SOC 2 Type 1 vs Type 2: Which Do You Need First?

ISO Cloud Consulting editorial team
Illustration contrasting a single snapshot of a shield with a months-long timeline of repeated checks

A SOC 2 Type 1 report checks that your controls are designed properly and in place on a single date. A Type 2 report checks that they actually worked over a period, commonly 3 to 12 months. Enterprise buyers usually want Type 2 in the end, but a Type 1 is the faster way to unblock early deals.

Key facts

  • Both are attestation reports by a licensed CPA firm against the same Trust Services Criteria (61 criteria; Security's 33 always in scope).
  • Type 1: design and implementation as of one date.
  • Type 2: design and operating effectiveness over a period, commonly 3 to 12 months.
  • Both are restricted-use and shared with customers, usually under NDA.
  • Neither is a certification, and neither expires on a fixed date, although customers typically expect an annual refresh.

What is a SOC 2 Type 1 report?

A Type 1 report is a snapshot. The auditor confirms that, on a specific date, your system description is fair and your controls are suitably designed and implemented to meet the criteria in scope.

The auditor reads your policies, inspects configurations and looks at one example of each control. For access reviews, that might be the most recent review. It does not prove the review happens every quarter, only that the control exists and is designed sensibly. That is why buyers treat Type 1 as evidence of intent and structure, not of track record.

What is a SOC 2 Type 2 report?

A Type 2 report is a track record. The auditor tests whether your controls operated effectively throughout a defined period, by sampling evidence from across that period.

If your policy says access is reviewed quarterly and the period is six months, the auditor expects two reviews and checks both. If you onboarded 30 people, they sample some and check each had training, a signed agreement and approved access. Failures appear in the report as exceptions, with your response. One exception does not automatically sink the report; a pattern can lead to a qualified opinion.

How do Type 1 and Type 2 compare?

The two reports use the same criteria and the same kind of auditor. They differ in what is tested, how long it takes and how much weight buyers give them.

Factor Type 1 Type 2
Question answered Are controls designed and in place? Did controls work over time?
Point in time or period One date A period, commonly 3 to 12 months
Evidence Policies, settings, one example per control Samples from the whole period
Time from readiness to report Weeks Period length plus fieldwork and reporting
Audit effort and fee Lower Higher, with more testing
Weight with enterprise buyers A useful first step What most eventually require
Risk of exceptions Low if design is sound Real if recurring controls slip

Which SOC 2 report should you get first?

Get a Type 1 first if a deal needs something soon and your controls are new. Go straight to Type 2 if your controls already run reliably and your buyers will wait for a report covering a period.

Use these questions to decide:

  1. What does the customer accept? Ask in writing. Some accept a Type 1 plus a committed Type 2 date; some accept only Type 2.
  2. How soon do you need a report? If a deal closes this quarter, a Type 2 with a meaningful period may simply be too far away.
  3. How mature are your controls? If most controls started last month, a Type 1 gives you an audited baseline while they bed in.
  4. What can you afford? Two audits in the first year cost more than one. Some auditors price a Type 1 followed by a Type 2 as a package; ask.

Can you skip Type 1 and go straight to Type 2?

Yes. Nothing requires a Type 1 first. Many companies whose controls are already stable start a Type 2 period directly and save one audit.

The trade-off is timing and risk. You receive nothing until the period ends and the auditor reports, and any design flaw you missed runs through the entire period as an exception. A careful readiness review, ideally a dry run where you pull evidence exactly as an auditor would, reduces that risk. So does asking your auditor to walk through your control matrix before the period starts. Our SOC 2 checklist covers the readiness steps.

How long should your first Type 2 period be?

Many companies choose a shorter first period, often 3 to 6 months, then move to 12-month periods that run back to back. A short first period gets a report into buyers' hands sooner; a 12-month period gives the strongest assurance.

Agree the period with your auditor and your key customers before you start. Make sure every quarterly or annual control will occur at least once inside the window, otherwise the auditor may have nothing to test for it.

