Guide
SOC 2 logging requirements, explained without the jargon
SOC 2 logging requirements come from the system operations criteria, CC7. They do not list exact log sources, so you decide what to log, but you must show that logs are collected, watched and acted on.
- Readiness, not the audit
- An independent CPA firm signs
- Written estimate, no call
Where SOC 2 logging requirements come from
CC7.2 asks you to monitor system components for anomalies. Therefore auditors look for central logs, alerts and evidence of response. The text is in the AICPA Trust Services Criteria.
What to log
Focus on events that show who did what to which system. So most companies cover the same sources.
- Authentication and failed logins
- Admin and privilege changes
- Production deploys and configuration changes
- Access to sensitive data stores
- Cloud provider audit trails
SOC 2 logging requirements check
Tick what you have in place.
Your result appears here as you tick, so you can see what is still open.
Retention and review
The criteria set no fixed period. However, your policy should state one, and you must meet it.
| Topic | Common practice |
|---|---|
| Retention | Often 90 days to one year, set in policy. |
| Alert review | Daily or on alert, with tickets. |
| Periodic review | Monthly or quarterly sign-off. |
Meeting SOC 2 logging requirements with evidence
Logs alone are not enough, because the auditor needs proof someone looked. So keep alert tickets, incident records and review sign-offs.
Part of readiness
We design logging and alerting with your engineers inside the fixed readiness fee. A licensed CPA firm then examines it, since we are not a CPA firm.
Start small and grow. For example, cloud audit logs plus authentication alerts already cover the highest-risk events for most software teams. Then add application and database logs as the team matures and the number of systems grows. However, keep every alert actionable, because alerts nobody reads create noise rather than evidence. A short monthly review note is often the simplest proof that monitoring really happens, so put it on a calendar with a named owner.
SOC 2 logging requirements questions
Do SOC 2 logging requirements need a SIEM?
No. A SIEM helps, but central logging with alerts can be enough for small teams.
How long must logs be kept?
As long as your policy says. Many companies choose 90 days to one year.
What evidence shows SOC 2 logging requirements are met?
Alert tickets, review sign-offs and incident records.
Do cloud audit logs count?
Yes, and they are usually among the most important sources.
Related guides
Meet SOC 2 logging requirements without overbuilding
Tell us your stack. We reply with a written scope and a fixed fee.
See if we can help