Attestation
SOC 2 Type 1 Readiness
A Type 1 answers one question: on this date, were the controls suitably designed and implemented? It is the shorter path, it is a real report signed by a licensed CPA firm, and it is not an end state — which is worth knowing before you buy one.
- Standard
- AICPA Trust Services Criteria
- Report covers
- Design, at a date
- Typical run
- 6–12 weeks
- Criteria categories
- 5
What a Type 1 actually says
A SOC 2 examination is performed under AICPA standards against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security — delivered through the common criteria — is required in every SOC 2; the other four are included only when a commitment you have made to customers calls for one.
A Type 1 reports on the DESIGN and implementation of those controls as at a single date. The auditor asks whether a control exists, whether it is suitably designed to meet the criterion, and whether it had been implemented by that date. What a Type 1 does not do is say the control has ever run.
That limit is the whole of the difference. A Type 1 cannot be evidence of operating effectiveness, and a buyer who asked for "your SOC 2" and receives one will often come back asking for the other. It is the right report when a contract is blocked now and the observation period a Type 2 needs has not started.
What it will ask of you
Less than a Type 2, but not nothing — and the work is the same work, which is why a Type 1 is the cheapest possible start on a Type 2.
A system description
A written account of the service being examined, its boundaries, and the commitments you have made to customers about it. The auditor tests against this, so an optimistic description is a trap you set for yourself.
A scoping decision you can defend
Which Trust Services Criteria are in and which are out. Security is in by definition; every other category you add becomes controls you must design and, later, evidence continuously.
Controls in place by the date
Not planned, not in flight — implemented and demonstrable on the as-of date. A control that goes live the following week is not in the report.
Subservice organisations, named
Which providers you rely on, whether they are carved out or included, and which complementary user entity controls your own customers are expected to run.
Why organisations start here
- It unblocks a contract in weeks rather than quarters, with a real report rather than a questionnaire.
- It proves the control design before you commit to a Type 2 observation window you cannot pause.
- Everything built for it counts towards the Type 2 — nothing is thrown away.
- It surfaces scoping mistakes while they are still cheap to correct.
Where we come in, and where we stop
A SOC 2 report can only be issued by an independent licensed CPA firm. We are not one, and no amount of preparation changes who signs.
Ours
- Scoping the Trust Services Criteria, and arguing against the ones you do not need
- Readiness assessment and the remediation plan
- Designing and implementing controls with your engineering and people teams
- Drafting the system description
- Running the auditor’s request list from your side, through to the report
An independent licensed CPA firm
- Performing the examination as at the agreed date
- Forming an opinion on the design and implementation of the controls
- Issuing the SOC 2 Type 1 report
How we get you there
The examination itself is performed by an independent licensed CPA firm. We prepare you for it and we do not perform it.
- 01Scoping the criteriaWe work out which Trust Services Criteria your customer commitments actually require, and — as importantly — which ones to leave out.
- 02Readiness assessmentA control-by-control gap assessment against the criteria in scope, covering the system description, subservice organisations and complementary user entity controls.
- 03Control design and remediationWe design controls that can be evidenced repeatably, then implement them with your teams. A control nobody can evidence is a finding waiting to happen.
- 04Choosing the as-of dateLate enough that everything is genuinely implemented, early enough to meet the commercial deadline that started this. Getting this wrong is the commonest way a Type 1 slips.
- 05Auditor selection and liaisonWe help you select a licensed CPA firm, prepare the system description, and act as your counterpart through fieldwork.
What you get from us
- A scoping decision with the reasoning written down, criterion by criterion
- Readiness assessment and remediation plan
- Designed and implemented controls with named owners
- A drafted system description ready for the auditor
- Support through fieldwork to a signed Type 1 report
- A standing start on the Type 2, if that is the next step
Common questions
Is a Type 1 enough?
For a specific blocked contract, often yes — ask the customer. As a standing answer to enterprise procurement, generally no: most buyers mean Type 2 when they say SOC 2, and a Type 1 buys time rather than closing the question.
How quickly can we have one?
Six to twelve weeks from kick-off for a contained scope, and the pacing constraint is remediation rather than the examination. If controls already exist and just need evidencing, it is faster.
Does the work carry over to a Type 2?
Almost all of it. The scope, the controls, the system description and the auditor relationship are the same; what a Type 2 adds is the observation period and evidence across it.
Can you issue the report?
No. Only an independent licensed CPA firm can perform the examination and issue the report. We prepare you, help you choose that firm, and manage the engagement from your side.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Vulnerability Assessment and Penetration Testing (VAPT)
Find what an attacker would find, ranked by what it would actually cost you — and get a report your auditor and your engineers can both use.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.