Cloud compliance evidence collection
Evidence is what an auditor samples, not what you describe. In the cloud, most configuration evidence can collect itself. Access reviews, change approvals and incident records still need a routine.
Collect cloud compliance evidence in two streams. Configuration evidence, such as encryption, logging, public exposure and MFA settings, should come from continuous tooling that keeps history: AWS Config, Azure Policy or Google Cloud's Security Health Analytics. Activity evidence, such as access reviews, change approvals, incident tickets and restore tests, comes from a schedule and the systems where the work happens. Store both by control and period.
How auditors sample
For a Type 2 SOC 2, auditors test a control's operation across the period. For a control that runs continuously, they may ask for its configuration at a few points in time or its history. For a control that runs on events, such as changes or new starters, they pick a sample from the population. For a quarterly control, they usually ask for every instance.
| Control frequency | Typical sample | Cloud example |
|---|---|---|
| Continuous or automated | 1 plus a test of the configuration | Default encryption enforced |
| Many times a day | 25 to 60 | Production deployments |
| Weekly | 5 to 15 | Vulnerability triage |
| Monthly | 2 to 5 | Security finding review |
| Quarterly | 2 to 4 | Access review |
| Annual | 1 | Restore test, penetration test |
Auditors set their own sample sizes, and these are common ranges rather than rules. The evidence request estimator on GetSOC2 estimates the total number of requests for your scope.
Where each piece of cloud evidence comes from
| Evidence | Automated source | Manual part |
|---|---|---|
| Encryption at rest | Config rules, Azure Policy, SHA | None |
| Logging enabled and retained | Trail and sink configuration, Config rules | Retention decision in policy |
| No public storage | Config rules, Azure Policy deny, org policy | None |
| MFA enforced | Identity provider policy | Exception list |
| Access review | Role assignment export | Owner sign-off |
| Change approval | Pull request and pipeline history | Emergency change tickets |
| Vulnerability remediation | Scanner finding history | Exceptions |
| Threat detection | GuardDuty, Defender, SCC enabled status | Triage notes |
| Backups | Backup job history | Restore test record |
| Incident response | Ticket system | Post-incident review, tabletop record |
How far native tooling gets you
Native tooling covers most configuration evidence and some activity evidence. It does not cover policies, training, vendor reviews, HR records or risk assessments. On a typical SOC 2 control set, native cloud tooling can collect evidence for roughly a third of controls automatically. The coverage estimator gives a figure for your setup, and the provider guides cover the detail: AWS, Azure, Google Cloud.
Organizing evidence
Whatever tool you use, keep evidence by control, then by period, with the date the artifact was produced in its name. A shared drive works for a first audit. A compliance workspace, such as the free traztech Workspace or a paid platform, keeps the mapping and chases owners. Compliance automation platforms for cloud compares the options.
Evidence mistakes that cost time
- Undated screenshots. The auditor cannot place them in the period. Include the date and the account or subscription in view.
- Evidence from after the fact. A restore test run the week before fieldwork proves the control today, not across the window.
- Settings without history. A current configuration export does not show it was true six months ago. Continuous recording does.
- Evidence of a different control. A security group rule proves segmentation, not access review. Map each artifact to the control it proves.
Can SOC 2 evidence be fully automated in the cloud?
No. Configuration evidence can be automated. Controls that involve people, such as access reviews, training, vendor assessments, policy approval and incident handling, need someone to do them and record it. Automation reduces the effort of collecting evidence, not the need to operate the controls.
Are screenshots acceptable evidence?
Yes, if they show the date, the environment and the setting clearly. Exports and reports from the console or API are better because they are complete and harder to misread.
How long should we keep evidence?
At least until the report for that period is issued, and in practice for a year or two after, so you can answer questions and compare periods. Your record retention policy should say.
Want the evidence routine set up for you?
Firms in the network map controls to evidence and automate what can be automated.
Get matched