Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you collect SOC 2 evidence continuously?
Last verifiedCapture evidence as controls run rather than assembling it before fieldwork: pull requests and approvals as they merge, provisioning and removal records as they happen, scan findings and their remediation dates, review records at each cadence. A Type II opinion covers a period, so evidence has to cover it too.
Continuous SOC 2 evidence collection, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
Continuous monitoring is best practice, not the requirement
Audience: a compliance owner, engineering lead, or CISO trying to keep an observation period audit-ready. This page separates what the attestation standards actually require from the practice that makes meeting it painless. It does not determine that YOU need SOC 2, does not set your cadence, and does not issue a SOC 2 report.
The requirement is narrow and specific: a Type II opinion addresses whether controls operated effectively throughout the stated period, which means the practitioner needs evidence spanning that period. Nothing in SSAE 18 or the Trust Services Criteria requires continuous monitoring, automation, or any particular tool. Continuous collection is best practice — the cheapest way to satisfy the requirement — and calling it a requirement would be inventing one.
SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report or a monitoring cadence. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate, and no continuous monitoring dashboard is one. Type I addresses the design of controls at a point in time, where point-in-time evidence is genuinely the right answer; Type II addresses operating effectiveness over a review period, which is where continuous capture pays for itself. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor. Last verified 10 September 2026. Not legal advice.
Point-in-time versus period evidence
The distinction that decides whether your period is evidenced or reconstructed. Both columns are legitimate; they answer different questions.
| Dimension | Point-in-time evidence | Period evidence | Kind of text |
|---|---|---|---|
| What it shows | A configuration or state on one date. | That a control operated repeatedly across a window. | Attestation-standard requirement — Type II addresses operating effectiveness over the period. |
| Where it fits | Type I, and design evaluation within a Type II. | Type II operating-effectiveness testing. | Attestation-standard requirement. |
| Typical artefact | A settings screenshot, a policy document, a current access list. | Ticket histories, approval records, dated review records, findings with remediation dates, log samples across months. | Best practice — the artefact list is ours, not a standard's. |
| Failure mode | Says nothing about the months before the screenshot. | Gaps become visible, which is uncomfortable and honest. | Market observation — the visible gap is the point. |
| How it is usually produced | Captured on request, near fieldwork. | Captured as the control runs, continuously. | Best practice — continuous capture, not continuous monitoring, is what the period needs. |
An example collection cadence
Illustrative and labelled: cadences are yours to set, and the examination tests whether you met your own stated cadence, not ours. Nothing here is imposed by an attestation standard.
| Cadence | What is captured | Series it supports | Kind of text |
|---|---|---|---|
| Continuous, event-driven | Pull requests with approvals, deployments, provisioning and deprovisioning records, secret-scanning and dependency findings, alerts and their disposition. | CC6, CC7, CC8. | Best practice — event capture is the only way to make these complete after the fact. |
| Weekly | Triage of new findings with owners and target dates; alert review; open incident status. | CC7. | Best practice — cadence is yours to choose; the examination tests the one you stated. |
| Monthly | Deprovisioning reconciliation against the leaver list; backup or restore checks where Availability is in scope. | CC6, and the Availability category if in scope. | Best practice — reconciliation catches the top exception source before fieldwork does. |
| Quarterly | Access reviews with named reviewers and resulting changes; vendor reviews for higher-tier vendors; control self-assessment. | CC4, CC6, CC9. | Best practice for the cadence; the review itself supports criteria you described. |
| Annually | Risk assessment, policy review and re-acknowledgement, security training, incident-plan exercise, continuity or recovery test. | CC1, CC2, CC3, CC7, CC9. | Best practice for the cadence; market observation that annual is the common choice. |
What automation does and does not do
Stated plainly, because this is the section most often overstated by tool vendors — this one included.
- It captures artefacts with their real timestamps, which is the difference between a period that is evidenced and one that is reconstructed.
- It makes populations producible: a system of record you can export beats a spreadsheet somebody maintained.
- It surfaces a control that stopped working while the period is still running, when fixing it is cheap.
- It does not decide whether evidence is sufficient. That is the practitioner's judgement under the attestation standards.
- It does not sample, does not test, and does not form an opinion.
