How do I take screenshots that SOC 2 auditors will accept?

March 6, 20262 min readSOC 2 Evidence Collection

What Auditors Want in a Screenshot

A screenshot is the most common form of SOC 2 evidence. Auditors accept screenshots when they can answer three questions from the image alone:

  1. What system is this? (URL bar, page title, or header visible)
  2. What control is demonstrated? (setting clearly shown)
  3. When was this captured? (timestamp visible)

Screenshot Best Practices

DoDon't
Include the browser URL barCrop to just the toggle or setting
Show the date/time (system clock or page timestamp)Capture without any time reference
Use full-page or section capturesTake tiny, context-free crops
Name files descriptively (e.g., "github-branch-protection-main-2026-03.png")Name files "screenshot1.png"
Capture production environmentsCapture staging or test environments
Include the logged-in user contextLeave ambiguity about which account

Common Screenshot Types

ControlWhat to Capture
MFA enforcementIdentity provider settings showing MFA required for all users
Branch protectionGitHub settings page showing required reviews and status checks
Encryption at restDatabase or storage settings showing encryption enabled
Access controlsUser list with role assignments visible
Firewall rulesSecurity group or WAF configuration
Backup settingsBackup configuration showing schedule and retention

How Many Screenshots?

For a SOC 2 Type I audit, expect to provide 50-100 screenshots across all controls. For Type II, you'll need configuration screenshots plus population samples (e.g., 25 PRs showing reviewer approval).

The Timestamp Problem

The most common screenshot rejection is missing timestamps. Solutions:

  • Keep your system clock visible in the screenshot
  • Use browser extensions that overlay timestamps
  • Use the page's own "last modified" or audit log timestamps
  • Document the capture date in a separate evidence log

Where Screenata Helps

Screenata automates screenshot-based evidence collection by recording your application workflows with built-in timestamps, user context, and control metadata. Instead of manually navigating to each settings page and capturing screenshots, Screenata generates audit-ready evidence automatically.

Ready to Automate Your Compliance?

Join 50+ companies automating their compliance evidence with Screenata.

© 2025 Screenata. All rights reserved.