Guide
Compliance evidence freshness and expiry
Evidence has a shelf life. A control that ran perfectly in March proves nothing about September, and in a Type II audit the whole period is under test. This guide sets out working freshness cadences and how to operationalize them.
Why freshness decides Type II outcomes
A Type II report covers an observation period, commonly three to twelve months. Auditors test whether controls operated throughout it. The failure mode is rarely "control never existed"; it is "evidence exists for months one through three, then stops." A gap in collection reads as a gap in operation, even when the control was actually running.
Working cadences by artifact type
These are common conventions, not standards. Your auditor's expectations override this table; confirm during planning.
| Artifact | Typical cadence | Expires when |
|---|---|---|
| Access reviews (user, privileged) | Quarterly | The next quarter starts without a completed, signed review |
| Vulnerability scan results | Monthly | A month passes with no scan, or findings age past remediation SLAs |
| Configuration snapshots (branch protection, security groups, MFA) | Weekly to monthly | The underlying system changes without a new capture |
| Policies and standards | Annual review | The review date passes, or the practice changes without an update |
| Security training records | Annual, plus onboarding | An employee passes their anniversary without refresher |
| Incident postmortems and tickets | Per event | Never expire, but must be complete for every event in the period |
| Vendor reviews | Annual | The vendor's own attestation (their SOC 2) lapses |
Operationalizing freshness
- Attach a cadence to every control. If a control has no stated frequency, the auditor will pick one for you, and you may not like it.
- Track evidence age, not just existence. "We have an access review" is not the same as "our newest access review is 23 days old against a 90-day cadence."
- Alert before expiry, not after. A stale-evidence alert two weeks before the cadence lapses is a task. The same alert after is a finding.
- Automate re-collection where possible. Configuration and scan artifacts can re-collect themselves from APIs on a schedule. Reserve human reminders for judgment artifacts: reviews, approvals, postmortems.
- Keep the failures. A lapsed artifact that was caught and re-collected, with the gap documented, is defensible. A silently overwritten history is not.
The freshness view you want
For every control: last collected, cadence, days until stale, owner. That four-column view, kept current, is the difference between an audit you prepare for and an audit you already passed operationally. It is also the core of what continuous compliance monitoring software should give you.
Frequently asked questions
Is there an official SOC 2 evidence expiry rule?
No. The Trust Services Criteria do not set artifact shelf lives. Cadence comes from your control descriptions and your auditor's expectations. That ambiguity is exactly why you should state frequencies in your controls and then meet them.
What happens if evidence goes stale mid-period?
Best case, the auditor marks a deviation and you explain the gap with remediation notes. Worst case, the control is marked ineffective for part of the period. Gaps you caught and documented are far easier to defend than gaps the auditor found.
How does this differ for FedRAMP?
FedRAMP fixes the cadences by requirement: monthly vulnerability scanning and POA&M submission, defined remediation windows, annual assessment. There is no negotiating the calendar. See our FedRAMP ConMon requirements guide.
Sources
- AICPA, SOC 2 overview: aicpa-cima.com
- FedRAMP Continuous Monitoring Playbook: fedramp.gov
- Cadence conventions reflect common audit practice; confirm your own with your auditor.