Skip to content
OnTrackio

Free template

SOC 2 asset inventory template

The inventory your auditor asks for behind CC6.1, as a ready-to-use XLSX: separate hardware, software and SaaS, and cloud sheets, an ownership and classification spine on every row, and a review log built for the Type II observation window. Direct download, no email gate.

Want to know when this template changes? Regulations and criteria move. Email sales@ontrackio.com and we will send the new version. Nothing else, no newsletter.

What is inside

Five sheets. The How to use sheet maps the file to CC6.1's points of focus and explains the Type I vs Type II difference; the other four are the working record:

  • Hardware. Laptops, servers, network gear: 13 columns including owner, classification, whether the device holds customer data, and a last-verified date.
  • Software and SaaS. Installed software and subscriptions: vendor, seat count, whether SSO is enforced, renewal date, and the same ownership + classification spine.
  • Cloud resources. Production and supporting infrastructure: provider, service, environment, region, and the customer-data flag that drives audit scope.
  • Review log. Dated verification passes with reviewer names. A Type II audit samples across months, so the reviews themselves are evidence.

The two columns auditors go to first

Owner. A named person, not a team. Every asset conversation in an audit starts with who is accountable, and a register without owners cannot be kept accurate, because nobody is on the hook when a row goes stale.

Holds customer data. This flag drives audit scope. Assets marked yes get sampled harder: encryption, access, disposal. Be honest in both directions, because overclaiming scope creates work and underclaiming creates findings.

The full evidence request behind the inventory, including the reconciliation and offboarding proof that usually accompany it, is unpacked in the asset inventory evidence guide and the Type II observation window guide. The wider ITAM-to-SOC 2 mapping lives on the SOC 2 evidence page.

Frequently asked questions

Does SOC 2 actually require an asset inventory?

Not by name. The Trust Services Criteria describe outcomes, and CC6.1's points of focus expect you to identify, inventory, classify, and manage information assets. In practice an inventory export with ownership and classification is a standing item on every auditor's evidence request list.

Why three separate inventory sheets?

Because auditors sample by asset class. Hardware questions are about custody and disk encryption; SaaS questions are about seats, SSO, and offboarding; cloud questions are about environment and customer data. One flat list makes every one of those conversations slower.

What is the Review log sheet for?

Type II audits cover an observation window of 3 to 12 months, and the auditor will ask when rows were last verified and by whom. A dated review log turns that from an awkward silence into a printout. If you only maintain the inventory the week before fieldwork, the timestamps will say so.

Is the template free, and what is the catch?

Free, direct download, no email gate. The catch is the same one every spreadsheet has: it records what someone typed, not what is true. We build a platform that keeps the same register agent-fed and reconciled daily; the template is the starting point either way.

Does filling this in make us SOC 2 compliant?

No. A SOC 2 report is an auditor's opinion on your whole control environment. This file contributes asset evidence to the CC6 family; policies, the rest of your controls, and the audit itself remain yours.

Evidence that maintains itself

OnTrackio keeps the same inventory agent-fed and reconciled daily, with timestamps a Type II sample can lean on. Public pricing, 30-minute demo.