SOC 2 Type II audit preparation — evidence collection at engineering scale
Our team is preparing for SOC 2 Type II certification and the evidence-collection overhead is larger than expected. We're a ~40-person engineering org with 12 microservices, and auditors are requesting artifacts across access control, change management, and incident response. Peer question: how did your team operationalize evidence collection without creating a full-time compliance role? Specifically: - Automated evidence gathering from CI/CD pipelines (deployment approvals, PR reviews, rollback records) - Access review workflows that don't break developer velocity (quarterly reviews are painful when you have 80+ cloud accounts) - Incident documentation standards that satisfy SOC 2 without requiring engineers to write essays after every P3 Jurisdiction: US-CA, EU (we serve customers in both regions and are considering GDPR Art. 32 alignment with SOC 2 controls to reduce duplicate work). Confidentiality acknowledged — this is peer experience exchange, not a request for legal advice.