- It does not oblige a practitioner to accept tool output as evidence. Ask your firm early what format they want.
- It does not replace the CPA examination. Automation supports the examination; only a licensed CPA firm can perform it and issue the report.
- A dashboard where everything is green is your own assessment, not an attestation, and should never be shown to a buyer as one.
Kinds of text on this page
Different sentences here carry different weight, and on this page one distinction dominates: the period requirement is a standard, continuous monitoring is a practice.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — including that a Type II opinion address operating effectiveness throughout the period and that the practitioner obtain sufficient appropriate evidence. | Not a statute, and it requires no monitoring cadence, automation, or tool. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | Continuous capture, reconciliation, and the cadence table above. | Not required by any attestation standard. Skipping it is not an exception — though it commonly produces one. |
| Market observation | What teams and firms are commonly observed to do, including annual cadences. | Not a rule, not a quote, and not a promise about YOUR engagement. |
| SRM recommendation | Something this product suggests doing, including using evidence automation. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
Instrument before the period opens if you can, and mid-period if you cannot. Partial coverage disclosed honestly is worth more than a reconstruction.
- List every control in scope and name the system of record that will hold its evidence. Controls with no named source are the ones that fail.
- Turn on event-driven capture for the high-volume areas first: changes, access, findings, alerts.
- Verify capture is actually working one week after the period opens, by producing a population and reading it.
- Set cadences you will keep, and write those cadences into the policy. The examination tests your stated cadence, so do not state a cadence you will miss.
- Reconcile deprovisioning against the leaver list monthly. It is the cheapest exception prevention available.
- Ask your CPA firm what evidence format they prefer before you build exports for a different one.
- Never back-date or fabricate. If a gap exists, record it and disclose it.
- Do not present a green readiness view as an opinion, internally or to a buyer.
Checklist
A continuous-evidence list, labelled by kind of text. Not a required schedule.
- Every in-scope control has a named evidence source and an owner? Best practice.
- Event-driven capture running for changes, access, findings, and alerts? Best practice.
- Populations producible and verified by actually running the export? Attestation-standard requirement for completeness.
- Stated cadences match what the team keeps? Attestation-standard requirement in effect — you are tested against your own description.
- Monthly deprovisioning reconciliation in place? Best practice.
- Evidence timestamps are creation dates, not export dates? Best practice.
- Firm's preferred evidence format confirmed? Market observation — saves rework.
- Nobody treating a monitoring dashboard as an attestation? Attestation-standard requirement — only a CPA firm issues an opinion.
Where this shows up in ShipReady Metrics
This is the closest fit between this cluster and what the product does. Evidence collection captures artefacts continuously with their own timestamps rather than at request time, which is what a Type II period needs. Evidence review with the met-verdict overlay records a named human's judgement that an item supports a control, as you go instead of in a final scramble — that verdict is an internal judgement, never an attestation opinion. Connector-sourced evidence covers a real slice automatically: dependency findings, code-scanning results, and secret-scanning results ingest with their own dates.
The bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set that is an illustrative readiness mapping to be tailored by a compliance owner. The 24-framework crosswalk maps SOC 2 to canonical controls by criteria series reference only, never reproducing Trust Services Criteria text, and mapped coverage is not a count of criteria met. The policies library holds documents and acknowledgements. The cyber risk register under the security area tracks remediation. ShipReady Passport and the auditor share token hand a reviewer a scoped, current view — which is a posture share, not a report and not a bridge letter.
Readiness in this product is not an attestation opinion. This product does not decide sufficiency, does not sample, does not issue a SOC 2 report, and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
The period requirement comes from the attestation standards. Cadences and collection practices are labelled best practice or market observation, because no authority publishes them as rules.
AICPA attestation standards SSAE 18, AT-C section 105 and AT-C section 205, including that a Type II examination addresses operating effectiveness throughout the specified period and that the practitioner obtain sufficient appropriate evidence. AICPA Trust Services Criteria, TSP section 100 — 2017 criteria with the 2022 revised points of focus, proprietary AICPA material cited by reference and paraphrased, never reproduced. AICPA SOC 2 guidance for service organisations. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The continuous-compliance guide on this site is the vendor-neutral background reading. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.