minutes.
Name an owner per control area before the list arrives. The projects that stall are the ones where a single coordinator chases nine people who each think somebody else is handling it.
Common questions
How long does answering the list take?
For a first Type 2 with nothing pre-collected, plan on three to six weeks of elapsed time and somewhere between forty and a hundred and twenty hours of internal effort spread across several people. The elapsed time is driven by how fast people answer, not by how many items there are, which is why naming owners in advance is worth more than any tool.
Does a compliance platform reduce the number of items?
No. It reduces the time each item takes, because access lists and configuration evidence are already collected with a timestamp rather than screenshotted the week fieldwork starts. The request itself is set by the criteria and by the auditor's testing plan. Compliance automation software covers what it does and does not remove.
Can we push back on items?
Yes, and you should, on two grounds: an item that duplicates one already provided, and an item that tests a control outside your described boundary. Both are ordinary conversations. What is not worth arguing is an item you simply cannot produce, because the answer to that is a control gap and the auditor has just found it. Evidence request triage checks one request at a time.
Why does the count go up in year two?
It usually goes down, not up. A renewal reuses the system description, the policies and the control set, and the request narrows to the period evidence plus whatever changed. Year two is where the economics of the whole exercise improve, provided the evidence was collected as it happened rather than reconstructed at the end.
What happens if we cannot produce an item?
For a Type 1, a missing artefact is usually fixable before the report date, because design can be remediated. For a Type 2, evidence that a control operated during the window cannot be created after the window has closed, and the result is an exception in the report. Exceptions and qualified opinions covers how they read to a customer.
Get quotes with your scope attached
Canadian audit firms price the report you have described rather than a generic one.
Get matched