SOC 2 comes in two versions, and they answer different questions. A Type I report says your security controls are designed properly as of a single date. A Type II report says those controls actually operated, without failing, over a period of months. Which one you need depends on who is asking and how fast they need an answer.
The short answer
- A deal is waiting and the deadline is weeks away: start with Type I, and commit to a date for Type II.
- You sell to banks, hospitals or large enterprises: they will usually require Type II, so build toward it now.
- You are not sure what customers will ask for: get ready for Type II and decide the report timing after a gap assessment.
What SOC 2 is (and is not)
SOC 2 is an examination framework from the American Institute of CPAs. An independent CPA firm tests your controls against the Trust Services Criteria: Security (always included), plus Availability, Processing Integrity, Confidentiality and Privacy when they are relevant to your service. You choose the scope, management writes a description of the system and an assertion about it, and the auditor issues a report.
Two points that surprise people. SOC 2 is not a law, and it is not a certification: it is an attestation report containing the auditor's opinion (unqualified, meaning clean, or qualified, adverse or disclaimed). And the report is confidential, shared with customers under NDA.
Type I in plain English
The auditor looks at your controls on one date and asks: are they suitably designed to meet the criteria? Policies exist, multi-factor authentication is enforced, logging is on, access is reviewed, vendors are assessed. It is faster and less expensive, and it gives customers a formal document to file. What it cannot show is that anyone followed the controls consistently.
Type II in plain English
The auditor looks at a period, commonly three to twelve months, and asks: did the controls operate effectively the whole time? They sample evidence from across the period: the access reviews for each quarter, the offboarding tickets for specific leavers, the change approvals for specific changes. The report lists each test and its result, including any exceptions. This is the report security teams trust.
Type I vs Type II at a glance
| Type I | Type II | |
|---|---|---|
| Question answered | Are the controls designed properly? | Did the controls work over time? |
| Time covered | A single date | A period, commonly 3 to 12 months |
| What the auditor does | Reviews design and implementation | Tests samples across the whole period |
| Effort and cost | Lower | Higher (more testing, and controls must run continuously) |
| Weight with customers | A start; many ask what comes next | The standard for enterprise and regulated buyers |
| Refresh | One-time first step | Repeated annually, typically covering 12 months |
| Best for | Closing a deal quickly; first-time programs | Ongoing enterprise sales; proving maturity |
How long it takes
For a company with cloud infrastructure and someone who owns the project, a Type I is realistic in about three months from kickoff, including scoping, a gap assessment, fixing the gaps and the auditor's fieldwork. A Type II adds the observation period: a first report often covers three to six months, so plan on roughly six to nine months from a standing start to a report in hand. Your auditor sets the minimum observation window, so ask early.
What drives the cost
- Scope: how many systems, locations and criteria are in the boundary.
- Starting maturity: whether MFA, centralized identity, endpoint management, logging and HR processes already exist.
- The audit firm's fee, which is higher for Type II because there is more to test.
- Tooling: compliance automation platforms collect evidence but do not fix gaps.
- Internal time, which is the cost most companies underestimate.
Five myths worth dropping
"SOC 2 is a certification."
It is an attestation. There is no pass or fail badge, only the auditor's opinion and the details of what was tested.
"A Type I lets us skip the Type II."
Customers who accept a Type I usually expect a Type II within a year. Treat Type I as a stepping stone, not a substitute.
"Exceptions mean we failed."
Exceptions are documented, with management's response. What matters is whether they are isolated and whether you fixed the root cause. A Type II with a few well-handled exceptions is normal.
"A compliance tool makes us compliant."
The tool gathers evidence. Someone still has to close the gaps, run the reviews and keep the controls operating.
"We should include all five criteria."
Start with Security. Add Availability, Confidentiality or the others only when customers or your contracts require them; every extra criterion adds scope.
What a Type II auditor actually samples
- Quarterly access reviews and who signed them.
- Onboarding and offboarding: the date access was revoked versus the termination date.
- Change management: ticket, review, testing and approval for a selection of changes.
- Vulnerability scans and the tickets that closed critical findings on time.
- Backup logs and at least one documented restore test.
- Vendor reviews, security training completion and incident response exercises.
Frequently asked questions
Do we need a Type I before a Type II?
No. Many companies go straight to a Type II. A Type I is a stepping stone that can satisfy a customer sooner, not a prerequisite.
How long is a SOC 2 report valid?
There is no official expiration date. Customers typically want a report that covers the last twelve months, so a Type II is normally refreshed every year.
How long should the Type II observation period be?
Commonly three to twelve months. A first report often covers three to six months. Your audit firm decides the minimum, so confirm it before you start the clock.
What is a bridge letter?
A short statement from management that nothing material has changed since the end of the last report period. Customers commonly accept it to cover a gap of a few months between reports.
Is SOC 2 the same as ISO 27001?
No. SOC 2 is an attestation report from a CPA firm, common in the US. ISO 27001 is a certification of your information security management system by an accredited body, common internationally. Some companies hold both.
Can CorporateTech perform the SOC 2 audit?
No. The audit must be done by an independent CPA firm. We handle readiness, implement the controls, manage the evidence and coordinate with the auditor.
How CorporateTech helps
We prepare you and stay with you through the audit: scoping, the gap assessment, the policy set, the technical controls, the compliance platform, monthly internal reviews and evidence collection, and coordination with your audit firm. The CPA firm issues the report, because independence requires it; our job is to make sure that what they test is ready. For a plain-English primer, download our SOC 2 Type I and Type II guides.
Talk to a compliance expert about your situation
A 30-minute call is usually enough to tell you where you stand and what to do first. No obligation.
Sales line: Monday to Friday, 8 AM to 6 PM Pacific. Existing clients: support is available 24x7.