How to Prepare Your Devices for a SOC 2 Audit

Written by Josh Caliguire | Oct 8, 2026, 10:50:15 PM

To prepare your devices for SOC 2, every laptop and phone needs encryption, a screen lock, current patches, and endpoint protection, all enforced and all provable. The audit isn't about owning the right tools. It's about showing, with evidence, that those controls are on across your whole fleet.

Most teams can name the controls. Where they lose weeks is proof. An auditor doesn't take "our laptops are encrypted" on faith. They want a report, pulled from a real system, that says so for every device.

Here's what to lock down, and how to have the evidence waiting.

The device controls SOC 2 actually checks

These map straight to the Trust Services Criteria. Get them enforced and you've handled most of what an auditor asks about at the device level.

  • Full-disk encryption on everything. FileVault on Mac, BitLocker on Windows, with recovery keys escrowed centrally. A lost laptop becomes a dead end instead of a breach.
  • A real screen lock. Password or biometric, auto-locking after a few idle minutes. "It locks when I shut the lid" is not a control.
  • Enforced patching. OS updates on a deadline, not left to whoever remembers to click "update," plus patch management for critical third-party apps like browsers.
  • Endpoint security, monitored. Disk encryption, firewall, and antivirus or EDR turned on and reporting in, so you can see drift the day a device falls out of policy.
  • Clean onboarding and offboarding. New devices enroll with the right settings on day one. Ex-employees lose access and their device can be wiped.
  • A device inventory you trust. You can't secure hardware you forgot you had. Stale records and ghost devices are an audit finding waiting to happen.

Enforcement and evidence both come from MDM

Here's the shift that makes SOC 2 sustainable instead of a fire drill: a mobile device management (MDM) platform like Jamf or Intune.

An MDM pushes every control above automatically, so a new Mac or Windows machine arrives already encrypted, locked, patched, and enrolled. No one clicks through setup by hand.

More importantly, it generates the proof. Instead of screenshotting fourteen laptops one at a time, you export one report showing encryption on, screen lock on, OS current, across the entire fleet. That report is your audit evidence. CIS-aligned baselines and drift monitoring keep it true between audits.

If you want the full item-by-item version, see our companion post: SOC 2 Compliance Checklist: What Your Device Management Needs to Cover.

Handle personal devices on purpose

If people check email on their own phones, SOC 2 expects an answer. The clean approach is a lightweight MDM profile that enforces a passcode and encryption and can wipe company data without touching personal photos. Put the policy in writing and have people acknowledge it. The written record counts as much as the setting.

Have the evidence before the auditor asks

The difference between a smooth audit and a painful one is whether your proof already exists. Keep four things current: the device inventory, encryption and lock status across the fleet, patch and OS-update status, and a signed device policy. When an MDM produces these on its own, audit prep stops being a project. It becomes an export.

That's the whole game. Build the controls once, let the system enforce them, and let it hand you the evidence. Your fleet stays audit-ready instead of audit-anxious. If this sounds like the kind of setup you'd rather hand off, that's what we do: In-House IT Hire vs. Managed MDM: The Real Math walks through the tradeoff.

Not sure where your fleet actually stands?

Take the free MDM Health Check. Ten questions, about two minutes, no login. You'll get a high-level read on which device controls are audit-ready and which ones an auditor would flag first. If you answer "not sure" to a few, that's the finding.

Take the free MDM Health Check →

Want someone to walk the gaps with you? Book a free consult.