GetSOC2

How many evidence items your SOC 2 audit will ask for

An audit firm sends one list and everything stops until it is answered. This estimates how long that list will be, which control areas carry most of it, and where the work actually lands.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

The first concrete thing a SOC 2 audit produces is a list. It arrives as a spreadsheet, one row per item, and each row wants a document, a screenshot, an export or a sample. Teams budget for the audit fee and then lose three weeks to the list, because nobody told them how long it would be or who would answer it.

This estimates the item count from the things that actually drive it: headcount, the number of places evidence has to be pulled from, the report type, and the criteria you elected. It returns a banded total, a breakdown by control area, and the three areas that will take most of your time. The estimate renders on this page and nothing is emailed anywhere unless you ask for it at the end.

Which report is being examined?

A Type 1 tests design at a point in time. A Type 2 tests operation across a period, which means samples rather than single artefacts.

How many people work there?

Headcount drives every sample that starts with a person: onboarding, offboarding, training, access reviews, background checks.

How many places does evidence come from?

Count systems an auditor would want an export or a screenshot from: cloud accounts, the identity provider, the code host, the ticketing system, the monitoring stack, the endpoint tool.

How often do you ship changes to production?

Change management is a sampled area. The sample size does not grow with your deploy count, but the work of producing a clean sample does.

Which categories are in the report?

Security is in every report. Tick the elective categories you have chosen.

How many vendors are in the dependency list?

How is evidence collected today?

Is this your first SOC 2?

When does the report need to exist?

The model this uses

The baseline is a small first Type 1 covering Security only, which lands at roughly eighty items spread across eight control areas. That is the shape of a first Type 1 at a small Canadian software company: a request list in the mid-eighties, most of it concentrated in access, policy and operations. From there the model applies the multipliers below.

What moves the item count, and by how much
DriverEffectWhy
Type 2 instead of Type 1Up by a third to a halfOperation over a period means samples, and a sample is several items where design was one
Window lengthUp modestly with the periodSample sizes rise with the population, and a twelve month period has more quarters to evidence
HeadcountUp across four areasOnboarding, offboarding, training and access review samples all start from a person list
Systems in scopeUp across three areasAccess and configuration evidence is pulled once per system, not once per company
Elective categoriesUp by categoryAvailability adds recovery testing, Privacy adds the largest block of any single election

What the model deliberately does not do is reduce the count because you use a compliance platform. A platform changes who does the work and how long each item takes. The auditor still asks for the same evidence.

Who actually answers the list

The request is one document and it is never one person's job. Access reviews and system configuration come from engineering. Onboarding, offboarding, training and background checks come from whoever runs people operations. Policies, vendor reviews and risk assessments come from whoever owns the program. Board and management oversight evidence comes from the executive team, and it is the category most likely to be missing because nobody wrote minutes.

Name an owner per control area before the list arrives. The projects that stall are the ones where a single coordinator chases nine people who each think somebody else is handling it.

Common questions

How long does answering the list take?

For a first Type 2 with nothing pre-collected, plan on three to six weeks of elapsed time and somewhere between forty and a hundred and twenty hours of internal effort spread across several people. The elapsed time is driven by how fast people answer, not by how many items there are, which is why naming owners in advance is worth more than any tool.

Does a compliance platform reduce the number of items?

No. It reduces the time each item takes, because access lists and configuration evidence are already collected with a timestamp rather than screenshotted the week fieldwork starts. The request itself is set by the criteria and by the auditor's testing plan. Compliance automation software covers what it does and does not remove.

Can we push back on items?

Yes, and you should, on two grounds: an item that duplicates one already provided, and an item that tests a control outside your described boundary. Both are ordinary conversations. What is not worth arguing is an item you simply cannot produce, because the answer to that is a control gap and the auditor has just found it. Evidence request triage checks one request at a time.

Why does the count go up in year two?

It usually goes down, not up. A renewal reuses the system description, the policies and the control set, and the request narrows to the period evidence plus whatever changed. Year two is where the economics of the whole exercise improve, provided the evidence was collected as it happened rather than reconstructed at the end.

What happens if we cannot produce an item?

For a Type 1, a missing artefact is usually fixable before the report date, because design can be remediated. For a Type 2, evidence that a control operated during the window cannot be created after the window has closed, and the result is an exception in the report. Exceptions and qualified opinions covers how they read to a customer.

Get quotes with your scope attached

Canadian audit firms price the report you have described rather than a generic one.

Get matched