Use Case Use Cases / SOC 2

SOC 2 · Type II Preparation

The evidence trail over the observation period — the expensive part of the SOC 2 audit.

Why this matters

Type II audits don't look at a single day — they look at an entire period.

"Compliance is my sales argument. Enterprise deals hang on the trust package and GDPR proof." That's how SaaS CISOs describe what SOC 2 is used for in practice — often it's not optional, but a hard requirement in contracts with larger customers. The difference from Type I is crucial: a Type I report certifies that controls existed on a specific date, but a Type II report certifies that they actually worked throughout an observation period, typically three to twelve months.

That's exactly what makes Type II preparation expensive: evidence must be collected continuously throughout the observation period, not assembled shortly before the audit date. Retroactively reconstructed proof — screenshots from three months ago, tickets edited after the fact — are a red flag to auditors, not a substitute for genuine continuous collection.

The nine Common Criteria categories (CC1–CC9) of the Trust Services Criteria overlap heavily with NIS2 and ISO 27001. If you're already maintaining these frameworks, you shouldn't have to collect the same evidence a third time separately.

What you get

Four building blocks for Type II preparation.

TSC Control Catalog (34 Controls)

The Trust Services Criteria are maintained as a structured control catalog with 34 controls across the nine Common Criteria categories — as a shared baseline, rather than being reinterpreted for each audit.

Control catalogue across all frameworks including SOC 2 TSC in ReportAct

Evidence Requests & Findings

Evidence requests are distributed to responsible parties and tracked continuously, deviations recorded as findings — rather than searched for in an Excel spreadsheet at the end of the observation period.

Evidence checklist per SOC 2 control in ReportAct

Type II Attestation Over Time

A traceable attestation of control effectiveness emerges for the entire observation period — with timestamps proving that evidence was collected continuously, not retroactively.

SOC 2 Type II attestation generated from live evidence in ReportAct

Verifiable Auditor Export

A complete export package is created for the external auditor, whose seal can be independently verified — without the auditor needing access to your system.

Independently verifiable auditor package with offline verifier in ReportAct
Dive deeper

More about SOC 2 and the engine behind it.

SOC 2 — the regulation

Trust Services Criteria, Type I vs. Type II, and primary sources in detail.

Regulation details →
Trust Center — the feature

How sealed evidence and the auditor export work together in workspace.reportact.com.

Feature details →
Next step

Your first sealed SOC 2 evidence — today.

In 30 minutes we show you what ReportAct delivers for this use case – no obligation.