Both report types come from the same standard, the same Trust Services Criteria and, usually, the same auditor. The difference is time. A Type I report looks at the design of controls as of one date. A Type II report looks at the design and the operating effectiveness of those controls across a period, normally six to twelve months, and tests samples of evidence from that period. For a buyer, that one difference decides how much weight the report can carry, and the wrong choice costs deals on the vendor side and incidents on the buyer side.
- 1 date
- A Type I report covers
- Design of controls only
- 6 to 12 months
- A Type II report covers
- Design and operating effectiveness, sampled
- 66%
- of B2B buyers check for SOC 2 before signing
- Agency, SOC 2 statistics roundup
The definitions, precisely
A Type I report contains the auditor’s opinion on whether the vendor’s description of its system is fairly presented and whether the controls are suitably designed to meet the criteria as of a specified date. A Type II report contains the same opinion plus an opinion on whether the controls operated effectively throughout a specified period, supported by tests described in section 4. The AICPA titles say it in one line: "design" for Type I, "design and operating effectiveness" for Type II.
Type 1 is a photograph. Type 2 is a film.
| Type I | Type II | |
|---|---|---|
| Question answered | Were suitable controls in place on this date? | Did the controls operate effectively over this period? |
| Evidence | Walkthroughs, policies, screenshots as of the date | Sampled records across the period: tickets, logs, access reviews, change approvals |
| Exceptions | Not applicable; nothing operated yet | Listed per control with counts and management responses |
| Typical timing | First report, three to six months after controls go live | Annually after the first period closes |
| How it ages | Immediately after the date | About three months after the period end without a bridge letter |
| Enterprise acceptance | Sometimes, with an agreed Type II date | The default requirement |
When a Type I is acceptable
- A young vendor with a first report and a Type II period already under way. Ask for the period start and the expected period end, and write both into the contract.
- A new product line inside a company whose other products already carry a Type II from the same firm.
- Low-sensitivity use where your own controls, not the vendor’s, protect the data, for example a marketing tool that never sees customer records.
- A proof of concept with an explicit re-review before production use.
When to insist on a Type II
- Any vendor that stores or processes customer data, credentials, health information or financial records.
- Any vendor that will appear as a subservice organisation in your own SOC 2 or ISO 27001 scope.
- Any renewal. A vendor that offered a Type II last year and a Type I this year has gone backwards; ask why before you renew.
- Any vendor whose contract value makes an incident material to your business.
How the period length changes what you learn
Type II periods run from three to twelve months. A three-month period is legitimate for a first Type II, but the sample sizes are small: a quarterly access review will have been performed once. A twelve-month period tests annual controls at least once and quarterly controls four times, which is what makes exceptions meaningful. Check the period in section 1 and the sample counts in section 4 before you weight an exception.
- Daily backup, 12-month period365sampled
- Weekly vulnerability scan, 12 months52
- Quarterly access review, 12 months4
- Quarterly access review, 3 months1
- Annual risk assessment, any period1
The reading order for a Type II
The order that saves the most time is the opinion, the period, the criteria in scope, the carve-outs, then the exceptions. The reading guide walks each section with a twenty-minute plan. The habit worth building is to read the exceptions before the passes: a report with two exceptions on access reviews and a clear management response is more useful than a spotless one you cannot tell anything from.
The gap after the period end
Between a period end and the next report, vendors issue bridge letters. A bridge letter is a management representation that nothing material changed; it is not an auditor opinion and no testing sits behind it. Industry practice caps a bridge letter at about 90 days, and buyers get sceptical past six months. CertReports records a bridge letter as vendor-stated next to the report it extends. More in what a bridge letter is.
What vendors get wrong, and what it costs them
Vendors sometimes present a Type I as equivalent to a Type II, or leave a badge on the trust centre after the Type II period has aged out. Buyers notice. In Agency’s roundup of SOC 2 statistics, over a third of organisations reported losing a deal for lack of a required security attestation, and SOC 2 audit volume is growing 20 to 30 percent a year as procurement teams standardise on it. The cheapest fix on the vendor side is to publish the type, the period end and the firm next to the badge.
For most buyers, SOC 2 Type 2 is preferred to Type 1 because a Type 2 report proves your controls worked over time, while a Type 1 only shows they were designed and in place on a certain date.
How the index records the difference
A SOC 2 row on CertReports carries the report type and, for a Type II, the period end. Rows are dated at capture and re-checked, so a Type II whose period ended more than twelve months ago shows as stale even when the trust centre badge never changes. Put two vendors side by side on Compare and the type and period sit in the same cell for both.
- 1
Ask for the type
If the answer is Type I, ask for the Type II period start and expected end.
- 2
Ask for the period end
Older than three months needs a bridge letter; older than twelve needs the next report’s date.
- 3
Ask for the criteria
Security only is common. Availability and Confidentiality matter for anything on your critical path or holding your data.
- 4
Ask for the firm
A licensed CPA firm, the same one on the report you receive.
Never "certified"
Neither report type certifies anything. Ask for the type, the period end, the criteria and the firm, and you have everything the badge was hiding.
People also ask
Is SOC 2 Type II better than Type I?
For assurance, yes. A Type II tests that controls operated over a period with sampled evidence; a Type I only confirms they were designed properly on one date. Type I is a reasonable first step, not a substitute.
How long does a SOC 2 Type II audit period have to be?
Between three and twelve months. Three-month periods are common for a first Type II; twelve months gives quarterly and annual controls enough repetitions for exceptions to mean something.
Do I need a Type I before a Type II?
No. Many vendors go straight to a Type II. A Type I is useful when a buyer needs something within months of controls going live and will accept a Type II date in the contract.
How much does SOC 2 Type II cost compared with Type I?
Type II costs more because the auditor samples evidence across the period. Published estimates vary widely by scope and firm; treat any single figure as indicative and ask the vendor for the scope instead.
Can a vendor be SOC 2 certified?
No. SOC 2 produces an attestation report with an opinion, not a certificate. Vendors that write "certified" usually mean they hold a report; ask which type and which period.
What happens after the Type II period ends?
The vendor issues a bridge letter covering the gap, then a new report for the next period. A bridge letter is a management statement without auditor testing and should not run past about 90 days.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
What is a bridge letter, and how much should a buyer trust one?
Solomon Amos · 12 Sep 2026 · 9 min read