SOC 2

SOC 2 Type I vs Type II: Which Report Should You Get First?

A CPA firm's plain-English comparison of SOC 2 Type I and Type II — what each tests, how long it takes, what it costs, and how to decide which one to pursue first.

The short answer

A SOC 2 Type I report tests whether your controls are designed appropriately at a single point in time (an “as of” date). A SOC 2 Type II report tests whether those same controls also operated effectively over a period of time — typically 3 to 12 months. Both are examined by a licensed CPA firm against the AICPA Trust Services Criteria; the only differences are the time dimension and the depth of testing.

Which first? Most first-time teams run a Type I (or a readiness assessment) to prove design and unblock a deal, then start the Type II observation window immediately after. Go straight to Type II when your controls are already mature and evidenced.

Key takeaways

  • Type I = design at a point in time; Type II = design plus operating effectiveness over a period. The controls tested are the same Trust Services Criteria — only the test method and time frame change.
  • The AICPA sets no minimum observation period. In practice, 3 months is the accepted floor, 6 months is the common first-report window, and 12 months is standard for renewals.
  • Enterprise buyers almost always want a Type II. A Type I is generally accepted only as an interim signal on the path to Type II.
  • A bridge letter is not a substitute for a report. It covers roughly 90 days between report periods and is management’s representation, not auditor-tested assurance.

SOC 2 Type I vs Type II at a glance

Both reports are issued by a licensed CPA firm under the AICPA’s attestation standards (SSAE 18, with the examination performed under AT-C section 205) and evaluate the same controls mapped to each Trust Services Criterion. What actually differs between Type I and Type II is summarized below.

SOC 2 Type I vs Type II — side-by-side comparison
DimensionSOC 2 Type ISOC 2 Type II
What it evaluatesDesign and implementation of controlsDesign and operating effectiveness of controls
Time frameA single point in time (an “as of” date)A period of time (the observation period, typically 3–12 months)
Auditor methodInspection and walkthrough of control designTests of operating effectiveness, usually via sampling across the period
Typical total timeline~3–6 months~6–15 months (includes the observation window)
Relative costLower — single-date examinationHigher — period testing and more evidence
Buyer acceptanceInterim signal; unblocks deals short-termPreferred by enterprise and regulated buyers
How often issuedOnce, or as a first stepAnnually (rolling observation periods)

The rest of this guide explains each report, the six differences that actually affect your decision, and a simple framework for choosing which to pursue first. For the end-to-end schedule, see our full SOC 2 audit timeline.

What is a SOC 2 Type I report?

A SOC 2 Type I report is an attestation, by an independent CPA firm, that your controls are suitably designed to meet the applicable Trust Services Criteria as of a specific date. The auditor inspects your policies, configurations, and control descriptions and performs walkthroughs to confirm that, on that date, the controls exist and are designed to achieve their objective. It does not test whether the controls actually worked, consistently, over time.

Because there is no observation period, a Type I is the faster of the two reports to obtain once your controls are in place. That makes it useful in three situations: a specific enterprise deal is stalled on a security review this quarter; your controls are too new to have a testable history yet; or your board or investors want an external signal that a compliance program is real. In each case, the Type I demonstrates that the foundation is sound while the longer Type II clock runs in the background.

One common point of confusion: a Type I is not the same as a readiness assessment. A readiness (or gap) assessment is an internal, non-attested exercise that surfaces design gaps before an audit; it produces no auditor’s opinion. A Type I is a formal report, with an independent opinion, that a buyer can request and rely on.

What is a SOC 2 Type II report?

A SOC 2 Type II report attests to both the design and the operating effectiveness of your controls across a defined observation period. Rather than confirming that a control exists on one date, the auditor samples evidence throughout the window — for example, pulling a selection of the access reviews, change tickets, or vulnerability scans that occurred during the period — and evaluates whether each control operated consistently as designed. This is why buyers weight it far more heavily than a Type I: it is evidence that your program actually functions in production, not just on paper.

A SOC 2 report (Type I or Type II) is made up of the same core sections: (1) the independent service auditor’s report and opinion; (2) management’s written assertion; (3) the description of the system; and (4) the applicable Trust Services Criteria and related controls. A Type II adds a fifth element that a Type I never contains — (5) the auditor’s tests of controls and the results of those tests over the period. That test-results section is the heart of a Type II’s value.

