Your Auditor Doesn’t Care How Good Your Firewall Sounds. They Want Proof.
A software company in Austin gets an email from a prospective enterprise client: “Can you send us your SOC 2 report before we sign?” The founder has never heard the term applied to their business before. Suddenly a six-month sales cycle depends on a compliance framework nobody on the team fully understands, and the clock is running.
This scenario plays out constantly for small businesses that sell to larger companies, handle sensitive data, or operate in regulated industries. SOC 2 has become a de facto entry ticket for B2B deals, and network access controls sit at the center of what auditors want to see. That’s where Zero Trust Network Access, or ZTNA, comes in as a practical way to satisfy what an auditor is actually looking for.
What SOC 2 Actually Asks For

SOC 2 is an audit standard developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how a company handles customer data across five categories called Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is mandatory for every SOC 2 report; the other four are optional depending on what a business does.
An auditor doesn’t test your marketing claims. They test whether you have documented controls, whether those controls are actually followed, and whether you can produce evidence of that over a period of time (for a Type II report, usually several months to a year). This is the part that catches small businesses off guard: it’s not enough to have a firewall. You need to show who has access to what, why, and how that access is reviewed and revoked.
The Access Control Problem
Most small businesses grew their network access the way most things grow in a small business: informally. Someone got VPN credentials three years ago for a project that ended. A former contractor still has a login. Everyone on the sales team can reach the finance server because nobody ever separated the network segments.
None of this is malicious. It’s just what happens when a company is focused on shipping product and closing deals instead of documenting access policies. But it’s exactly the kind of thing a SOC 2 auditor flags, because unrestricted or undocumented access runs against what the security criteria expects around logical access controls.
Why ZTNA Maps Well to SOC 2 Criteria
Zero Trust Network Access works on a simple premise: nobody and nothing gets broad network access by default. Instead of connecting a user to an entire network the way a traditional VPN does, ZTNA connects a verified user to a specific application or resource, checks their identity and device status, and re-evaluates that trust on an ongoing basis rather than granting it once and forgetting about it.
This lines up with several specific things SOC 2 auditors ask about.
Least Privilege Access
The security criteria expects organizations to restrict access based on job function rather than granting broad network access to everyone. ZTNA enforces this at the architecture level. Instead of relying on a policy document that says “employees should only access what they need,” ZTNA platforms let administrators define access rules per application, per user group, and per device posture, so the enforcement isn’t just written down, it’s built in.
Continuous Monitoring and Logging
Auditors want evidence, not assurances. ZTNA platforms typically generate logs of who connected to what resource, when, from what device, and whether that connection was approved or denied. That log trail becomes direct audit evidence rather than something a compliance team has to reconstruct manually before an assessment.
Access Revocation
Offboarding is a natural stress point for access control. When an employee or contractor leaves, did their access actually get revoked, and how quickly? With ZTNA, access is tied to identity through a central policy engine, so revoking a user in one place cuts off access across every connected application, instead of requiring someone to remember every system that person could reach.
Device Posture Checks
Some SOC 2 controls extend to endpoint security, not just network access. Modern ZTNA tools can check whether a device has updated software, an active firewall, or disk encryption before granting access, which supports the confidentiality and security criteria at the same time.
Where This Gets Harder in Practice
None of this means installing a ZTNA product and calling the audit finished. Auditors evaluate whether controls are operating effectively over the audit period, which means policies have to be applied consistently, not configured once and left alone. A ZTNA platform that isn’t actually integrated into your identity provider, or where access rules haven’t been reviewed since setup, doesn’t give an auditor much confidence.
Scope matters too. ZTNA addresses network and application access controls. It doesn’t cover every SOC 2 requirement; things like vendor risk management, incident response planning, and physical security still need separate attention. Treating ZTNA as a single fix for a SOC 2 audit is a common misstep for small businesses trying to move fast.
Picking a ZTNA Platform With Compliance in Mind
For small businesses without a dedicated security team, ease of policy management and reporting matters as much as the underlying architecture. A platform that requires deep networking expertise to configure correctly can end up with the same gaps as the informal access setup it replaced.
NordLayer is one option built with smaller IT teams in mind. According to NordLayer’s own product documentation, the platform offers centralized access policies, activity logging, and integrations with common identity providers, the pieces most directly relevant to SOC 2 evidence gathering. If you sign up through some of the links in this article, EdgeTrustNetwork may earn a commission at no extra cost to you. Whatever platform a business chooses, the evaluation should center on whether it produces the access records and policy enforcement an auditor will actually ask to see, rather than on feature lists alone.
Building the Evidence Trail Before the Audit Starts
Access management is one of the control areas SOC 2 auditors test directly, alongside logging, change management, and incident response. The practical habits that make evidence gathering easier aren’t complicated: turn on logging before you need it, write down access policies instead of only configuring them in a dashboard, and review who has access to what on a set schedule instead of waiting until something forces the question.
Offboarding falls squarely into that category. Timely revocation of access is one of the specific things auditors check, which is a good reason to treat shutting off a departing employee’s access as a routine task rather than something that gets remembered after the fact.
It also means having a plan for exceptions. Auditors expect that not everything will be perfect, and a documented process for handling access requests, approvals, and temporary elevated permissions often matters more than a spotless record. Showing that you catch and correct issues is frequently more convincing than claiming you never have any.
The Deal That Started This
That Austin software founder eventually got the SOC 2 report done. The process took longer and cost more than it needed to, mostly because access controls had to be rebuilt from scratch under deadline pressure: users who should have been offboarded years ago, permissions nobody could explain, a network segmented by habit rather than policy.
None of that had to happen at the last minute. ZTNA can’t hand you a clean audit by itself, and no vendor’s dashboard substitutes for documented, consistently applied policy. But the logs, the least-privilege enforcement, and the centralized revocation it produces are the same evidence an auditor is going to ask for anyway. Building that trail before a prospective client’s email shows up beats scrambling to rebuild it after.