Cybersecurity · September 10, 2026 · intSignal Security Team

How to Actually Manage SOC 2, ISO 27001, and HIPAA Evidence

Share this article

The controls aren't the hard part — the evidence is

Ask anyone who has been through a SOC 2, ISO 27001, or HIPAA audit what actually consumed the weeks, and it's almost never "we didn't know what the controls were." The frameworks are public and well understood. What eats the time is evidence: proving, control by control, that each thing you say you do is actually done — and being able to produce the proof, correctly dated, when the auditor asks.

That's where most teams struggle, because they run the whole program in a shared spreadsheet and a folder of screenshots. It works right up until fieldwork, when an auditor asks for "the Q2 access review" and it's in someone's email, or the MFA screenshot is from a settings page that changed three months ago, or nobody can say who marked control CC6.1 as "done" or when.

Why the spreadsheet breaks

A tracking spreadsheet fails an audit in predictable ways:

  • Status without proof. Every row says "yes," but "yes" isn't evidence. An auditor tests the control; a green cell doesn't.
  • Evidence scattered from the control it supports. The proof lives in Drive, Slack, email, and ticket systems — not attached to the control it belongs to — so audit week becomes a scavenger hunt.
  • No dates, no history. Auditors care that a control operated over time. A screenshot with no date, or evidence that's silently a year old, doesn't demonstrate that.
  • One person's side project. When the whole program lives with one overloaded person, gaps don't get assigned and evidence doesn't get collected until the deadline panic.

What a real evidence program looks like

The teams that walk into an audit calm have four things in place:

  1. A structured program, not a list. Every control for the framework, grouped by domain, each with an honest status — not started, in progress, implemented, or N/A with a justification.
  2. Evidence attached to the control it proves. The access-review record lives on the access-review control; the encryption config lives on the encryption control. Nothing is hunted for.
  3. Readiness you can see. A live percentage complete and a prioritized gap list, so you always know how audit-ready you are and the one thing to do next — instead of discovering the truth in week two of fieldwork.
  4. Owners and due dates. Controls assigned to the people who actually do the work, with reminders, so evidence collection happens steadily instead of in a last-week scramble.

None of this is exotic. It's just structure applied to a problem most teams try to solve with a spreadsheet.

What counts as good evidence

Auditors want to see a control both designed and operating. In practice, favor evidence that is dated and system-generated over anything hand-made:

  • Policies — the written document (access control, incident response).
  • Configurations — a screenshot or export showing the setting is enforced.
  • Records of operation — the completed access review, the resolved incident, the onboarding checklist — proof the process actually ran, with a date.
  • Tickets and logs — hard to fake, easy to date, the least work to refresh next year.

Our evidence checklist breaks this down by domain, and there's a printable PDF you can hand to owners.

Run it for free

You don't need to buy a five-figure GRC platform to do this well. intSignal's Compliance Workspace is a free, self-service place to run a full SOC 2, ISO 27001, or HIPAA program: a fillable control program, live readiness scoring and gaps, an encrypted evidence vault (your evidence is isolated and encrypted — even our admins can't see it), task owners and reminders, and a one-click auditor-ready export. Create an account, pick a framework, and start closing controls in minutes — see the getting-started guide.

And if you'd rather not run it yourself, our team can operate the whole program for you as a virtual CISO / managed engagement — mapping controls, gathering evidence, and getting you audit-ready. Talk to sales to scope it, or read about the two ways to get compliant.

The audit is a deadline you can see coming. The teams that hit it calmly are the ones that treated evidence as a program from day one — not a spreadsheet they'd reconcile the week before.

Share this article