The SOC 2 PBC list: 26 requests and how to answer each

Here is the evidence request list itself, not a definition of it. Each item shows what to send and what gets it returned.

A SOC 2 PBC list is the set of evidence requests your auditor sends when fieldwork starts. PBC means prepared by client. Each numbered line is an export, a document or a screenshot you owe, and the examination waits until it arrives. Below are all 26 requests, with what to send and what gets a response returned.

The requests themselves are plain. The answers are where time goes. A reply that looks complete but misses the test sends your file to the back of the auditor's queue, and that costs days of calendar each time. So read the right hand column of each table first. It is the part that saves you the most.

Why you have to produce it yourself

The name draws a line between the auditor's work and yours. That line exists for independence. An auditor who assembled your evidence would be testing their own work.1 So every item is something only your company can generate. You can ask the auditor what would satisfy a request. You cannot ask them to produce it.

That is also where the cost question starts. Somebody on your side has to pull these exports. Some teams pay an outside consultant to do it. Here is one published estimate of what that route costs:

  • Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.

Most of the list is exports and screenshots from tools you already run. An engineer with admin access and this page can answer nearly all of it.

Four defects that send evidence back

Scan the last column below and the same four problems repeat. None is a security weakness. Each one costs a round trip.

  1. A document where an export was asked for. Retyped data proves only the typing.
  2. No date or scope in the artifact. The auditor cannot tie it to the period.
  3. A subset instead of the full population. Picking the sample is the auditor's job.
  4. Timestamps in the wrong order. An approval after the change is no approval.

All 26 requests by control area

The wording is representative, not copied from one firm. Numbers run straight through so you can assign and chase each line by number. One caveat: we scope Security only, and a Security examination does not test availability commitments. Items 24 to 26 still come up, because recovering from a security incident sits inside the common criteria,3 but how deep they go depends on your scope.

Access control

No.RequestSend thisReturned when
1List every user with production access as of period end, with name, role and the date access was grantedAn export from the identity provider or cloud console, with the tool name and export date showingA hand built spreadsheet. With no source or date, it only proves someone typed it
2Show the latest user access review: who ran it, when, and what changed because of itThe review record plus the tickets or console entries for each removal it causedA review that changed nothing. No removals at all looks like no review happened
3Show that multi factor authentication is enforced for everyone using the production consoleThe settings page showing enforcement and the group it coversA screenshot of your own MFA prompt. It shows you use it, not that it is required
4For the sampled leavers in the period, show that access was removed and whenThe offboarding ticket plus a timestamped deprovisioning log or directory recordA ticket closed as done with no system record. Done is a status, and the test needs a date
5List current privileged and admin accounts, service accounts included, with a reason for eachThe export, with a named human owner beside each service accountService accounts missing. The auditor spots them in item 1 and asks again

Change management

No.RequestSend thisReturned when
6Provide every production change in the period, with its ID, date and requesterA full period export from the pipeline or ticketing tool, with the row countA filtered list. Choosing the sample is the auditor job, so a trimmed list is not a population
7For the sampled changes, show review and approval before deploymentThe pull request or ticket with an approver, and a merge time later than the approvalAn approval timestamped after the deploy. Sequence is the whole test
8Show that only authorized people can deploy to productionAn exported permission list from the repository or pipeline showing who can deployThe written policy in place of the setting. The policy describes; the setting proves
9Explain the emergency change process and show evidence for any emergency changes in the periodThe written procedure, plus a ticket and after the fact approval for each emergency changeAnswering none when item 6 shows a late Saturday deploy

Monitoring and vulnerabilities

No.RequestSend thisReturned when
10Provide the latest vulnerability scan of production, with its date and scopeThe untouched scanner report with target range, date and counts by severityA dashboard screenshot with no scope. Nobody can tell what was scanned
11For sampled critical and high findings, show remediation and the close dateA rescan or ticket showing the fix, closed within the window your policy setsA close date with no discovery date. Without both ends the window cannot be tested
12Show that security events are logged and watched, including alert setup and alerts fired in the periodThe alert rules plus real alerts with timestamps and the response logged for eachRules that never fired. That shows intent, not a running control
13Show that logs are kept for the period your policy statesThe retention setting plus a query returning a real record from the oldest date you claimThe setting alone. A configured value and data still on hand are two different facts

Incident response

No.RequestSend thisReturned when
14Provide all security incidents in the period, or written confirmation that there were noneAn export of the incident register, or a dated statement from the named owner if emptyA spoken none or a line buried in email. It must be a dated artifact
15For each incident, give the ticket, timeline, root cause, and proof of resolution and communicationThe incident record with detection time, actions, and who was told and whenA postmortem missing the detection time, the field the test depends on
16Show that the incident response plan was tested or exercised in the periodThe tabletop agenda, attendees, date and resulting findingsAn exercise held before the window opened. The date decides coverage

Vendors and subservice organizations

No.RequestSend thisReturned when
17List third party vendors and subservice organizations, with the data each one handlesA vendor register showing data type and where each vendor sits against your system boundaryA list of everything you pay for. Scope here is data access, not spend
18For sampled vendors, give the latest SOC 2 report or equivalent and proof it was reviewedThe report itself plus a dated note of who read it and what they concludedA link to a trust page. A link is not a report, and a download is not a review
19For vendors added in the period, show the risk assessment done before onboardingThe assessment record, dated before the contract or first data transferAn assessment dated after go live. The control is preventive, so the date is the test

