SOC 2 · Type II Preparation
The evidence trail over the observation period — the expensive part of the SOC 2 audit.
Type II audits don't look at a single day — they look at an entire period.
"Compliance is my sales argument. Enterprise deals hang on the trust package and GDPR proof." That's how SaaS CISOs describe what SOC 2 is used for in practice — often it's not optional, but a hard requirement in contracts with larger customers. The difference from Type I is crucial: a Type I report certifies that controls existed on a specific date, but a Type II report certifies that they actually worked throughout an observation period, typically three to twelve months.
That's exactly what makes Type II preparation expensive: evidence must be collected continuously throughout the observation period, not assembled shortly before the audit date. Retroactively reconstructed proof — screenshots from three months ago, tickets edited after the fact — are a red flag to auditors, not a substitute for genuine continuous collection.
The nine Common Criteria categories (CC1–CC9) of the Trust Services Criteria overlap heavily with NIS2 and ISO 27001. If you're already maintaining these frameworks, you shouldn't have to collect the same evidence a third time separately.
Four building blocks for Type II preparation.
TSC Control Catalog (34 Controls)
The Trust Services Criteria are maintained as a structured control catalog with 34 controls across the nine Common Criteria categories — as a shared baseline, rather than being reinterpreted for each audit.
Evidence Requests & Findings
Evidence requests are distributed to responsible parties and tracked continuously, deviations recorded as findings — rather than searched for in an Excel spreadsheet at the end of the observation period.
Type II Attestation Over Time
A traceable attestation of control effectiveness emerges for the entire observation period — with timestamps proving that evidence was collected continuously, not retroactively.
Verifiable Auditor Export
A complete export package is created for the external auditor, whose seal can be independently verified — without the auditor needing access to your system.
More about SOC 2 and the engine behind it.
Trust Services Criteria, Type I vs. Type II, and primary sources in detail.
Regulation details →How sealed evidence and the auditor export work together in workspace.reportact.com.
Feature details →