Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What happens during a SOC 2 audit?
Last verifiedThe CPA firm plans the engagement, walks through each control, requests complete populations of events, selects samples, tests design and — for a Type II — operating effectiveness, discusses deviations, then drafts the report and issues an opinion. The procedures are the practitioner's judgement, not your preference.
The SOC 2 audit process, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
This is the examination, not YOUR engagement plan
Audience: a CISO, CTO, engineering lead, or compliance owner preparing a team for fieldwork, and buyers who want to know what stands behind a report. This page describes what the practitioner does and where your work stops. It does not determine that YOU need SOC 2, does not plan YOUR examination, and does not issue a SOC 2 report.
The examination is performed under SSAE 18 — AT-C section 105 for concepts common to attestation engagements and AT-C section 205 for examinations. Those standards bind the CPA firm. They are not a statute. SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate, because what fieldwork produces is a report with an opinion.
Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, and almost everything about sampling below exists only because of that. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor. Last verified 10 September 2026. Not legal advice.
Auditor procedures versus your preparation
The left column is the practitioner's obligation under the attestation standards. The right column is what makes their work possible — useful, but not required of you by any standard.
| Stage | What the CPA firm does | Kind of text | What you do |
|---|---|---|---|
| Acceptance and planning | Assess independence and competence, agree the engagement terms, understand the system, assess risk, and design procedures accordingly. | Attestation-standard requirement — AT-C sections 105 and 205. | Provide the system description, org context, and prior reports. Best practice: give this early, not at fieldwork. |
| Obtaining the assertion | Require management's written assertion about the description and the controls before reporting. | Attestation-standard requirement — without the assertion there is no examination. | Write and sign the assertion, having actually read it. |
| Walkthroughs | Inquire and observe how each in-scope control is performed, and inspect supporting documents to evaluate design. | Attestation-standard requirement — evaluating design is part of both report types. | Put the person who performs the control in the room, not only the manager who owns it. Best practice. |
| Requesting populations | Ask for the complete population of relevant events for the period — every change, every joiner and leaver, every incident, every access review. | Attestation-standard requirement — sampling depends on population completeness. | Be able to produce complete, reproducible populations from a system of record. Best practice, and the most common failure point. |
| Sampling and testing | Select items, decide sample sizes, and test whether the control operated as described throughout the period. | Attestation-standard requirement — the selection method and sample size are the practitioner's judgement. | Answer requests with dated artefacts rather than reconstructions. Best practice. |
| Evaluating deviations | Decide whether a deviation is an exception, consider its cause and effect, and decide whether the opinion is modified. | Attestation-standard requirement — professional judgement under AT-C section 205, not client discretion. | Explain context and provide additional evidence if it exists. You do not get to overrule the conclusion. |
| Reporting | Draft the report, include the description of tests and results, and issue the opinion. | Attestation-standard requirement — the opinion is the practitioner's. | Review the description for accuracy and write management responses to any exceptions. Best practice. |
Populations and sampling, in plain terms
This is the part engineering teams underestimate. Sampling is only as good as the population it is drawn from, so an incomplete population is a worse problem than a failed sample.
- A population is the complete set of events of one kind during the period: all production changes, all new hires, all terminations, all incidents, all access reviews. Attestation-standard requirement that populations be complete for testing to mean anything.
- Completeness must be demonstrable. "Here is a spreadsheet someone maintained" invites the question of what is missing; an export from the system of record does not. Best practice.
- The practitioner selects the sample and decides its size, informed by population size, control frequency, and risk. You do not choose the items, and asking to is a bad look. Attestation-standard requirement.
- Control frequency drives sample size: daily controls are sampled more heavily than annual ones. Market observation about how firms commonly scale samples; no fixed table applies to every engagement.
- One sampled item without evidence is a deviation. Whether it becomes a reported exception, and whether that changes the opinion, is the practitioner's judgement.
- Reperformance happens: the practitioner may re-execute a check, for example verifying that a terminated user really has no active session or key. Best practice on your side is to assume they will.
- Where a subservice organisation is carved out, the practitioner considers the complementary controls that fall to you and to the report reader. Attestation-standard requirement that the description address them.
