The 5 Questions Every SOC 2 Auditor Will Ask
2026-07-28 · 6 min read
Auditors do not start with your policy binder. They start with how a new engineer gets access, who approved last week’s production change, and what happens when a laptop is lost.
1. Who can reach production, and how do you know?
Expect to show identity providers, role assignments, joiners/movers/leavers, and the last access review. “We use SSO” is not an answer. “Here is the Okta group, the owner, and the quarterly review with exceptions closed” is an answer.
2. How does a change get to production?
Auditors want a ticket, a review, a deploy record, and a way to see emergency changes. If your team merges to main and hopes, you will spend the engagement reconstructing history. Wire the pipeline to the control — not the other way around.
3. Where does customer data live, and who else can see it?
Map stores, backups, logs, support tools, and subprocessors. The painful answers are usually a CRM export, a shared support inbox, or a vendor that got production credentials “just for the migration.”
4. What happens when something goes wrong?
Incident response is not a PDF. They will ask for a recent event — even a near miss — and walk the timeline: detect, contain, notify, review. If you have never run the playbook, run a tabletop before the auditor does it for you.
5. Can you show the evidence without a scavenger hunt?
The teams that look mature are not the ones with the longest policies. They are the ones who can pull an access review, a change sample, and a vendor packet in the same afternoon. That is what a readiness engine is for.
Want this mapped onto your stack?
Send a readiness request. A representative will get in touch to collect details — this is not the assessment itself, and not an examination or certification.