Audit Trail: Compliance Evidence Report
Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.
Prerequisites
Read First
See references/control-mapping.md for the full control → query mapping table and retention requirements by framework.
Retention Check (Run First)
PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:
If the requested time window exceeds 90 days and no archive is confirmed, surface this gap in the report header.
Workflow
- Confirm: framework (SOC 2 / PCI DSS), time window, org scope
- Run retention check
- Run each relevant control query
- Format output using the Evidence Report template
SOC 2 Queries
CC6.2 — User Provisioning / Deprovisioning
CC6.3 — Role and Permission Changes
CC6.6 — Failed Logins and Suspicious Access
CC7.2 — Privileged / Support User Actions
PCI DSS Queries
PCI 10.2.2 — Actions by Privileged Users
Same as CC7.2 above. Also include org-level admin actions:
PCI 10.2.3 — Access to Audit Trail Itself
PCI 10.2.4 — Invalid Access Attempts
Same as CC6.6 failed logins above.
PCI 10.2.5 — All Authentication Events
PCI 10.2.7 — Object Creation and Deletion
Evidence Report Template
Scope Caveat
Datadog Audit Trail covers the Datadog platform as the system being audited. For PCI purposes, this is evidence that the monitoring platform's access controls are functioning — not direct evidence about the cardholder data environment (CDE) itself. Auditors should understand this scope boundary.


