Skip to content
SecuriFii

Choosing

SOC 2 Type 1 or Type 2: which one to get, and what each can evidence

The decision is usually framed as fast-and-cheap against slow-and-thorough, which is the wrong axis. A Type 1 and a Type 2 answer different questions, and only one of them is what a customer means when they ask for your SOC 2. Getting this right is mostly a matter of knowing what each report can actually be used to prove.

Facts checked2026-09-11

What each report answers

Type 1Type 2
AnswersWere the controls suitably designed and implemented, as at a stated date?Were they also operating effectively across a stated period?
CoversA single date.A period. AICPA guidance suggests at least six months; no length is mandated.
EffectivenessNo — it cannot evidence that a control has ever actually run.Yes, within the period and the auditor’s sampling.
Typical runSix to twelve weeks.The observation period, then fieldwork and reporting on top.
Buyer intentRarely what “send us your SOC 2” meant.Almost always what they meant.

A SOC 2 is an attestation examination performed under AICPA standards — AT-C section 105, and AT-C section 205 as superseded by SSAE No. 21 for reports dated on or after 15 June 2022 — against the Trust Services Criteria. Only a licensed CPA firm can perform one, and there is no such thing as a SOC 2 certificate.

What each report can actually evidence

A Type 1 reports on whether your controls were suitably designed and implemented as at a single date. The auditor asks whether a control exists, whether its design would meet the criterion if it ran, and whether it had been put in place by that date. It is a real report, signed by a licensed CPA firm, and it is genuinely useful — within that limit.

The limit is the whole of the difference: a Type 1 cannot evidence that a control has ever operated. Not once. A control designed the week before the stated date and never exercised since satisfies a Type 1 exactly as well as one that has run daily for two years.

A Type 2 covers both design and operating effectiveness, across a period. The auditor samples — pulls the records a control produced on particular dates, tests them, and reports exceptions. That is why buyers ask for it: it is the only one of the two that is evidence about behaviour rather than intent.

Neither is a certification. A SOC 2 is an attestation examination under AICPA standards, and what you receive is a report with an opinion in it. If a vendor offers to certify you, or a prospect asks to see your SOC 2 certificate, the terminology is wrong in a way worth gently correcting.

The decision: is something blocked right now?

That is the question, and it is very nearly the only one. Do the Type 1 first when a specific deal, renewal or procurement gate is waiting on it today and the observation period a Type 2 needs has not started. Weeks instead of quarters, and it unblocks the thing.

Go straight to Type 2 when nothing is waiting. You avoid paying for two examinations, and you arrive at the report buyers actually ask for without an intermediate stop that a customer may not accept.

The failure mode is treating a Type 1 as the destination. A customer who asked for your SOC 2 and receives a Type 1 will usually come back — sometimes immediately, sometimes at renewal when their own auditor reviews the vendor file and notices the report evidences design only. Budget for the Type 2 at the point you commission the Type 1, not after the follow-up question arrives.

How long does the Type 2 period have to be?

This is where most guidance is confidently wrong, and it is worth getting right because it changes your plan by months.

There is no minimum period mandated by the attestation standards. The commonly repeated “minimum three months” is market convention, not a requirement — and AICPA guidance has suggested a period of at least six months, which points the other way from the figure most vendors quote. Your auditor exercises judgement about what period supports the opinion they are being asked to give.

So the real constraint is not compliance, it is credibility. A three-month window produces less evidence for the auditor to sample and a report a sophisticated customer may read as thin — particularly for controls that only run quarterly, such as access reviews or a management review, which a short period may not contain a single instance of. Map your periodic controls before you choose the window, and make sure the period contains at least one run of each.

For a first Type 2 with no deadline pressure, six months is the pragmatic choice, moving to twelve once you are on an annual cycle. For a first Type 2 with a deadline, three months is defensible — just expect to explain the window, and expect the next report to cover longer.

What carries over if you do both

Almost all of it, which is the genuine argument for the Type 1 when you need one. A Type 1 is the cheapest possible start on a Type 2 rather than a detour.

