SOC2 Evidence Collector

Turn a SOC 2 audit into an organized evidence package. Joy maps your policies, tickets, config exports, and access reviews against the Trust Services Criteria, showing for each control what's already on hand, what's still missing, and who owns the gap.

For Security and Compliance Leads GRC Managers Founders at Growing Companies IT and Engineering Owners
Sample prompt to Joy's Assistant

We have a [SOC 2 type] audit coming up, and our observation window is [window]. Here's the context: [context]. Organize our evidence against the Trust Services Criteria into an audit-ready index, showing for each control what evidence we already have in the Knowledge Center, what's still missing, and who owns each gap.

What it can look like

An illustrative example. Your output will reflect your own sources, data, and prompts.

We have a SOC 2 Type II audit coming up, and our observation window is April 1 through September 30. Here's the context: it's our first Type II with Sterling & Beck, we cover the Security and Availability criteria, most of our policies are current and our quarterly access reviews are logged, but our change-management evidence and a couple of config exports aren't pulled together yet, and I want the full picture before I hand gaps to owners. Organize our evidence against the Trust Services Criteria into an audit-ready index, showing for each control what evidence we already have in the Knowledge Center, what's still missing, and who owns each gap.

I've organized your evidence against the Trust Services Criteria, drawing on the policies, tickets, config exports, and access reviews already in your Knowledge Center. Each control shows what's on hand against what's still missing, with an owner named on every gap so you know exactly who to chase before the window closes.

SOC 2 Type II evidence index: draft

Audit: First SOC 2 Type II
Auditor: Sterling & Beck
Criteria in scope: Security, Availability
Observation window: April 1 – September 30, 2026

Here is your evidence organized by control. For each one, what is already in the Knowledge Center, where it stands, and who owns closing the gap.

ControlEvidence on handStatusOwner / next step
CC1.4 — Background checks on new hiresBackground-check policy; completed checks for the 9 people hired in the windowOn handPeople Ops — complete
CC6.1 — Logical access controlsAccess control policy; SSO and MFA enforcement config export from OktaOn handSecurity — complete
CC6.2 — Provisioning and deprovisioningOnboarding tickets present; offboarding tickets for 2 of the 5 leavers not yet linkedPartialIT Ops — attach the 3 missing offboarding tickets
CC6.3 — Quarterly access reviewsQ2 and Q3 user access reviews, signed off in the Knowledge CenterOn handSecurity — complete
CC7.2 — Security monitoring and alertingMonitoring runs, but the alert configuration export and a sample triaged alert are not gatheredMissingSecurity — pull the alert config and one worked alert
CC7.3 — Incident responseIncident response plan; no incident occurred in the window, so a tabletop exercise record is needed in its placeMissingSecurity — run and document a tabletop
CC8.1 — Change managementChange policy on hand; pull-request approval and deploy records exist in the tooling but are not exported as evidenceIn progressEngineering — export a sample of PR approvals and deploys
A1.2 — Backups and recoveryBackup policy; backup job config export on hand; last restore test predates the windowPartialIT Ops — run an in-window restore test and log it

Six of the eight controls have complete or partial evidence; the real work is the four gaps. Two of them, CC7.2 monitoring and CC7.3 incident response, are the ones an auditor tends to push on, and both sit with Security, so that is where I would start. The change-management exports (CC8.1) and the offboarding tickets (CC6.2) are quick to close once someone is assigned. Nothing here is fabricated evidence — each row reflects what is actually uploaded, so the missing rows are genuinely missing, not just unindexed.

Want me to draft the gap request note you can send each owner, or sequence the four gaps into a readiness timeline for the rest of the window?

From scattered evidence to an audit-ready index in a few steps

SOC2 Evidence Collector takes the criteria you're audited against and whatever context you can give it, and organizes your evidence into an index mapped control by control. Joy, the JoySuite assistant, checks each Trust Services Criterion against what's in your Knowledge Center, marks the evidence on hand against what's still missing, and names an owner for every gap.

  1. Give Joy the context

    Tell Joy which SOC 2 report you're going for, the observation window, and the criteria in scope. Mention anything you already know is solid or missing. Rough is fine.

  2. Say what you need organized

    Ask for an evidence index mapped to the Trust Services Criteria, with each control marked on hand or missing and an owner on every gap. Joy fills in the standard controls and sensible owners if you don't spell them all out.

  3. Review the index

    Get your evidence laid out control by control, with statuses and owners, and the gaps pulled into a clear read at the end. Check it against what's actually uploaded and how your controls really run.

  4. Use it where your team works

    Ask for a tweak, "move the change-management export to Engineering" or "add a row for vendor reviews," then copy the index into your GRC tool, shared drive, or the note you send each gap owner.

  5. Make it one click for your team

    Save this ask as a custom command on the assistant your team already uses, so anyone can run it in one step.

Make it yours

Mapped to the Criteria

Evidence is organized against the Trust Services Criteria the way an auditor asks for it, so the index lines up control by control with the request.

On Hand vs Missing

Each control is marked on hand, partial, or missing, so you see the coverage gap at a glance instead of digging for it across drives.

Gap Owners Named

Every gap names who's responsible for closing it, so nothing sits unclaimed as the observation window and fieldwork approach.

The Real Gaps Surfaced

The controls without evidence get called out with a read on which ones an auditor tends to push on, so you know what to close first.

Gap Request Note

Turn the open gaps into a short note you can send each owner with the evidence you need and by when.

Readiness Timeline

Sequence the gaps into a working plan for the weeks before the observation window closes.

Roll Forward Last Year

Start from last year's evidence set and mark what carries over, what needs refreshing, and what's newly in scope.

Type I Readiness Snapshot

Run the same index at a point in time to check control design before you commit to a Type II window.

Frequently Asked Questions

What does a SOC 2 evidence collector do?

It organizes your evidence against the Trust Services Criteria into an audit-ready index. You give Joy the context and it maps each control to the policies, tickets, config exports, and access reviews in your Knowledge Center, marks what's on hand against what's missing, names a gap owner, and reads out the gaps to close first.

Does Joy pull evidence from my live systems automatically?

No. Joy organizes and indexes the evidence you've uploaded to your Knowledge Center, and can read from a connected system only where a connector actually supports it. It won't fabricate evidence or claim to auto-pull from tools it isn't connected to. A control shows as covered only when the evidence is really there.

Which Trust Services Criteria does it cover?

Whichever ones you're audited against. The Security (Common Criteria) set is always in scope, and you can add Availability, Confidentiality, Processing Integrity, or Privacy. Tell Joy the criteria in scope and it maps your evidence to the relevant controls, from logical access to change management to incident response.

Can it use last year's evidence set?

When your Knowledge Center holds the prior report's evidence, Joy uses it to tell what carries over and what's already in place from what needs refreshing for the new window, so you're not rebuilding the index from a blank criteria list.

How do I assign the gaps to my team?

Joy names a suggested owner on each gap, and you can reassign any of them in the same conversation, "move the change-management export to Engineering." Then copy the index into your GRC tool or the note you send each owner. Joy drafts and organizes; it doesn't send.

Ready to know exactly where your SOC 2 evidence stands?

Join the waitlist and be first to try this workflow when JoySuite launches.