“I always advise first-time clients to think of Type I as your proof of concept and Type II as your production deployment. Type I gets you in the door with buyers, but Type II is what keeps them confident year after year.”

— Sébastien Ruosch, CPA, Director of Audits at Auditsuisse

The differences that actually matter

Six practical differences drive the Type I vs Type II decision: scope of testing, time frame, auditor method, timeline, cost, and buyer acceptance. Scope, method, and buyer acceptance are covered above; the three that most often change the plan — timeline, cost, and the observation period — are detailed here.

How long each takes

The single biggest scheduling mistake is quoting only fieldwork duration. What matters for a buyer commitment is total elapsed time, which for a Type II is dominated by the observation period.

Typical elapsed time by phase (varies with scope and readiness)
PhaseSOC 2 Type ISOC 2 Type II
Readiness & remediation1–3 months1–3 months
Observation / audit windowPoint-in-time (“as of” date)3–12 months
Fieldwork~2–5 weeks~2–5 weeks
Report drafting & delivery~2–6 weeks~2–6 weeks
Total elapsed~3–6 months~6–15 months

How much each costs — and what drives the price

Report type is only one input to cost; scope is the real driver. A Type II costs more than a Type I for the same company because the auditor tests controls repeatedly across the period rather than once. The factors below move the price of both.

What drives SOC 2 audit cost
Cost factorEffect on Type IEffect on Type II
Trust Services Criteria selected beyond SecurityModerate increaseLarger increase
Number of in-scope systems / cloud environmentsIncreaseLarger increase
Headcount & process complexityIncreaseIncrease
Current readiness / evidence maturityLower cost if matureLower cost if mature
Length of the observation periodNot applicableLonger period → more sampling → higher cost
Compliance automation platform in placeModest reductionLarger reduction

Published market ranges vary widely and are not a substitute for a quote; the way to control cost is to scope your systems correctly and go into fieldwork with mature evidence. Auditsuisse quotes a single fixed fee after a short scoping call, so there are no surprises mid-engagement.

The observation period, explained

The observation period is the window over which a Type II auditor tests operating effectiveness. Importantly, the AICPA and SSAE 18 do not prescribe a minimum length — the “three-month minimum” you will read elsewhere is an industry convention, not a rule. In practice: 3 months is the accepted fast path when a deal is on the line, 6 months is the recommended window for a first Type II, and 12 months is standard once you are on an annual renewal cycle. A shorter window is quicker but gives buyers less assurance; a longer window is more credible but delays the report.

Which should you get first? A decision guide

The right sequence depends on how mature your controls are and how much time you have. Use the situations below to place yourself.

Choosing your first SOC 2 report
Your situationBest first reportWhy
A named enterprise deal is blocked this quarterType I, then Type IIFastest credible signal; many buyers accept a Type I to proceed while the Type II runs.
Your controls are less than ~3 months oldType I firstThere isn’t enough history to test operating effectiveness yet; a Type I proves design now.
Investors or the board want a signal quicklyType IA point-in-time attestation is achievable in weeks once controls are designed.
Controls are already mature and evidenced for 3+ monthsGo straight to Type IIYou can skip Type I and start the observation clock immediately.
The buyer’s contract explicitly requires “Type II”Type II (Type I optional)Only a Type II satisfies the requirement; a Type I won’t close it.
You expect continuous enterprise diligenceType II on an annual cadenceSustained trust requires proof that controls operate over time, every year.

The standard progression — and won’t I pay twice?

The classic path for first-timers is Type I → Type II, because a Type I readiness pass surfaces design gaps before the Type II observation clock starts, reducing the risk that exceptions accrue during the tested period. You do not pay full price twice: the observation window can begin immediately after the Type I, and many firms credit part of the Type I fee toward the subsequent Type II when it is completed within the same annual cycle. Skipping straight to Type II is entirely valid — and increasingly common for teams with mature, well-evidenced controls (often those already running a compliance automation platform). Reviewing the common exceptions that lead to a qualified opinion before you start is the cheapest insurance either way.

After your report: renewals and bridge letters

SOC 2 is not a one-time certificate; it is a recurring examination. A Type II covers a stated period, so buyers expect a fresh report on a rolling basis — usually annually. In practice a Type I is treated as current for roughly 6–12 months, and a Type II is generally accepted until about 12 months after its period end date, after which prospects and existing customers will ask for a refresh.

