All insights
Cybersecurity

SOC 2 Type 1 vs Type 2: Which Report Do You Need First?

SOC 2 type 1 covers a single date, type 2 covers a period. Here is how to tell which report your buyer needs first, and what has to be in place before the examination.

By Akam Dasi, Founder and CEO · Published

September 24, 20267 min read

A prospect asks for your SOC 2 report, and the deal stalls while you figure out what they actually want. The SOC 2 type 1 vs type 2 question is usually the first fork in the road, and picking the wrong one costs you months. This guide explains the difference in plain English, shows you how to decide which report to pursue first, and outlines what your team has to have in place before an auditor will start.

Both reports are produced by a licensed CPA firm under AICPA attestation standards. Neither is a certification, and neither is something a consultancy can issue. What a consultancy can do is get you ready, which is a separate and usually longer job than the examination itself.

What both report types have in common

Every SOC 2 examination is built on the same foundation, so start there before worrying about type 1 or type 2.

The Trust Services Criteria. The AICPA publishes the 2017 Trust Services Criteria with revised points of focus, organized into five categories: security, availability, processing integrity, confidentiality, and privacy. Security is the common set that every SOC 2 report includes. The other four are optional and you add them only when they match commitments you actually make to customers.

The system description. You write a description of your system, and the auditor evaluates it against the 2018 SOC 2 description criteria. This document explains what your service does, where the boundaries sit, which subservice organizations you rely on, and which controls you claim to operate. Most first-time companies underestimate how long this takes to write.

A restricted audience. SOC 2 reports go to customers, prospects under NDA, and auditors. They are not marketing collateral. If you want something you can post publicly, the AICPA's SOC 3 report covers the same subject matter with less detail and is described as a general use report that can be freely distributed.

A CPA firm. The examination is performed under the AICPA guidance for SOC 2 examinations, which reflects the requirements of SSAE No. 20 and SSAE No. 21. Your auditor must be independent of the people who built and run the controls.

SOC 2 type 1 vs type 2: the actual difference

The difference comes down to one word: time.

A type 1 report covers a specific date. The auditor looks at your controls as they exist on that date and gives an opinion on whether the system description is fairly presented and whether the controls are suitably designed to meet the criteria. It answers the question: did you build the right controls?

A type 2 report covers a period, commonly three, six, or twelve months. The auditor evaluates design and also tests whether those controls operated effectively across the whole period. It answers a harder question: did you actually run the controls, consistently, over time?

That distinction drives everything else:

  • Type 1 needs your controls to exist and be documented on one date. Type 2 needs evidence that they ran every time they were supposed to, for months.
  • Type 1 evidence is largely policies, configurations, and system screenshots. Type 2 evidence adds tickets, logs, access review records, onboarding and offboarding files, and vendor reviews spanning the period.
  • A gap in type 1 means a control is missing or poorly designed. A gap in type 2 can also mean a control existed but was skipped one quarter.
  • Buyers treat them differently. Many security review teams accept a type 1 as a signal that you are serious, but ask for a type 2 before renewal or before handling sensitive data.

One more practical point on SOC 2 type 1 vs type 2: a type 1 is not a prerequisite. You can go straight to a type 2 if your controls have already been running. Plenty of companies do.

When a type 1 makes sense first

A type 1 is the right starting point when speed matters more than depth of proof.

Choose a type 1 if:

  • A named deal or renewal is waiting on evidence and the buyer has said a type 1 is acceptable.
  • Your controls are new. If you rolled out multi-factor authentication and formal access reviews last month, you have no history to test, and a type 2 window has to start somewhere.
  • You want a low-risk rehearsal. Going through the description, the evidence requests, and the auditor's questions once teaches your team a lot before the longer examination.
  • Your leadership needs a visible milestone to keep the program funded.

The tradeoff is real. You pay for two examinations instead of one, and the type 1 tells a buyer nothing about whether you will still be running those controls in six months.

When to skip straight to a type 2

Go directly to a type 2 if:

  • Your controls have been operating for a while and you can produce evidence going back several months.
  • Your buyers are enterprises or regulated firms. Many will not accept a type 1 at all.
  • You already failed a security review because of a missing type 2, and a type 1 will just delay the same conversation.
  • Budget is tight. One examination costs less than two.

A common middle path is a short first type 2 window, often three months, followed by annual twelve-month periods after that. Discuss the window with your auditor early, because it affects how much evidence you have to reconstruct.

What has to be true before an auditor starts

Readiness is where most of the work lives. Before an examination of either type, you generally need:

  1. A defined scope. Which product, which environments, which locations, which trust services categories.
  2. A written system description that matches reality, not the reality you plan to have next quarter.
  3. Policies that people follow. Access control, change management, incident response, risk assessment, vendor management, and business continuity at minimum.
  4. Identity controls in place. Unique accounts, multi-factor authentication, least privilege, and a documented joiner, mover, and leaver process.
  5. Change management with a trail. Code and infrastructure changes reviewed and approved, with records.
  6. Monitoring and logging that actually gets reviewed, with evidence of the review.
  7. A risk assessment performed and documented, with treatment decisions recorded.
  8. Vendor oversight. A list of subservice organizations, the reports you collect from them, and who reviews those reports.
  9. Evidence you can retrieve. If pulling last quarter's access review takes two days of searching, the examination will hurt.

Mapping these to a recognized framework first can save rework. The NIST Cybersecurity Framework is a reasonable backbone, and the control work you do there carries over to SOC 2, insurance questionnaires, and customer security reviews.

A short decision checklist

Work through these in order:

  • Ask the buyer, in writing, exactly which report and which trust services categories they require.
  • Confirm whether a deadline is fixed or negotiable.
  • Inventory the controls that already run today and how far back the evidence goes.
  • If the evidence history is under three months, price out a type 1 now and a type 2 later.
  • If the history is solid, choose a type 2 window and set the start date.
  • Run a readiness assessment to find gaps before the auditor does.
  • Select a CPA firm and confirm its independence from anyone who helped you remediate.
  • Assign an internal owner. Compliance without a named owner drifts.

Honest limits worth stating

A SOC 2 report is not a certification, and no report means your systems are secure. It means an independent CPA firm examined a described system against stated criteria for a date or a period, and reported findings, including any exceptions. Exceptions are common and do not automatically sink a deal, though you should expect questions about them.

MarkKings Group provides readiness and advisory work: scoping, gap assessment, control design, evidence process, and auditor coordination. We do not issue SOC 2 reports, certifications, or legal advice. The examination and the opinion come from an independent CPA firm, and that separation is what makes the report worth anything to your customers. If you want the broader picture of how the readiness phase runs before an examination starts, our guide to getting SOC 2 ready in 90 days walks through the sequence.

Next steps

Start with the buyer requirement, then match it to the evidence you can actually produce. If you are not sure which side of the SOC 2 type 1 vs type 2 decision you belong on, a readiness assessment answers it quickly and tells you what the gap list looks like.

Our GRC and compliance readiness services cover scoping, gap analysis, and control design, and our cybersecurity audit services test whether the controls hold up in practice. For a wider view of the program, see how we approach security, risk and compliance.

Ready to pick a direction? Book a consultation and we will map your scope, your evidence position, and a realistic timeline.

soc 2complianceaudit readinessgrccybersecurity