SOC 2 Type 1 versus Type 2

How Type 1 (design at a point in time) and Type 2 (operating effectiveness over a period) differ, which customers usually want, and how the review period sets the calendar.

The short version

A Type 1 report says whether controls are suitably designed and in place on a single date. A Type 2 report also tests whether those controls operated as described over a review period, commonly three to twelve months.

Most customers ultimately want Type 2. Many will accept a Type 1 now with a Type 2 to follow if you ask the security or vendor-risk team, not only the salesperson who relayed the request. The calendar is set by the review period, not by the week of fieldwork.

Confirm three things in writing before you plan:

  1. Type 1, Type 2, or Type 1 now and Type 2 later.
  2. Which Trust Services Categories they expect beyond Security.
  3. How recent the report must be, and whether they accept a bridge letter for the gap.

What each report actually tests

SOC 2 is an examination by a licensed CPA firm under AICPA attestation standards, not a certification. Both report types include the auditor’s opinion, management’s assertion, and a system description.

  • Type 1 evaluates design and implementation at a point in time. It can be issued as soon as the controls exist and the description is stable. It does not prove the controls ran next month.
  • Type 2 adds tests of operating effectiveness over a defined period. Evidence has to exist for that whole period. A control turned on the week before fieldwork does not have a period to test.

Exceptions found during Type 2 testing appear in the report even when the overall opinion is unqualified (clean). A qualified opinion means the auditor found problems material to one or more criteria.

How to choose

  1. Ask who will read the report. Security and vendor-risk teams almost always mean SOC 2, and they almost always mean Type 2. Finance and financial-statement auditors may mean a SOC 1 report, which covers controls relevant to a customer’s financial reporting and is a different examination.
  2. Ask whether a Type 1 will hold the deal. That is a normal request. If the answer is yes, start evidence collection on day one of Type 1 so the Type 2 period can begin immediately after.
  3. Look at control maturity. If policies are unwritten, access reviews have never run, and logging is incomplete, a Type 2 period cannot start honestly. Close those gaps, issue Type 1 if the customer will take it, then start the period.
  4. Price and time both move with type. A Type 1 examination commonly costs $7,000 to $40,000. A typical Type 2 costs $20,000 to $75,000. A first Type 1 often lands two to four months after readiness starts. A first Type 2 adds the review period, so six to twelve months to a report in hand is realistic. See How much does SOC 2 cost?.

If nobody has asked for a report yet, you may not need either type this quarter. A completed questionnaire or a recent penetration test sometimes clears a smaller deal. Several customers asking, or one large one making it a contractual condition, is usually the business case for starting.

What to do now

  1. Get the requirement in writing from the customer’s security, procurement, or vendor-risk team.
  2. If they said “SOC report” without a number, confirm SOC 1 versus SOC 2 and Type 1 versus Type 2.
  3. Engage a licensed CPA firm early. Their view on scope and period length shapes the plan, and independence rules mean the consultant who builds the controls should not be the firm that opines on them.
  4. If Type 2 is required and controls are not yet running, ask whether Type 1 now will hold the deal, and start leaving evidence the day controls go live.
  5. Read the SOC 2 page for the rest of the questions to ask, then follow SOC 2 for criteria and program updates.

Published September 3, 2026.