Skip to content
compliancebase

What an Auditor Actually Does During a SOC 2 Type II Review

July 22, 2026 · ComplianceBase Editorial, Independent security compliance reference editors; frameworks cited to primary sources (AICPA TSC, ISO/IEC 27001, GDPR, HIPAA)

Demystifying Type II fieldwork — samples, walkthroughs, exceptions, and why “we have a policy PDF” is not enough.

A SOC 2 Type II examination tests whether controls operated effectively over a period — not whether you can narrate a secure architecture in a sales call. Licensed CPA firms (or firms that issue under AICPA attestation standards) perform the work; ComplianceBase does not.

The rhythm of fieldwork

  1. Planning / readiness — scope, system description draft, population completeness.
  2. Walkthroughs — how access, change, and logging actually work (CC6, CC8.1, CC7.2).
  3. Sampling — tickets, reviews, deploys, and alerts across the observation window.
  4. Exceptions — deviations documented; management responses matter.
  5. Report — opinion, system description, and complementary user entity controls.

Type I skips period operating-effectiveness testing; compare at /compare/soc-2-type-1-vs-type-2.

What auditors are not doing

  • They are not “certifying” you as secure forever.
  • They are not validating every marketing claim on your website.
  • They are not a substitute for GDPR/HIPAA legal compliance.

How to make fieldwork boring (in a good way)

  • Keep dated access reviews and change records.
  • Inventories that match reality beat perfect CMDB theater.
  • Align IR and monitoring so CC7 samples have a story (CC7.4).

Timeline pressure: /costs/soc-2/timeline and /tools/soc-2-timeline-calculator.

Disclaimer: Educational only — not an audit guide from your CPA firm. Examination procedures follow professional standards and your engagement letter.