SOC 2 Type 1 vs Type 2

SOC 2 Type 1 vs Type 2:
a date, or a period.

Both are SOC 2 reports against the same criteria. One says your controls are designed properly on a given day; the other says they worked for months. Here is how they differ, and which one to ask your auditor for.

Last updated Published by TryTrustableNot legal advice

01

What is the difference between SOC 2 Type 1 and Type 2?

A SOC 2 Type 1 report is an auditor's opinion on whether your system description is fair and your controls are suitably designed, as of one date. A Type 2 report covers the same, plus whether the controls operated effectively throughout a period, usually three to twelve months, tested by sampling evidence from across that period.

SOC 2 Type 1SOC 2 Type 2
Opinion coversFair description of the system; suitability of control designThe same, plus operating effectiveness of the controls
TimeAs of a specified dateThroughout a specified period
Typical periodNone; a single dateThree to twelve months; twelve for mature programmes
Auditor testingInquiry, observation and inspection that each control exists and is designed to meet the criteriaSamples drawn from the whole period's populations, re-performance, inspection of records
What can go wrongA control missing or badly designedThe same, plus a control that did not operate for part of the period: exceptions listed in section 4
Time to first reportWeeks after readinessThe window, plus weeks of fieldwork after it ends
What buyers think of itA start; often accepted temporarily with a Type 2 date committedThe report most enterprise security reviews ask for
Evidence you needPolicies, configurations and the controls in place on the dateRecords of every occurrence in the period, retained so the auditor can sample

Both are examinations against the same AICPA Trust Services Criteria. Checked September 2026.

02

Which SOC 2 type should you get first?

Get a SOC 2 Type 1 first only if a deal needs a report in weeks and your controls are newly built. Otherwise go straight to a Type 2 with a three-month first window: it costs one engagement instead of two, and it produces the report buyers actually want.

A common sequence for an Indian SaaS company with US prospects: readiness for two to four months; a Type 1 at the end of readiness if sales needs something immediately; a three-month Type 2 window starting the same day; then a twelve-month period that starts when the first ends, so coverage never lapses.

03

Why a Type 2 fails where a Type 1 passed

The Type 1 asks whether the control exists. The Type 2 asks for the list of every time it should have run. Most Type 2 exceptions come from four places:

  • Quarterly tasks missed once. An access review done in three quarters of four is an exception
  • Leavers. Access removed late for one person in a sample of twenty-five
  • Emergency changes. A hotfix merged without review, never documented after the fact
  • Evidence that was not kept. The control ran, but nothing recorded it in a form the auditor can sample

The fix for all four is the same: evidence produced by the system as the control runs, kept for longer than the period. The evidence ledger keeps timestamped, hash-chained results for failing controls as well as passing ones, and the compliance as code guide covers change-management evidence from CI. TryTrustable does not hold SOC 2 or ISO 27001 itself yet: both are in progress, as the trust page says.

Questions

The things people ask us

What is the difference between SOC 2 Type 1 and Type 2?

A SOC 2 Type 1 report is an auditor's opinion on whether your system description is fair and your controls are suitably designed, as of one date. A Type 2 report covers the same, plus whether the controls operated effectively throughout a period, usually three to twelve months, tested by sampling evidence from across that period.

Do US customers accept a SOC 2 Type 1?

Some do, for a while. A Type 1 shows the controls exist and are designed sensibly, which can unblock a smaller deal or a first security review. Most enterprise buyers want Type 2 because only Type 2 shows the controls worked over time. Treat a Type 1 as a bridge to a Type 2 already scheduled, and say so.

Can we skip Type 1 and go straight to Type 2?

Yes. Nothing requires a Type 1 first. Teams that already run their controls, or whose buyers will wait, often go straight to a Type 2 with a short first window. A Type 1 is most useful when a deal needs a report within weeks and the controls have only just been built.

What is the minimum SOC 2 Type 2 observation period?

The AICPA sets no fixed minimum. First Type 2 reports commonly cover three months so that a report exists sooner; later reports usually cover twelve months, back to back, so there is no gap in coverage. Some buyers reject very short periods, so ask what your customers accept before you fix the window.

Is a Type 2 report harder to pass than a Type 1?

There is no pass mark for either, but a Type 2 is more demanding. A control that exists on the day of a Type 1 can still fail in a Type 2 when the auditor samples a quarter where it did not run. Those failures appear as exceptions in the report, where buyers read them.

How long is a SOC 2 Type 2 report valid?

Reports do not expire, but buyers treat them as current for about twelve months after the period ends. Between reports you supply a bridge letter, signed by management, stating there have been no material changes. That is why most companies run consecutive twelve-month periods once the first report is out.

Book a walkthrough

See a Type 2 population, not a screenshot.

We connect a repository and show every merged change in a period, with review and check results, as the auditor would sample it.