To cover the gap between a report’s period-end date and the date a buyer is reviewing it, companies issue a bridge letter (also called a gap letter). A bridge letter is a management-signed statement that no material changes have occurred to the control environment since the last report. It is a representation by your management — not auditor-tested assurance — so industry practice limits it to about 90 days (no more than three months), and it can never substitute for a new Type II report.

SOC 2 vs SOC 1 vs SOC 3

SOC 2 is one of three “SOC for Service Organizations” reports. They are frequently confused, but they answer different questions and reach different audiences.

SOC 1 vs SOC 2 vs SOC 3
ReportWhat it coversPrimary readerDistribution
SOC 1Controls relevant to a client’s internal control over financial reporting (ICFR); performed under AT-C section 320User auditors, finance teamsRestricted use
SOC 2Security, Availability, Processing Integrity, Confidentiality, Privacy (Trust Services Criteria); performed under AT-C section 205Security & procurement teamsRestricted use
SOC 3The same criteria as SOC 2, summarized without the detailed test resultsGeneral public, prospectsGeneral use (publishable)

Note that AT-C section 320 governs SOC 1, not SOC 2 — a distinction worth getting right in buyer conversations. For international buyers, the closest equivalent is ISAE 3402, the international standard for assurance on service-organization controls. If you are unsure which report your buyers actually need, start with SOC 1 vs SOC 2 for B2B software vendors.

Frequently asked questions

What is the difference between SOC 2 Type 1 and Type 2?

A SOC 2 Type I report tests whether your controls are designed appropriately at a single point in time. A SOC 2 Type II report tests whether those same controls also operated effectively over a period of time, usually three to twelve months. Both are examined by a licensed CPA firm against the AICPA Trust Services Criteria.

Should I get SOC 2 Type 1 or Type 2 first?

Get a Type I first if you need to unblock a deal quickly or your controls are less than three months old — a Type I proves design now and lets the Type II observation window start immediately after. Go straight to Type II if your controls are already mature and evidenced.

How long is the SOC 2 Type 2 observation period?

The AICPA sets no minimum observation period. In practice, three months is the accepted minimum and fastest path, six months is the recommended window for a first Type II report, and twelve months is standard for mature organizations on an annual renewal cycle.

How much does a SOC 2 Type 1 vs Type 2 audit cost?

Cost is driven by scope, not report type alone: the number of Trust Services Criteria beyond Security, the count of in-scope systems, headcount, evidence maturity, and — for Type II — the length of the observation period. A Type II costs more than a Type I because it tests controls over time. Auditsuisse quotes a fixed fee after a short scoping call.

Can you skip SOC 2 Type 1 and go straight to Type 2?

Yes. Skipping Type I and going directly to Type II is viable and increasingly common when your controls are already mature and evidenced. Most first-time teams still run a Type I or a readiness assessment first to catch design gaps before the Type II observation clock starts.

Is a SOC 2 Type 1 report enough for enterprise customers?

Usually not on its own. Most enterprise and regulated-industry buyers require a Type II because it proves controls operated effectively over time. A Type I is typically accepted only as an interim signal to unblock a deal while your Type II observation period is underway.

What is a SOC 2 bridge letter?

A bridge letter (or gap letter) is a management-signed document covering the gap between the end of your last SOC 2 report period and the current date. Industry practice limits it to about 90 days, and because it is not auditor-tested it cannot replace a new Type II report.

Sources & further reading

  1. AICPA & CIMA — SOC 2® — SOC for Service Organizations: Trust Services Criteria.
  2. AICPA & CIMA — 2017 Trust Services Criteria (with Revised Points of Focus — 2022), TSP section 100.
  3. AICPA — Statement on Standards for Attestation Engagements No. 18 (SSAE 18); SOC 2 examinations are performed under AT-C section 205, and SOC 1 under AT-C section 320.
Sébastien Ruosch Reviewed by Sébastien Ruosch, CPA (US & Swiss licensed), Director of Audits at Auditsuisse. Last reviewed July 1, 2026.

Not sure which report your buyers need?

Auditsuisse is a US & Swiss licensed CPA firm. We’ll help you scope the right SOC 2 report, sequence Type I and Type II sensibly, and quote a fixed fee — see our SOC 2 audit services or book a call.

Request Consultation