All Resources
Download
Guide 2026-03-29
What Causes SOC 2 Exceptions
A detailed breakdown of the operational and technical controls that most commonly cause SOC 2 audit exceptions, with practical advice on how to avoid them.
Download this resource
Download What Causes SOC 2 Exceptions (DOCX)
This document covers the specific controls that most frequently cause SOC 2 audit exceptions. It's organized into three sections:
- GRC software setup — integrations, SLAs, and scoping
- Operational controls — onboarding/offboarding SLAs, access reviews, device compliance, and documentation requirements
- Technical controls — MFA, PR approvals, vulnerability SLAs, infrastructure monitoring, and password policies
It also includes an appendix with guidance on observation window timing, vendor security reviews, auditor and pen test selection, employee agreements, and risk assessments.
Want help implementing this?
Get introed to the founders of our transition partner and Vanta's #1 compliance implementation partner.
Get Introed