Report decision guide

SOC 2 Type I Versus Type II

Compare what each report evaluates, how buyers use them, and the operational questions to answer before selecting a path.

By Shawn Thornton6-minute readReviewed July 2026
Direct answer

A Type I report evaluates the design of specified controls as of a point in time. A Type II report also evaluates whether specified controls operated effectively over a defined period. Many enterprise buyers prefer Type II, but the correct path depends on the contract requirement, maturity, deadline, and CPA firm plan.

Type I and Type II compared

FactorType IType II
Time basisPoint in timeDefined review period
Main questionAre controls suitably designed?Are controls suitably designed and operating effectively?
EvidenceDesign and implementation evidenceDesign, implementation, and operating evidence across the period
Buyer signalEarly assurance or milestoneStronger evidence of sustained operation

Questions to answer before choosing

  • Does the customer contract explicitly state Type I or Type II?
  • Is there a date by which the report must be issued?
  • Are the controls already implemented and consistently operating?
  • Can the company sustain evidence collection through the expected review period?
  • Would Type I unlock the opportunity, or will the buyer still require Type II?
  • Has the independent CPA firm confirmed the approach and timing?

A practical maturity test

Policies exist but are inconsistent

Validate implementation before assuming the company is ready for either report.

Named control owners

Ownership across access, change, incidents, vendors, and people operations strengthens readiness.

Recurring evidence workflows

Consistent evidence generation supports a sustainable Type II period.

Failures discovered late

Monitoring and ownership are not mature enough for a clean operating period.

Frequently asked questions

Can a startup go directly to Type II?

Potentially. The decision should reflect control maturity, buyer requirements, and the CPA firm's plan.

How long is the Type II period?

The exact period is defined in the engagement and report. Confirm it with the CPA firm.

Can a company call itself SOC 2 certified?

No. SOC 2 is an attestation reporting framework, not a certification program.

Does Type I reduce the work for Type II?

It can validate design and reveal gaps, but controls still must operate and produce evidence for Type II.

Recommended next step

Choose the report path based on buyer requirements and operating maturity.

Clarify the commercial requirement, assess current controls, and coordinate with an independent CPA firm before publishing a date.

Book a Compliance Clarity CallRead the customer-request response plan

Sources and editorial note

Based on official AICPA SOC guidance. This educational resource is not legal advice or a guarantee of a particular examination result.

How long is a SOC 2 Type II observation period?

There is no minimum period set by the attestation standard. SOC 2 examinations are assertion-based examination engagements performed under AT-C section 205, as amended by SSAE No. 21, which applies to practitioner reports dated on or after June 15, 2022. That standard governs how the examination is performed. It does not prescribe how many months the period must cover.

The period is set in the engagement between the organization and the CPA firm, and in practice it is shaped by what customers will accept. Three patterns are common:

  • A first Type II covering roughly three months. This is the fastest route to a report that demonstrates operating effectiveness, and it is usually chosen when a deal is waiting.
  • A six-month period, often used as a step between a short first report and an annual cycle.
  • A twelve-month period aligned to the fiscal year. This is where most mature programs land, and some enterprise buyers expect it once a vendor relationship is established.

A shorter first period is not a shortcut around the work. Controls still have to be operating for the whole period, and evidence has to exist for the whole period. A three-month window simply means the evidence trail starts three months before the report closes rather than twelve.

What each report actually tells a buyer

Type I

A Type I addresses whether controls are suitably designed as of a single specified date. It says the control environment was described accurately and the design was appropriate on that date. It says nothing about whether the controls were followed the week before or the month after.

Type II

A Type II addresses design and operating effectiveness across a defined period. The CPA firm tests samples drawn from that period. If access reviews were supposed to happen quarterly and one was skipped, a Type II is where that surfaces. This is why buyers weigh it more heavily.

When a Type I is worth doing

  • A customer has accepted a Type I explicitly, in writing, as sufficient for now.
  • The control environment is new and the organization wants an independent check on design before committing to an observation window.
  • A deal is time-boxed and a Type I buys room while the Type II period runs.

When a Type I is not enough

  • The customer's security review explicitly requires evidence of operating effectiveness.
  • The organization already has a Type I and the same customer is asking again a year later.
  • The buyer is in a regulated sector and passes the report to their own auditors.

Some organizations skip Type I entirely and go straight to a short Type II. Whether that is sensible depends on how mature the controls already are and how much time the deal allows.

What covers the gap between reports

A Type II report covers a period that has already closed. If a customer asks for assurance in March and the most recent report ended in December, that three-month gap is usually addressed with a bridge letter, also called a gap letter.

Two things matter about bridge letters. They are issued by the organization's management, not by the CPA firm, so they carry no independent assurance. And they are generally expected to cover a short interval, commonly around three months. A bridge letter is not a substitute for a current report, and a buyer who is paying attention will treat it that way.

Which criteria the report covers

Both report types are scoped to the Trust Services Criteria the organization selects. Security, referred to as the common criteria, is always included. Availability, Processing Integrity, Confidentiality, and Privacy are optional and are added based on what the organization does and what its customers ask for. Adding criteria increases the control and evidence burden, so scope should follow real buyer requirements rather than an attempt to look comprehensive.

SOC 2 is an attestation reporting framework, not a certification program. Reports are issued by independent licensed CPA firms. Smart Biz iT supports readiness, implementation, and operations, and does not perform examinations or issue reports.