All Resources
Guide 2026-03-29

What Causes SOC 2 Exceptions

A detailed breakdown of the operational and technical controls that most commonly cause SOC 2 audit exceptions, with practical advice on how to avoid them.

Download this resource

Download What Causes SOC 2 Exceptions (DOCX)

Download

This document covers the specific controls that most frequently cause SOC 2 audit exceptions. It's organized into three sections:

  • GRC software setup — integrations, SLAs, and scoping
  • Operational controls — onboarding/offboarding SLAs, access reviews, device compliance, and documentation requirements
  • Technical controls — MFA, PR approvals, vulnerability SLAs, infrastructure monitoring, and password policies

It also includes an appendix with guidance on observation window timing, vendor security reviews, auditor and pen test selection, employee agreements, and risk assessments.

Want help implementing this?

Get introed to the founders of our transition partner and Vanta's #1 compliance implementation partner.

Get Introed