What an Auditor Actually Does During a SOC 2 Type II Review
Demystifying Type II fieldwork — samples, walkthroughs, exceptions, and why “we have a policy PDF” is not enough.
A SOC 2 Type II examination tests whether controls operated effectively over a period — not whether you can narrate a secure architecture in a sales call. Licensed CPA firms (or firms that issue under AICPA attestation standards) perform the work; ComplianceBase does not.
The rhythm of fieldwork
- Planning / readiness — scope, system description draft, population completeness.
- Walkthroughs — how access, change, and logging actually work (CC6, CC8.1, CC7.2).
- Sampling — tickets, reviews, deploys, and alerts across the observation window.
- Exceptions — deviations documented; management responses matter.
- Report — opinion, system description, and complementary user entity controls.
Type I skips period operating-effectiveness testing; compare at /compare/soc-2-type-1-vs-type-2.
What auditors are not doing
- They are not “certifying” you as secure forever.
- They are not validating every marketing claim on your website.
- They are not a substitute for GDPR/HIPAA legal compliance.
How to make fieldwork boring (in a good way)
- Keep dated access reviews and change records.
- Inventories that match reality beat perfect CMDB theater.
- Align IR and monitoring so CC7 samples have a story (CC7.4).
Timeline pressure: /costs/soc-2/timeline and /tools/soc-2-timeline-calculator.
Disclaimer: Educational only — not an audit guide from your CPA firm. Examination procedures follow professional standards and your engagement letter.