Most companies preparing for a SOC 2 Type 2 audit know the basics: it covers an observation period, not a single date, and it's what enterprise buyers actually want to see. What almost nobody explains is what actually happens once the observation period starts, what an auditor is looking at, and what the finished report contains.
This page walks through the mechanics. If you need the Type 1 vs Type 2 basics first, start with the complete SOC 2 guide.
What Actually Happens During a Type 2 Audit
A Type 2 audit has two distinct phases. First, the observation period, typically three to twelve months, during which your controls simply run and generate their own evidence trail. Second, fieldwork, which starts once the period closes and is when the auditor actively tests what happened.
The critical point people miss: the auditor is not watching you in real time during the observation period. They arrive afterward and reconstruct, from evidence, whether each control operated consistently throughout.
The Observation Period: What "Continuous" Testing Actually Means
"Continuous" does not mean the auditor is logged into your systems daily. It means your own controls need to generate evidence continuously, so that when fieldwork starts, a full trail exists to sample from. A quarterly access review that only happened once during a six-month period is a gap regardless of how well-designed the control looks on paper.
This is why compliance automation platforms exist: they capture evidence automatically as it's generated, rather than relying on someone remembering to screenshot a config six months later. See how that model compares to a done-for-you approach in our Avantcert vs Vanta, Drata & Sprinto comparison.
What Auditors Test and How They Sample
Auditors don't review every instance of every control, that would be impractical for anything running daily. Instead they use sampling: a statistically defensible subset selected across the period.
- High-frequency controls (logging, automated alerts) get larger samples pulled from multiple points in the period.
- Low-frequency controls (quarterly access reviews, annual risk assessments) may be tested near-exhaustively, since there are only a handful of instances to check.
- Population-based sampling is used for things like new hires or terminations: the auditor requests the full list, then samples a subset to verify onboarding or offboarding evidence exists for each.
Evidence Requests: What You'll Actually Be Asked For
A typical Type 2 evidence request list includes:
- Access logs and periodic access review records, showing who had access and that it was reviewed
- Change management tickets linking code changes to peer review and deployment approval
- HR records for onboarding and offboarding, timestamped against system access provisioning and deprovisioning
- Meeting minutes or sign-offs for management review and risk assessment activities
- Vendor risk assessments and any subprocessor SOC 2 reports you rely on
- Incident tickets, if any occurred, with evidence they followed your documented response process
- Configuration exports or screenshots for encryption, firewall rules, and logging settings, usually requested at more than one point in the period
Expect several rounds of requests, not one, as the auditor's initial sample sometimes surfaces follow-up questions.
Fieldwork Week by Week
| Week | What happens |
|---|---|
| 1 | Kickoff call, auditor confirms system description and control matrix against what you submitted |
| 2 – 3 | Initial evidence request list issued; you upload documents and screenshots to the auditor's portal |
| 4 – 5 | Auditor reviews evidence, flags gaps or asks follow-up questions; control-owner interviews scheduled |
| 6 | Interviews conducted with control owners; any exceptions identified and discussed |
| 7 – 8 | Draft report circulated for management review; final report issued |
This assumes evidence is well organised going in. Disorganised evidence, or gaps discovered mid-fieldwork, routinely stretch this to twelve weeks or more.
What's Inside a SOC 2 Type 2 Report
The finished report has four parts, and enterprise buyers read them in a specific order:
- The auditor's opinion — a short letter stating whether controls were suitably designed and operated effectively. This is what gets skimmed first.
- Management's assertion — your own written statement describing the system and asserting the controls as designed.
- System description — a detailed narrative of your infrastructure, people, and processes in scope. Security teams check this against their own risk model.
- Tests of controls and results — a control-by-control table showing what the auditor tested, the sample size, and the outcome, including any exceptions. This is the section that actually gets scrutinised.
Want your evidence organised before fieldwork starts?
A readiness assessment catches gaps before the auditor does, and keeps fieldwork on the eight-week track instead of twelve.
