Home/Blog/How to Cut SOC 2 Access Findings to Zero Before Your Next Audit
Playbooks

How to Cut SOC 2 Access Findings to Zero Before Your Next Audit

Every CISO with an upcoming SOC 2 audit knows the feeling: the last audit had three access findings, remediation dragged for months, and this year's audit is 60 days out. Fieldwork is the wrong time to discover a problem. Here is how to compress the discovery and remediation into a 60-day sprint that lands you at zero access findings on day one of fieldwork.

The plan is aggressive but not heroic. It requires focus, a working access review tool, and the CISO or GRC lead's attention for the full 60 days.

What do "access findings" actually cover in SOC 2?

Three CC6 categories account for most access-related findings.

  • CC6.1 (logical access controls). Findings here mean unauthorized access exists, roles are ill-defined, or privileged access lacks additional controls. Most common finding: "sampled users retained privileged access after role change."
  • CC6.2 (prior authorization). Findings here mean access was granted without documented approval. Common finding: "provisioning for X users could not be traced to an authorized approval."
  • CC6.3 (removal of access). Findings here mean deprovisioning was delayed or incomplete. Most common finding: "sampled terminated users retained active access more than 30 days post-termination."

Zero findings on all three is the target. This plan addresses each explicitly.

What happens in days 1 to 10 (scope and inventory)?

Ten business days to establish the baseline. No reviews yet, just facts.

  • Day 1-2. Confirm audit scope in writing with the auditor: which systems, which entities, which reporting period. Any ambiguity gets resolved now, not during fieldwork.
  • Day 3-5. Pull the current entitlement population from every in-scope system. Every user, every entitlement, every last-used timestamp. Snapshot and freeze.
  • Day 6-8. Cross-reference the population against HRIS. Every active entitlement should belong to an active employee or a documented service account. Flag anomalies.
  • Day 9-10. Categorize entitlements: privileged, standard, service, contractor, dormant. Category counts become the scoping input for the sprint.

Deliverable: a frozen population inventory with categorization. This is the starting point for everything that follows.

What happens in days 11 to 30 (real access review)?

Twenty days for a full campaign with executed revocations.

  • Day 11-12. Launch the campaign with the frozen population. Route to direct managers. Plain-language descriptions on every entitlement, last-used timestamp visible.
  • Day 13-20. Reviewer decisions land. Day 15 nudge, day 18 manager escalation.
  • Day 20. Decision cutoff. Any unresolved items route to fallback reviewers (usually the reviewer's manager).
  • Day 21-28. Revocation execution. Every "revoke" decision executed through source-system API within 5 business days. Verify state in the source system, not in the ticket queue.
  • Day 29-30. Campaign evidence bundle exported. Executed-state confirmed for every revocation.

Deliverable: one closed campaign with full evidence bundle. This is your SOC 2 CC6.1 and CC6.3 evidence for the audit period.

What happens in days 31 to 45 (deprovisioning sweep)?

Fifteen days for a targeted sweep on the highest-risk classes.

  • Terminated user sweep. Every user terminated in the audit period. Confirm access removed within SLA in every source system. Any access still live is remediated immediately; any breach of the SLA is documented with root cause.
  • Dormant privileged sweep. Every privileged entitlement not used in 90 days. Follow the safe revocation sequence: notify, sandbox first, prod during low-traffic, 24-hour rollback window. Target: dormant privileged rate under 3% by day 45.
  • Orphaned account sweep. Every active account with no assigned owner or manager. Reassign or terminate. Target: zero orphans.
  • Service account sweep. Every service account with a departed user as owner. Reassign to a team-shared identity or a named replacement.

Deliverable: four sweep completion reports. This is your CC6.3 depth evidence.

What happens in days 46 to 60 (evidence rebuild and dry run)?

Fifteen days for evidence assembly and a self-audit.

