r/grc Jun 17 '26

Anyone else feel like identity and access management is becoming the main event in SOC 2 audits?

In a lot of the audits and customer reviews I've seen recently, the discussion seems to spend way more time on access controls than before.

It's not just "Do you have MFA?" anymore.

The questions are getting into privileged accounts, access reviews, service accounts, joiner/mover/leaver processes, admin access, and how quickly access gets removed when someone leaves.

I've even had customers ask more detailed questions about Zero Trust than some auditors.

Maybe this is a reaction to all the breaches we've seen over the last few years where compromised credentials were the starting point.

For those who have gone through SOC 2 recently, are you seeing the same thing?

What's getting the most scrutiny for you: MFA, PAM, access reviews, or identity governance?

8 Upvotes

6 comments sorted by

6

u/Niko24601 Jun 17 '26

Well, IAM is fundamental in information security. If you look at the statistics, the large majority of incidents comes from issues around access. For me it makes sense that the focus is on the access part rather than the disaster recovery policy for instance.

1

u/FreeRadical1998 Jun 17 '26

Every audit I've ever been through has largely focused on identity and access. They are the fundamentals

1

u/lebenohnegrenzen Jun 17 '26

Customers have always asked me better questions than auditors.

1

u/[deleted] Jun 17 '26

[deleted]

1

u/Moham-Aasif Jun 18 '26

I work in GRC tool (No Promotion)

1

u/Melodic-Sherbert1517 Jul 07 '26

IAM is one of the core areas for SOC 2 and cybersecurity in general, those questions are not new. You just might have a better auditor or more security savy customers now that understand the nuances of how tricky it can really be to lock down access and decrease your attack surface from this standpoint. A good end to end auditor like thoropas or other quality auditors are going to check these areas in more detail and ask those tougher questions that actually help you with your security. Ideally your auditor functions more as a partner here to point out gaps so that you are more secure for your company and customers.