GetSOC2

Is this SOC 2 evidence request reasonable?

Pick the request your auditor sent and say a little about your audit. You get a verdict, what to send, and, when the request reaches past your scope, a reply you can paste.

Last reviewed 2026-10-01Written by Jacob Masse, TrazTech Inc.

Most items on a SOC 2 request list are routine. A handful are not: a template line left in by mistake, a request about a system you excluded, or a demand for raw data the control never needed. This tool sorts one request at a time into one of four answers, based on the criteria in your report, your scope and what you have already sent.

Which report is this audit producing?

Which optional categories are in scope, besides Security?

Leave all unticked for a Security-only report.

What is the auditor asking for?

Is the system, team or location it concerns inside the boundary you agreed?

Which dates does the request cover?

Have you already sent something that covers it?

The four answers, and what they mean

Typical: send it
The request tests a criterion in your report and sits inside your scope. Send it promptly, labelled with the request number and the dates it covers.
Typical: narrow what you send
The control is in scope, but the request asks for more than the control needs, usually raw data or personal information. Send the evidence that the control operated and offer the rest on a screen share.
Ask which criterion it tests
The request might be legitimate, but nothing in your answers ties it to a criterion or a control. Ask, politely and in writing, before you produce it.
Outside your agreed scope
The request concerns a category you did not elect, a system you excluded or dates outside the period. Point to the engagement letter or scope memo.

The reasoning behind these, with a longer table of common requests, is on when your SOC 2 auditor asks for more than the criteria require. The wider routine, from scope memo to final report, is on managing your SOC 2 auditor. TrazTech, which runs this site, also publishes a longer auditor evidence simulator that walks through a whole request list.

Common questions

What if the tool says a request is out of scope and the auditor disagrees?

Ask which criterion or control the request tests. If they name one you had missed, the request stands and you have learned something. If they cannot, point to the scope memo and ask for the request to be withdrawn.

Does this replace reading the request list with the auditor?

No. It is a quick check on one request at a time. The kickoff meeting, where the auditor walks through the list, is still the best place to remove items that do not fit your scope.

Why is a request for raw data marked as one to narrow?

Because the control being tested almost never needs the data itself. Evidence that encryption, backups or log review operated comes from configuration and records, and sending customer or personal data to a third party creates a privacy obligation the audit does not require.

Get help with a request list that keeps growing

Firms that prepare companies for SOC 2 also run the auditor liaison.

Get matched