What should I expect during the SOC 2 Type 2 observation period?
Last updated: June 23, 2026
Context
Once all controls are passing and your preparation phase is complete, your observation period begins. Our clients often want to understand what happens during this phase, what actions are required from their side, and what the overall timeline looks like through to the final report.
Answer
The observation period is a minimum 3-month window during which your security controls must be actively followed and documented. Here is what to expect:
1. Monitoring
Oneleet will continuously monitor your automated checks to confirm ongoing compliance. If a monitor fails, you will have 7 days to resolve it before it becomes an exception in your final SOC 2 report. Make sure SLA alerts are enabled in your settings so you are notified when a monitor moves to an alerting or breaching state.
It is normal for alerts to occasionally trigger during the observation period — what matters is that you address them within the SLA window.
2. Supplementary Evidence Requests
During the observation period, Oneleet will request additional evidence to confirm your controls were operating effectively throughout the window. There are two types of evidence requests:
Active requests (open at the start): These mostly involve uploading updated screenshots to show that settings remain in place. Aim to complete these within the first month of the observation period, though the deadline has some flexibility.
Upcoming requests (activated later in the period): These ask for a full log of events that occurred during the observation window (e.g., all new hires, access requests). Oneleet will not send an automatic alert for these, so it is recommended to set a calendar reminder. Some back-and-forth is normal — Oneleet may follow up to ask how specific events were handled (e.g., approvals, tickets, documentation).
Example: If you had 100 access requests, you would upload the full list. Oneleet may then ask for examples of how individual requests were processed.
Note: If no events occurred (e.g., no new hires), that is fine — simply add a note to the request or show that the control was in place and ready.
Controls with open evidence requests will appear as "In Progress" on the Oneleet platform. This is expected and does not indicate a compliance issue — it simply means evidence is pending review.
3. Auditor Onboarding
Your assigned auditor is onboarded near the start of the observation period, though they conduct most of their review toward the end. You will also need to review and complete the Auditor Intake Form and Section III, which is the core client-facing description of your system included in the SOC 2 report. It is best to review and update this document as early as possible, as the auditor will reference it throughout the process.
Additionally, your auditor will send over a letter of engagement (and potentially an MNDA) that will need to be signed before the audit can formally begin.
4. Creating New Policies During the Observation Period
Creating new policy documents during the observation period is acceptable and will not impact the audit end date, as long as you continue to follow the guidelines outlined in the policy and ensure all relevant team members acknowledge it in a timely manner.
5. Post-Observation: Audit Timeline
Once the observation period closes, the audit proceeds in the following approximate stages:
Testing (~2 weeks): The auditor reviews your submitted evidence. No action is required from your side during this phase.
Requests for Evidence / RFEs (~1 week): Based on their review, the auditor may request clarifications or additional evidence. Oneleet manages this process and will reach out if anything is needed from you. A bit of back-and-forth is normal here, and a faster turnaround helps keep the timeline on track.
QA and Draft Report (~1 week): Once all RFEs are resolved, the auditor performs a final QA review and issues a draft report for your review and approval.
Final Report: After you approve the draft, the auditor finalizes and signs the report.
Depending on your auditor selection, you will have the final report in hand 2-10 weeks after the close of the observation period. The delivery time is very within your control.
Key Reminders
Continue following all established controls, policies, and procedures throughout the observation period.
Notify Oneleet of any security incidents so they can help ensure your incident response process is properly documented.
Full payment is required before the audit begins.
Include timestamps and sufficient context in all screenshots to confirm they came from your system.
The faster evidence is uploaded, the sooner the auditor can be onboarded, which lowers the risk of exceptions in the final report.