TLS Certificate Evidence Auditors Actually Want
It's the third quarter. Your SOC 2 audit is in eight to twelve weeks. The auditor is going to ask for cert inventory, lifecycle records, alerting proof, and exception tracking. Most teams build this evidence from scratch every year, and most of them are doing it the week before the auditor arrives.
This is avoidable. The pattern that works isn't "build the audit package in October." It's continuous evidence collection that turns the audit conversation into showing a dashboard, not assembling a binder.
What auditors actually ask for
Different frameworks, similar questions. The common ones:
SOC 2 CC6 (Logical and Physical Access). Are TLS certificates used to authenticate access to systems? Who has access to issue/revoke certificates? Are issuance and revocation logged?
SOC 2 CC7 (System Operations). Are certificates monitored for expiration? Are there alerts before expiry? Are exceptions tracked? Is there a documented process for renewal?
SOC 2 CC9 (Change Management). When a certificate is rotated, is the change logged? Is the new certificate validated? Is there evidence of testing before production deployment?
PCI DSS 2.3 and 4.1. Strong cryptography for transmission of cardholder data. Inventory of all certificates used for in-scope systems. Documented configuration baselines and exception tracking.
ISO 27001 A.10 (Cryptography). Policy on use of cryptographic controls. Key management lifecycle. Inventory of keys and certificates.
HIPAA Security Rule § 164.312 (Transmission Security). Encryption of ePHI in transit. Evidence that the encryption is current and configured correctly.
The specific control numbers differ by framework. The underlying questions converge on the same set: do you know what certificates you have, are they monitored, are exceptions tracked, do alerts actually fire?
The "we have a spreadsheet" problem
Most teams answer the inventory question with a spreadsheet. The auditor sees a list of certificates, with expiry dates and owners, last updated three weeks ago.
This works for the audit. It doesn't work for continuous evidence, and good auditors increasingly know to ask the follow-up question: "is this current?" A point-in-time snapshot of cert inventory is a check-the-box answer that doesn't actually demonstrate ongoing control. The control framework wants ongoing control, not annual snapshots.
A spreadsheet also doesn't generate the audit-tail evidence that the framework actually asks for. "Show me the alert that fired three months ago when this cert was 14 days from expiry, and the renewal that completed five days later" - that's an evidence request your spreadsheet can't answer.
What continuous evidence looks like
Three components, kept current by the monitoring system rather than by a periodic exercise:
Inventory. Every certificate, with the system it serves, the team that owns it, the CA that issued it, the dates that bound its validity. Updated continuously as new certs are issued and old ones are decommissioned.
Lifecycle log. For each cert, a history: when it was issued, when each alert fired, when each renewal happened, when each rotation completed. The thing the auditor wants to see to demonstrate "monitoring works as designed."
Exception tracking. When a cert was supposed to be renewed and wasn't, why? When an alert fired and wasn't acted on within SLA, why? When a deviation from your TLS standard was detected, was it accepted, remediated, or exempted? Auditors care about exceptions. So should you.
Together, these three give you what auditors want without requiring an annual exercise to assemble them.
Audit prep that takes hours, not weeks
The teams that do this well treat the audit as a side effect of normal operations, not a special event. The dashboard the on-call team uses to manage certs is the same dashboard the auditor sees. The evidence the auditor wants is generated continuously by the monitoring, exported on demand, and never reconstructed retroactively.
The cost is upfront: setting up the inventory, the alerting, the exception workflow. The payoff is every audit thereafter: the prep is hours of exporting evidence, not weeks of reconstructing it.
This matters especially for enterprises with multiple compliance frameworks (SOC 2 + PCI + ISO + customer-specific contracts). Each framework wants the same underlying evidence in slightly different shapes. Continuous evidence collection lets you serve all of them from one source.
Make the next audit hours, not weeks
TLS Radar produces audit-grade evidence continuously: certificate inventory, lifecycle logs, alert history, and exception tracking, exportable in the formats your SOC 2, PCI, and ISO auditors actually accept. Built for enterprise teams with API integration into your existing GRC tooling, SAML/SSO, and pricing tailored to your certificate volume. Tell us about your audit cadence.
Related reading
Get the next post in your inbox
TLS monitoring tips and product updates. No spam, unsubscribe anytime.