SOC 2 audit prep: what to do the month before
Devika Rao

The audit itself isn't where teams lose time. The scramble in the four weeks before it is.
By the time your auditor shows up, most of the outcome is already decided. What happens in the month before determines whether the audit is a smooth confirmation of what you already knew, or a slow discovery of gaps you didn't.
Here's what that month should actually look like.
Week 4: Pull every access list, and check it against reality
Start with the least glamorous task, because it takes the longest to fix if something's wrong.
Pull a current list of everyone with access to production systems
Cross-check it against your HR system's active employee list
Flag anyone who left the company but still has an active account
This is the single most common finding in SOC 2 audits: former employees with access nobody remembered to revoke. Finding it yourself in week four is a fix. Finding it during the audit is a documented exception.
Pull quote:
Auditors don't expect zero findings. They expect you to have found the same things they would have, first.
Week 3: Reconcile your access reviews
If your policy says access gets reviewed quarterly, this is the week to prove it actually happened.
Gather evidence of your last two or three access reviews
Check that reviews covered every system in scope, not just the obvious ones
Confirm that flagged access from previous reviews was actually revoked, not just noted
A review that identifies a problem and never resolves it looks worse than not reviewing at all. It tells the auditor the process exists on paper but not in practice.
Week 2: Test your incident response, don't just read it
Most teams have an incident response policy sitting in a document nobody's opened in a year.
Walk through your policy as if a real incident happened yesterday
Check that the contact list in the document still has the right names on it
Confirm your logging actually captures what the policy claims it captures
If your policy says you can detect unauthorized access within 24 hours, this is the week to verify that's true, not assumed.
Week 1: Get your evidence into one place
Auditors ask for the same categories of evidence almost every time. Have them ready before they're requested.
Access control lists and role definitions
Audit logs covering the review period
Change management records for any production changes
Vendor and subprocessor list, kept current
Signed policies: security, incident response, data handling
Scattered evidence is the biggest source of delay in the audit itself. When everything lives in one folder with a clear index, the audit moves at the pace of the auditor reading, not the pace of your team searching.
The pattern underneath all of this
Every item above is easier if it was already true before the month started. Access reviews that happen quarterly because it's a habit, not because an audit is coming. Offboarding that revokes access automatically, not manually. Logs that exist because they're built into the system, not bolted on for compliance.
The month before an audit should feel like gathering proof of what you already do, not building the thing you're being asked to prove.