Example fieldwork sequence
An illustrative sequence for a first Type II with a modest boundary. It is a market observation of how engagements commonly run, not a schedule any standard imposes, and not a promise about YOUR engagement.
| Step | What typically happens | Who is involved | Kind of text |
|---|---|---|---|
| Kickoff | Scope confirmation, the request list arrives, evidence-delivery mechanics agreed. | Practitioner, compliance owner, engineering lead. | Market observation — the request list is the moment readiness gets tested. |
| Walkthrough block | A series of sessions per control area: access, change, operations, vendor, governance. | Practitioner plus the person who actually performs each control. | Attestation-standard requirement that design be evaluated; the scheduling is observation. |
| Population delivery | Complete exports per control area, with the query or method used to produce them. | Engineering and IT. | Attestation-standard requirement for completeness; documenting the method is best practice. |
| Sample testing | Sampled items requested and tested; follow-up questions on items that look thin. | Practitioner, control owners. | Attestation-standard requirement. |
| Deviation discussion | Possible exceptions raised, context and further evidence sought while there is still time. | Practitioner, compliance owner, leadership. | Attestation-standard requirement that the practitioner evaluate; the timing courtesy is observation. |
| Draft and response | Draft report circulated, description corrected, management responses written for any exceptions. | Leadership, compliance owner, practitioner. | Attestation-standard requirement that the report contain the opinion; your response is a representation. |
| Issuance | Final report issued and dated by the firm. | The CPA firm. | Attestation-standard requirement — only the firm issues it. |
Kinds of text on this page
Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination. | Not a statute, and it binds the practitioner rather than you. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | What experienced teams do to support fieldwork without a scramble. | Not required by any attestation standard. Skipping it is not an exception. |
| Market observation | What firms and engagements are commonly observed to do, including sequencing and sample scaling. | Not a rule, not a quote, and not a promise about YOUR engagement, timeline, or price. |
| SRM recommendation | Something this product suggests doing. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
Preparation is mostly about populations and named humans. Do these before the request list lands, not after.
- List every population the examination will need and, for each, the exact export or query that produces it completely. Test it now.
- Identify the person who performs each control and tell them a walkthrough is coming. Managers describing controls they do not perform is a reliable source of follow-up questions.
- Collect evidence with dates attached at the moment it is created. Reconstructed evidence reads as reconstructed.
- Ask the firm early how they want evidence delivered, and in what format. Saves a week of rework.
- Raise a known gap yourself rather than waiting for it to be found. It does not remove an exception, but it does keep the conversation about facts.
- Do not attempt to influence sample selection. Selection and sample size are the practitioner's judgement.
- Book leadership time for the draft review and management responses. That step is routinely under-scheduled. SRM recommendation.
Checklist
A fieldwork-readiness list, labelled by kind of text. Not an audit programme.
- Every population identified with a reproducible export method? Attestation-standard requirement for completeness; the method is best practice.
- Control performers identified and available for walkthroughs? Best practice.
- Evidence dated and stored in one place? Best practice.
- Management assertion drafted and read by whoever will sign it? Attestation-standard requirement.
- Subservice organisations decided — carved in or out — and their reports obtained? Attestation-standard requirement that the description address them.
- Known gaps written down and disclosed to the firm? Best practice.
- Leadership time booked for draft review and management responses? SRM recommendation.
- Nobody expecting to choose the samples? Attestation-standard requirement — that is the practitioner's judgement.
Where this shows up in ShipReady Metrics
The bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set that is an illustrative readiness mapping to be tailored by a compliance owner.
If you already have a session: evidence collection accumulates dated artefacts so a request list can be answered from a record rather than from memory, and evidence review with the met-verdict overlay records a named human's judgement per control before a practitioner ever looks at it. Connector-sourced evidence — dependency, code-scanning, and secret-scanning ingest — supports the operations and change-management areas. The crosswalk maps SOC 2 to canonical controls by criteria series reference only, without reproducing Trust Services Criteria text. ShipReady Passport and the auditor share token give a reviewer a scoped view during fieldwork; that share is not a report and not a substitute for the populations the firm will ask you to produce.
Nothing in this product samples on the auditor's behalf, decides sufficiency of evidence, or forms an opinion. Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
Procedure descriptions come from the AICPA attestation standards below. Sequencing and sample-scaling comments are labelled market observation because no authority publishes them as rules.
AICPA attestation standards SSAE 18, AT-C section 105 (concepts common to all attestation engagements) and AT-C section 205 (examination engagements), including the requirements for management's assertion, evidence, and reporting. AICPA Trust Services Criteria, TSP section 100 — 2017 criteria with the 2022 revised points of focus, proprietary AICPA material cited by reference and paraphrased, never reproduced. AICPA SOC 2 guidance for service organisations, and AICPA guidance on audit sampling as background for how sampling reasoning works. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.