# SOC 2 Evidence Plan

> Use this template to evidence collection plan for SOC 2 audit controls.

## Template Metadata

| Field | Details |
|-------|---------|
| Category | Cybersecurity & Privacy |
| Owner | [Team or owner] |
| Version | [Version number] |
| Effective Date | [Date] |
| Review Cycle | [Monthly / Quarterly / Annual / Event-based] |
| Status | [Draft / In Review / Approved] |

## Audit Scope

Define report type, trust service criteria, systems, and period.

| Item | Details | Owner | Status |
|------|---------|-------|--------|
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |

### Notes

[Add context, assumptions, exceptions, evidence links, screenshots, calculations, or reviewer comments.]

## Control Mapping

Map controls to evidence artifacts and responsible teams.

| Item | Details | Owner | Status |
|------|---------|-------|--------|
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |

### Notes

[Add context, assumptions, exceptions, evidence links, screenshots, calculations, or reviewer comments.]

## Evidence Requests

List required exports, screenshots, policies, tickets, logs, and approvals.

| Item | Details | Owner | Status |
|------|---------|-------|--------|
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |

### Notes

[Add context, assumptions, exceptions, evidence links, screenshots, calculations, or reviewer comments.]

## Owners

Assign control owners, reviewers, and backup contacts.

| Item | Details | Owner | Status |
|------|---------|-------|--------|
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |

### Notes

[Add context, assumptions, exceptions, evidence links, screenshots, calculations, or reviewer comments.]

## Collection Schedule

Set due dates, sampling windows, and auditor delivery dates.

| Item | Details | Owner | Status |
|------|---------|-------|--------|
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |

### Notes

[Add context, assumptions, exceptions, evidence links, screenshots, calculations, or reviewer comments.]

## Quality Checks

Describe validation steps before evidence is submitted. Use auditor-ready naming, dates, and evidence status tables.

| Item | Details | Owner | Status |
|------|---------|-------|--------|
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |
| [Item or requirement] | [Describe the relevant detail, evidence, or decision] | [Owner] | [Open / Complete] |

### Notes

[Add context, assumptions, exceptions, evidence links, screenshots, calculations, or reviewer comments.]

## Review and Signoff

Document review conclusions, approvals, unresolved items, and next review date.

| Role | Name | Date | Notes |
|------|------|------|-------|
| Preparer | [Name] | [Date] | [Notes] |
| Reviewer | [Name] | [Date] | [Notes] |
| Approver | [Name] | [Date] | [Notes] |