Get a Free QuoteExceptions: What They Mean and Whether They're Fatal
An exception is a documented instance where a control didn't operate as claimed, one offboarding that took four days instead of the promised 24 hours, for example. Isolated exceptions are normal and get described in the report rather than blocking it; a clean report with zero exceptions across a full observation period is actually somewhat unusual for a first-time Type 2.
What matters is the pattern. A single late offboarding reads very differently from ten late offboardings out of a sample of twelve, the second is a control that isn't really operating, and can push the auditor toward a qualified opinion.
Common Reasons Type 2 Audits Get Delayed
- Slow evidence turnaround. The single biggest cause. Every week you take to respond to a request is a week added to the timeline.
- Evidence that contradicts the system description. If your documentation says quarterly access reviews happen and the evidence shows two instead of four, that's a finding, not a formality.
- Staff turnover mid-period. If the person who approved access changes left the company, reconstructing that evidence trail takes real time.
- Scope surprises. A system or vendor that turns out to be in scope but wasn't documented at the start.
- Auditor scheduling. Reputable firms are often booked weeks out; this delay exists independent of how ready you are.
Ready to start your observation period?
We coordinate readiness and audit scheduling together so fieldwork isn't the first time gaps get discovered.
Talk to an Avantcert ExpertFrequently asked questions about the SOC 2 Type 2 audit process
What does a SOC 2 Type 2 auditor actually look at during fieldwork?
The auditor tests whether each control you claimed actually operated throughout the observation period, not just whether it exists. That means reviewing access logs, change tickets, HR onboarding and offboarding records, meeting minutes for management reviews, and screenshots or exports of system configurations, sampled across multiple points in the period rather than a single date.
How does an auditor sample evidence for a Type 2 report?
Rather than reviewing every single instance of a control, auditors select a statistically defensible sample, for example a subset of access reviews, deployments, or new hires from across the observation period. Sample sizes typically scale with frequency: a control that runs daily gets a larger sample than one that runs quarterly.
What is an exception in a SOC 2 Type 2 report, and is it disqualifying?
An exception is an instance where a control did not operate as described, for example one offboarding that happened three days late instead of within 24 hours. A small number of isolated exceptions is common and does not disqualify the report; auditors describe them in the report rather than withholding it. A pattern of repeated exceptions on the same control is what typically leads to a qualified opinion.
What sections does a SOC 2 Type 2 report contain?
Four main sections: the auditor's opinion letter, management's written assertion about its own controls, a detailed description of your system, and the auditor's description of each control tested along with the results and any exceptions. The last section is what enterprise security teams actually read closely.
How much of the observation period do auditors actually review?
The full period is in scope, but auditors sample within it rather than reviewing every day continuously. For a six-month observation period, expect evidence requests covering activity from the first month, a middle point, and the final weeks, so gaps late in the period are just as visible as gaps at the start.
Why do SOC 2 Type 2 audits get delayed?
The most common causes are slow evidence turnaround from the client, evidence that does not match what the system description claims, staff turnover mid-period that breaks the chain of who-approved-what, and scope changes discovered during fieldwork. Auditor scheduling backlogs also add delay independent of your own readiness.
Do auditors interview employees during a Type 2 audit?
Yes, typically control owners rather than the whole company: whoever approves access changes, runs the incident response process, or owns vendor risk reviews. Interviews corroborate the evidence and check that the person executing a control actually understands it, not just that a document describing it exists.
How soon after the observation period ends do you receive the report?
Typically four to eight weeks after the observation period closes and fieldwork evidence requests are complete, longer if exceptions require follow-up documentation or management response. Auditors cannot finalize the opinion until every sampled control has been tested and any findings addressed in the report narrative.
About Avantcert. Avantcert is an ISO and compliance certification consultancy that has guided 3,000+ organisations across 40+ markets to certification and attestation, with readiness assessment and audit coordination for SOC 2. See our SOC 2 service or request a free quote.