Why does your SOC 2 auditor keep asking for more evidence?

March 6, 20262 min readSOC 2 Evidence Collection

Common Reasons for Additional Evidence Requests

ReasonExampleHow to Prevent
Missing timestampScreenshot has no date visibleInclude system clock or page timestamp
Wrong environmentCaptured staging instead of productionAlways capture from production
Unclear what's shownCropped too tightly, context lostInclude URL bar and page header
Insufficient sample sizeProvided 5 PRs, auditor needs 25Ask auditor for expected sample sizes upfront
Missing period coverageEvidence only shows one month of a 6-month periodCollect evidence throughout the observation period
Policy-evidence gapPolicy claims control the evidence doesn't demonstrateAlign policies with what you can actually prove

The Cycle That Frustrates Startups

  1. You submit evidence
  2. Auditor reviews it 3-5 business days later
  3. Auditor requests additional or clearer evidence
  4. You spend 2-3 hours re-collecting
  5. Submit again, wait another 3-5 days
  6. Repeat

This cycle can extend an audit by weeks. The fix is frontloading quality: make sure every piece of evidence is clear, timestamped, and from the right environment before the first submission.

How to Minimize Follow-Up Requests

Before the audit:

  • Ask your auditor for their evidence request list (most have a standard template)
  • Ask what sample sizes they expect for population testing
  • Confirm which environment they want to see (production, always)

During evidence collection:

  • Include the browser URL bar in every screenshot
  • Show a visible date/time in every capture
  • Name files descriptively: "aws-iam-mfa-enforcement-2026-03.png"
  • Organize evidence by control (CC6.1, CC7.2, CC8.1)

If the auditor asks for more:

  • Clarify exactly what they need before recollecting — ask for a specific example of acceptable evidence
  • Address all requests in one batch rather than one at a time

Ready to Automate Your Compliance?

Join 50+ companies automating their compliance evidence with Screenata.

© 2025 Screenata. All rights reserved.