Skip to main content

Explainers

SOC 2 Type I vs Type II: what each one proves to a buyer

Type I says controls were designed properly on one date. Type II says they operated over a period with sampled evidence and listed exceptions. Which to accept, when, and what to ask.

Solomon AmosPublished 14 Sep 2026Updated 18 Sep 202610 min read

A team reviewing documents around a table
Photo by Annie Spratt on Unsplash

Both report types come from the same standard, the same Trust Services Criteria and, usually, the same auditor. The difference is time. A Type I report looks at the design of controls as of one date. A Type II report looks at the design and the operating effectiveness of those controls across a period, normally six to twelve months, and tests samples of evidence from that period. For a buyer, that one difference decides how much weight the report can carry, and the wrong choice costs deals on the vendor side and incidents on the buyer side.

1 date
A Type I report covers
Design of controls only
6 to 12 months
A Type II report covers
Design and operating effectiveness, sampled
66%
of B2B buyers check for SOC 2 before signing
Agency, SOC 2 statistics roundup

The definitions, precisely

A Type I report contains the auditor’s opinion on whether the vendor’s description of its system is fairly presented and whether the controls are suitably designed to meet the criteria as of a specified date. A Type II report contains the same opinion plus an opinion on whether the controls operated effectively throughout a specified period, supported by tests described in section 4. The AICPA titles say it in one line: "design" for Type I, "design and operating effectiveness" for Type II.

Type 1 is a photograph. Type 2 is a film.
Type IType II
Question answeredWere suitable controls in place on this date?Did the controls operate effectively over this period?
EvidenceWalkthroughs, policies, screenshots as of the dateSampled records across the period: tickets, logs, access reviews, change approvals
ExceptionsNot applicable; nothing operated yetListed per control with counts and management responses
Typical timingFirst report, three to six months after controls go liveAnnually after the first period closes
How it agesImmediately after the dateAbout three months after the period end without a bridge letter
Enterprise acceptanceSometimes, with an agreed Type II dateThe default requirement
Printed reports and a pen on a desk beside a laptop
Section 4 of a Type II lists every test and every exception. A Type I has no section 4 results to read. · Photo by Helloquence on Unsplash

When a Type I is acceptable

  • A young vendor with a first report and a Type II period already under way. Ask for the period start and the expected period end, and write both into the contract.
  • A new product line inside a company whose other products already carry a Type II from the same firm.
  • Low-sensitivity use where your own controls, not the vendor’s, protect the data, for example a marketing tool that never sees customer records.
  • A proof of concept with an explicit re-review before production use.

When to insist on a Type II

  • Any vendor that stores or processes customer data, credentials, health information or financial records.
  • Any vendor that will appear as a subservice organisation in your own SOC 2 or ISO 27001 scope.
  • Any renewal. A vendor that offered a Type II last year and a Type I this year has gone backwards; ask why before you renew.
  • Any vendor whose contract value makes an incident material to your business.

How the period length changes what you learn

Type II periods run from three to twelve months. A three-month period is legitimate for a first Type II, but the sample sizes are small: a quarterly access review will have been performed once. A twelve-month period tests annual controls at least once and quarterly controls four times, which is what makes exceptions meaningful. Check the period in section 1 and the sample counts in section 4 before you weight an exception.

How many times a control is exercised inside the period
  • Daily backup, 12-month period365sampled
  • Weekly vulnerability scan, 12 months52
  • Quarterly access review, 12 months4
  • Quarterly access review, 3 months1
  • Annual risk assessment, any period1

The reading order for a Type II

The order that saves the most time is the opinion, the period, the criteria in scope, the carve-outs, then the exceptions. The reading guide walks each section with a twenty-minute plan. The habit worth building is to read the exceptions before the passes: a report with two exceptions on access reviews and a clear management response is more useful than a spotless one you cannot tell anything from.

The gap after the period end

Between a period end and the next report, vendors issue bridge letters. A bridge letter is a management representation that nothing material changed; it is not an auditor opinion and no testing sits behind it. Industry practice caps a bridge letter at about 90 days, and buyers get sceptical past six months. CertReports records a bridge letter as vendor-stated next to the report it extends. More in what a bridge letter is.

What vendors get wrong, and what it costs them

Vendors sometimes present a Type I as equivalent to a Type II, or leave a badge on the trust centre after the Type II period has aged out. Buyers notice. In Agency’s roundup of SOC 2 statistics, over a third of organisations reported losing a deal for lack of a required security attestation, and SOC 2 audit volume is growing 20 to 30 percent a year as procurement teams standardise on it. The cheapest fix on the vendor side is to publish the type, the period end and the firm next to the badge.

For most buyers, SOC 2 Type 2 is preferred to Type 1 because a Type 2 report proves your controls worked over time, while a Type 1 only shows they were designed and in place on a certain date.
A padlock resting on a laptop keyboard
Operating effectiveness is the point: a Type II shows the lock was used, not just installed. · Photo by FLY:D on Unsplash

How the index records the difference

A SOC 2 row on CertReports carries the report type and, for a Type II, the period end. Rows are dated at capture and re-checked, so a Type II whose period ended more than twelve months ago shows as stale even when the trust centre badge never changes. Put two vendors side by side on Compare and the type and period sit in the same cell for both.

  1. 1

    Ask for the type

    If the answer is Type I, ask for the Type II period start and expected end.

  2. 2

    Ask for the period end

    Older than three months needs a bridge letter; older than twelve needs the next report’s date.

  3. 3

    Ask for the criteria

    Security only is common. Availability and Confidentiality matter for anything on your critical path or holding your data.

  4. 4

    Ask for the firm

    A licensed CPA firm, the same one on the report you receive.

Never "certified"

Neither report type certifies anything. Ask for the type, the period end, the criteria and the firm, and you have everything the badge was hiding.

People also ask

Is SOC 2 Type II better than Type I?

For assurance, yes. A Type II tests that controls operated over a period with sampled evidence; a Type I only confirms they were designed properly on one date. Type I is a reasonable first step, not a substitute.

How long does a SOC 2 Type II audit period have to be?

Between three and twelve months. Three-month periods are common for a first Type II; twelve months gives quarterly and annual controls enough repetitions for exceptions to mean something.

Do I need a Type I before a Type II?

No. Many vendors go straight to a Type II. A Type I is useful when a buyer needs something within months of controls going live and will accept a Type II date in the contract.

How much does SOC 2 Type II cost compared with Type I?

Type II costs more because the auditor samples evidence across the period. Published estimates vary widely by scope and firm; treat any single figure as indicative and ask the vendor for the scope instead.

Can a vendor be SOC 2 certified?

No. SOC 2 produces an attestation report with an opinion, not a certificate. Vendors that write "certified" usually mean they hold a report; ask which type and which period.

What happens after the Type II period ends?

The vendor issues a bridge letter covering the gap, then a new report for the next period. A bridge letter is a management statement without auditor testing and should not run past about 90 days.

SOC 2Type IType IIattestationvendor review
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like