What does a first-year SOC 2 timeline look like?

Most first-year plans follow one of two paths. The illustration below uses Harbor Ledger (fictional), a 20-person software company that becomes audit-ready at the end of March.

Stage Path A: Type 1 first Path B: straight to Type 2
April Type 1 as of an agreed date 3-month Type 2 period starts
May to June Type 1 report shared with prospects; 6-month Type 2 period starts Controls running, monthly evidence checks; period ends in June
July to December Controls running; period ends in December Fieldwork and first Type 2 report; 12-month period begins
Following year First Type 2 report; 12-month periods begin Annual reports continue

Path A gives buyers something early and builds a longer track record. Path B saves one audit and gets a Type 2 out sooner, but offers nothing in the meantime. The dates are illustrative; your auditor's calendar and your readiness set the real ones.

What do buyers look for when they read a SOC 2 report?

Experienced buyers read past the cover page. They check the report type and period, the opinion, which categories are in scope and whether the system description covers the product they are buying.

They also read any exceptions with your responses, and the complementary user entity controls: the controls your report says customers must run themselves, such as managing their own users. A report that covers the wrong product or an old period does little for them.

What happens between SOC 2 reports?

Between reports, customers may ask for a bridge letter. This is a short statement from your management, not the auditor, saying whether anything significant has changed since the last period ended.

Plan your periods so gaps are short. The usual pattern is annual Type 2 periods that start the day after the previous one ends, so there is always a recent report and a short bridge.

What mistakes do companies make choosing between Type 1 and Type 2?

  • Not asking the customer. Teams spend months on a Type 1 only to learn the buyer requires Type 2.
  • Starting the Type 2 period on the day controls go live. Give new controls a few weeks to settle first.
  • Choosing a period that misses annual controls. If the risk assessment or restore test falls outside the window, it cannot be tested.
  • Treating Type 1 as the finish line. Without a plan and date for Type 2, a Type 1 loses value quickly with buyers.
  • Letting periods lapse. A gap between one period's end and the next one's start leaves months that no report covers, and buyers notice.

How can you prepare for either report?

Preparation is the same for both: scope, gap assessment, policies, risk and vendor reviews, working controls and organized evidence. The difference is how long you must keep controls running before the auditor looks.

A control matrix is the tool that makes Type 2 manageable, because it lists every control, owner, frequency and evidence location. Our SOC 2 Readiness Assessment & Control Matrix ($59) is built for this. For background on the criteria and report structure, read what SOC 2 is or visit the SOC 2 guide. Official material on SOC 2 examinations is on the AICPA SOC 2 page. Templates help you prepare; the report itself always comes from a CPA firm.

Last reviewed: 29 September 2026

Back to blog

Frequently asked questions

Is a SOC 2 Type 1 report worth getting?

It is worth it when a customer needs evidence soon and your controls are new. A Type 1 gives buyers an independent view of your control design and gives you an audited baseline. It is less useful if your buyers only accept Type 2, so confirm their requirement before you commit time and budget.

What is the minimum SOC 2 Type 2 period?

There is no single minimum written into the criteria. Periods of 3 to 12 months are common, and many first reports use a shorter window of around three to six months. Discuss the length with your auditor and customers, because a very short period gives buyers limited assurance and may miss infrequent controls.

Does a SOC 2 Type 2 include everything in a Type 1?

Yes. A Type 2 covers the fairness of the system description and the suitability of control design, which is what a Type 1 covers, and adds testing of operating effectiveness over the period. That is why companies that already have stable controls often skip Type 1 and go straight to Type 2.

What is an exception in a SOC 2 Type 2 report?

An exception is a case where the auditor's test found a control did not operate as described, for example a leaver whose access was removed late or a quarterly review that was missed. The report lists exceptions with management's response. Isolated exceptions are common; widespread ones can lead to a qualified opinion.

Templates that do this job

Editable Word and Excel files. Instant download. Licensed for one organization.