The scoping decision carries: which Trust Services Criteria categories you are reporting against. Security, delivered through the common criteria, is in every SOC 2; Availability, Processing Integrity, Confidentiality and Privacy are included only where a commitment you have made to customers calls for one. Getting that wrong is expensive in both directions — an unnecessary category is work you pay for twice, and a missing one is a report that does not answer the question your customers asked.

The system description carries — the written account of the service, its boundaries and the commitments you have made about it. So do the controls themselves, the evidence-collection habits, and the auditor relationship. What does not carry is time: the Type 2 observation period starts when it starts, which is why the sequencing question is really a question about your calendar.

Reading the opinion, because “unqualified” does not mean “no exceptions”

Every SOC 2 report carries an opinion, and there are four. An unqualified — unmodified — opinion is the clean one. A qualified opinion means a material problem in the description or in the design or operation of controls that is confined rather than pervasive. An adverse opinion means the same kind of problem, pervasive. A disclaimer means the auditor could not gather enough to form an opinion at all, and is rare.

Two things surprise people. Qualified opinions are reasonably common, and are not the catastrophe the word suggests — they are usually confined to one area, change management being the classic. And an unqualified opinion does not mean the auditor found nothing: exceptions can be noted within a clean opinion.

Which means the opinion paragraph is where you start reading, not where you stop. The testing section — controls, tests performed, results — is where the report actually says what happened, and it is the part your own reviewers should read when you are the one assessing a supplier’s report.

The gap between reports, and the letter that does not close it

A Type 2 covers a period that ended, and the period keeps ending. A customer whose financial year closes three months after your report period will ask what happened in between, and the usual answer is a bridge letter — also called a gap letter.

Know what it is before you promise one. A bridge letter is issued and signed by your own management, not by your auditor, because the CPA firm’s attestation is limited to the period it examined. It states that you are still operating the controls described and discloses any material changes in the control environment since the period ended. It typically covers up to about three months.

It is a supplement, not a substitute. It carries your assertion rather than an auditor’s opinion, and stretching one across a long gap is transparent to anyone reading carefully. The structural fix is a reporting cadence that keeps the gap short — which is another reason the annual rhythm matters more than the first report’s date.

Common questions

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 reports on whether controls were suitably designed and implemented as at a single date. A Type 2 also reports on whether they operated effectively across a period, which the auditor tests by sampling records. Only a Type 2 can evidence that a control has actually run.

Should we do a Type 1 first or go straight to Type 2?

Do a Type 1 first only if a specific deal or procurement gate is blocked now and the Type 2 observation period has not started. Otherwise go straight to Type 2 and avoid paying for two examinations. Everything built for a Type 1 carries into the Type 2 except elapsed time.

What is the minimum period for a SOC 2 Type 2?

None is mandated by the attestation standards. The widely repeated three-month minimum is market convention, and AICPA guidance has suggested at least six months. The practical constraint is that the period should contain at least one run of every periodic control, such as quarterly access reviews.

Is a SOC 2 a certification?

No. It is an attestation examination performed under AICPA standards by a licensed CPA firm, and the output is a report containing an opinion. There is no SOC 2 certificate and no certification body — which is a genuine difference from ISO 27001, where an accredited body issues a certificate.

Does an unqualified opinion mean no problems were found?

No. Exceptions can be noted within an unqualified opinion. The opinion states whether the description is fairly presented and the controls suitably designed and — in a Type 2 — operating effectively; the testing section is where individual exceptions appear. Read both, especially when assessing a supplier.

What is a SOC 2 bridge letter?

A letter covering the gap between the end of your report period and a customer’s year-end, typically up to about three months. It is issued and signed by your management, not your auditor, and states that the controls are still operating and discloses material changes. It supplements a report rather than replacing one.

The bottom line

Only a blocked contract justifies a Type 1, and it should be commissioned as the first step of a Type 2 rather than as an end state. When you pick the Type 2 window, ignore the three-month figure and choose a period that contains at least one run of every periodic control you rely on.

  • SOC 2 Type 1 Readiness

    Prove your controls are designed and in place on a given date — the fastest honest way to unblock a contract.

  • SOC 2 Type 2 Readiness

    Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.

Related insights