Why does SOC 2 Type II require continuous evidence?
More context
The reason point-in-time evidence is insufficient is that a control can pass on the day it is checked and silently fail for weeks in between. A quarterly scan says nothing about the eighty-nine days it did not run. Auditors sampling operating effectiveness are trying to gain assurance that a control held throughout the period, so a sparse set of snapshots invites exactly the sampling gaps they are meant to close.
This is why teams move from campaign-style evidence collection to always-on scanning. Instead of a scramble before the audit window to gather screenshots, a continuous scanner records configuration state on a schedule and retains it, so the evidence for any given control across the review period already exists. The audit becomes a matter of exporting the record rather than reconstructing history under time pressure.