People

No.RequestSend thisReturned when
20List all employees and contractors hired in the period, with start datesAn HR system export for the period with contractors includedContractors left off. If they can reach production, they belong in the list
21For sampled new hires, show a background check completed around the start dateThe screening provider record with the candidate identifier and dateA confirmation email with no name or date, which matches nobody in the sample
22Show that each sampled employee accepted the security policy and code of conductA signed acknowledgment or a system record with each person acceptance dateA company wide announcement. Acknowledgment has to be per person
23Show security awareness training completion for the period, with datesThe training platform completion report for every current employeeAn enrollment list. Enrolled is not completed, and the column headers show it

Backup and continuity

No.RequestSend thisReturned when
24Show that production backups run on schedule and are monitoredThe backup job settings plus run records for the period, failures includedSuccesses only. A year with zero failures looks edited
25Show a restore from backup tested in the period, with date and resultA restore test record naming who ran it, what came back and how long it tookA claim that restores are tested regularly with no dated instance
26Provide the continuity or disaster recovery plan and proof of its latest review or testThe current plan with a version date, plus an exercise record from inside the periodA solid plan last reviewed two years ago. The review date is the finding

When each part of the list arrives

The list comes from the CPA firm doing the examination, not from a software vendor. It shows up in two waves and then produces a third. Knowing which wave you are in tells you what you can answer fast.

Planning wave
Short, and early. Policies, an org chart, your system description, the scope boundary. You either have these or you do not, so it is an early warning that costs nothing.
Fieldwork wave
The long one, sent once the period is fixed. Populations, samples, exports and screenshots. For a Type 2 it waits until the period closes, since the auditor samples from a complete population.
Follow up wave
Whatever the first two did not settle. Its size depends entirely on how well you answered the fieldwork wave.

For a Type 2 the timing is fixed. The population must span the whole 3-month observation window before sampling can start,2 which is why the observation period sets the earliest possible start of the examination.

What a slow answer really costs

Auditors work in blocks of time. When your response comes back incomplete, your file goes down and another client's comes up. You are not waiting for a reply. You are waiting for their next free block. The rework takes twenty minutes. The requeue takes days, and two of them can stretch a short examination into a month. How long SOC 2 takes shows where that month lands.

It works in your favor too. A complete, well formatted first reply keeps your file on the desk, and the follow up shrinks to a few clarifications. Same controls, same evidence, shorter calendar.

Missing evidence is worse than slow evidence. It becomes a test the auditor could not perform, and it lands in the report as an exception or a scope limitation that your buyers will read.2 What happens when an examination finds exceptions shows how that looks.

On a small engagement, the hours go into chasing unorganized evidence, not judging your controls.

Answering it in one pass

None of this takes special skill. A handful of habits decides whether the follow up is four lines or forty.

  1. One named owner per line. Assign them the day the list lands. A line owned by a team is still open in week three.
  2. Export, never retype. Send the raw system output with the tool and date visible. The messy export beats your tidy copy.
  3. Show date and scope in every screenshot. Capture the whole window, clock and account name included, instead of cropping to one setting.
  4. Send full populations. Filtering first looks helpful and reads as selection.
  5. Answer what was asked. If item 12 wants fired alerts and you only have the rules, say so. A flagged gap gets discussed. A quiet swap gets returned.

Fixing weak controls before the list arrives removes whole rows from it. Five common control failures covers the ones to check first, and the access review template handles item 2.

How this fits your costs

The software is $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, including every Type 2, and you see the price in your account before you book, so a second round of requests does not change it. A slow reply costs you calendar, not money.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Your next step

See how many of these 26 lines you could answer today. The free readiness assessment takes about 15 minutes and returns a readiness assessment, score, gap list and one AI sample policy, so the gaps show up before an auditor asks. Then compare plans on the pricing page.

Questions

What does PBC stand for in SOC 2?
Prepared by client. It is the numbered list of documents, exports and screenshots the CPA firm asks you to supply. The auditor cannot create your evidence and stay independent, so every factual artifact about your company must come from you.
When do I get the PBC list?
In stages. A short planning request covering scope, policies and system boundaries comes before fieldwork. The main request follows once the examination period is set, and for a Type 2 it cannot be fully answered until the period closes, since the auditor samples from a complete population.
Why does an auditor send evidence back?
Rarely because of security. The common reasons are a hand typed spreadsheet where a system export was asked for, a screenshot without a date or scope, a filtered list where the full population was needed, and an approval dated after the change it approved.
What if we cannot produce an item?
Tell the auditor early and in writing. Missing evidence becomes a test they could not perform, and that shows up in the report as an exception or a scope limitation. Raising it in week one leaves time to offer an alternative.
Can software answer the PBC list for us?
It can gather and index most items and pull system exports directly, which removes a lot of rework. It cannot answer on your behalf. Someone at your company still confirms each artifact, because the statement about your system is yours to make.

Sources

  1. AICPA Code of Professional Conduct AICPA. Independence, integrity, commissions and referral fees. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.