  • Day 46-50. Assemble the audit evidence package. Six artifacts per campaign, plus the four sweep reports, plus the control mapping index. Everything tagged to SOC 2 CC6.1, CC6.2, CC6.3.
  • Day 51-55. Pre-audit dry run. Sample 15 to 25 users from your own population and test them against every control as if you were the auditor. Every failure is a finding you catch, not one the auditor catches.
  • Day 56-58. Remediate anything the dry run surfaced. Document remediations even for issues you fully closed.
  • Day 59-60. Package handoff. Evidence is in the format the auditor requested, indexed to their control language, ready for fieldwork.

Deliverable: audit-ready evidence package. The auditor's first question is answered before they ask it.

What are the highest-leverage moves inside the sprint?

Three moves matter more than the others.

  • Verify revocation state in the source system, not the ticket. The single most common finding is "revoked in log, active in system." Every revocation gets verified. No exceptions.
  • Run the dry run with the auditor's sampling method. Do not test what you want to test. Test what the auditor will sample. Terminated users, revoked entitlements, privileged access grants.
  • Document remediation-in-progress. Anything you cannot close inside 60 days gets a documented remediation plan with owner, target date, and compensating control. Auditors accept plans; they reject unmentioned gaps.

Skip any of these three and the sprint produces a smaller reduction in findings.

What does the sprint look like as a calendar?

Consolidated view.

Phase Days Deliverable
Scope and inventory 1 to 10 Frozen population inventory
Real access review 11 to 30 Closed campaign, evidence bundle
Deprovisioning sweep 31 to 45 Four sweep completion reports
Evidence rebuild and dry run 46 to 60 Audit-ready package

Ten weeks compressed into 60 business days. Every phase depends on the previous phase, so there is no parallelizing without losing quality.

How do you know the sprint worked?

Five checks. All measurable on day 60.

  • Access review completion rate: 100%.
  • Revocation execution rate: 95%+ within 5 business days.
  • Dormant privileged rate: under 3%.
  • Terminated user residual access: zero.
  • Dry run findings: at most 1 to 2, all remediated before handoff.

Hit those five and expect zero access-related findings in fieldwork. Miss any of them and the finding rate scales with the miss.

The mistake to avoid

The instinct with 60 days to audit is to focus on evidence assembly and skip the operational fixes. This is backwards. Evidence assembly on a broken program produces documented failure; operational fixes on a well-run program produce clean evidence almost automatically. Spend the first 45 days fixing the operations (review, revocations, sweeps) and the last 15 assembling. If you invert the order, you will produce a beautiful evidence bundle that documents every finding the auditor will otherwise miss.

soc 2audit prepaccess controlscc6grc

Frequently asked questions

Is 60 days really enough?

For a mid-market company with existing tooling and no material control gaps, yes. If you have never run a real access review, 60 days is too tight; plan on 90 to 120 days to include the first campaign as a rehearsal. The compressed timeline works when the bones of the program exist and just need to be tightened.

What if we find major gaps during the sprint?

Document them, remediate what you can inside the window, and open compensating controls for the rest. Auditors accept documented remediation-in-progress with compensating controls; they do not accept undocumented gaps discovered during fieldwork. Discovery-before-fieldwork is always better than discovery-during-fieldwork.

Do we need to hire external help?

Optional. A vCISO or specialist firm can accelerate the sprint by 20 to 40%, mostly on evidence assembly and control mapping. Internal teams can run it if the CISO or GRC lead can commit half their time for 60 days. The bottleneck is usually reviewer response time, which external help cannot fix.

What if fieldwork starts before day 60?

Compress ruthlessly. Drop the deprovisioning sweep from days 31-45 to days 15-25 (in parallel with the review). Skip the pre-audit dry run and use the audit itself as the dry run. Accept that findings will show up mid-fieldwork rather than pre-fieldwork; remediate in real-time with the auditor watching. Not ideal but survivable.

How do we prevent findings from recurring next year?

Convert the 60-day sprint into a steady-state program. The four phases become continuous: entitlement inventory always live, reviews quarterly, deprovisioning sweep monthly, evidence bundle exported per campaign. The sprint is a one-time rebuild; the program is the sustaining pattern.

Close access reviews in days, not quarters

Orvaron pulls entitlements from every system, routes reviews to the right manager, and executes revocations in the source app so evidence builds itself.

Request early access