Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

SOC 2 Type I or Type II — which report do you need?

Last verified

Type I reports whether controls are suitably designed at a point in time. Type II reports whether they also operated effectively across a review period, commonly three to twelve months. Most enterprise buyers ask for Type II; Type I is an interim artefact, not lighter assurance.

SOC 2 Type I versus Type II, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.

This is the difference, not YOUR choice

Audience: a CTO, CISO, founder, engineering lead, compliance owner, auditor, or investor choosing a first report. This page explains the two report types and how the observation period works. It does not determine that YOU need SOC 2, does not set YOUR review period, and does not issue a SOC 2 report. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor.

SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report, and no statute tells you which type to get. Your buyer's questionnaire and your contract do. "SOC 2 certified" is a misnomer either way — there is no SOC 2 certificate for a Type I or a Type II, only a practitioner's report with an opinion.

Type I addresses the design of controls at a point in time. Type II addresses operating effectiveness over a review period. Both are examinations under AT-C section 205, performed by the same kind of firm, against the same criteria you put in scope. The difference is what the auditor tests and therefore what the opinion covers. Last verified 10 September 2026. Not legal advice.

Comparison table

The rows below are the differences that change a decision. Labels mark what is an attestation-standard requirement, what is best practice, and what is only a market observation.

Type I versus Type II (paraphrase of the attestation standards plus labelled market observation; not legal advice)
DimensionType IType IIKind of text
What the opinion coversFairness of the description and suitability of control design as of a specified date.The same, plus whether controls operated effectively throughout a specified period.Attestation-standard requirement — AT-C section 205 distinguishes design from operating effectiveness.
Time dimensionA single point in time — "as of 30 June 2026".A period — "1 January 2026 through 30 June 2026".Attestation-standard requirement.
Testing performedInquiry, inspection, and observation to evaluate design. No sampling across a population of events.Design work plus tests of operating effectiveness, including sampling from populations spanning the period.Attestation-standard requirement — the practitioner selects procedures; sampling is their judgement.
Evidence needed from youCurrent policies, configurations, and a description you can stand behind.Evidence generated continuously across the whole period: tickets, reviews, logs, approvals with dates inside the window.Attestation-standard requirement that evidence support the period; how you keep it is best practice.
What buyers commonly acceptOften accepted as an interim step, sometimes with a commitment to a Type II by a stated date.The usual enterprise procurement expectation.Market observation — not a rule, and not a promise about YOUR deal.
Renewal rhythmNot a cycle. A Type I is a one-off snapshot.Commonly repeated annually so periods abut with little or no gap.Market observation — no attestation standard sets a renewal cadence.
Failure modeDesign looks fine, so nothing proves the control ever ran.Controls ran but evidence for part of the period is missing, producing exceptions.Best practice — plan evidence capture before the period opens, not during fieldwork.

Decision path

Walk this in order. It is a decision aid, not a determination, and the first question outranks the rest: what does the buyer actually require in writing?

  • Does a named customer or contract specify a report type or a period length? If yes, that answer wins. Market observation: procurement teams rarely negotiate this away.
  • Is the deal blocked right now, with no report of any kind? A Type I can unblock a signature while a Type II period runs. Market observation, not a guarantee your buyer accepts it.
  • Have the controls in scope actually been running, with evidence, for several months already? If yes, go straight to Type II — a Type I first would spend money on an artefact you will replace.
  • Were controls stood up last month? A Type II period starting now will not produce a report until the period closes and fieldwork completes. Choosing Type I is honest sequencing, not a shortcut.
  • Are you adding optional Trust Services Criteria categories (Availability, Confidentiality, Processing Integrity, Privacy)? Each one widens both types. Decide categories before type.
  • Is anyone promising a customer a date? Do not promise a report date before a licensed CPA firm has confirmed a fieldwork slot. SRM recommendation.

Observation-period mechanics

The review period — usually called the observation period — is the window the Type II opinion covers. Its mechanics cause most of the surprises in a first examination. Last verified 10 September 2026.

  • Periods are commonly three, six, nine, or twelve months. Three to twelve months is a typical market observation, not a rule set by any attestation standard; the practitioner and the buyer's expectations drive it.
  • A short first period is a common bridge to an annual cycle: run a shorter window to get a report in hand, then extend to twelve months at renewal. Market observation.
  • Evidence must exist for the whole period, not just its end. A control implemented halfway through will be tested against a population that includes the half where it did not run. Attestation-standard requirement in effect, since operating effectiveness is tested across the period.
  • The report arrives after the period ends, once fieldwork and drafting finish. The report date is not the period end date. Attestation-standard requirement that the practitioner report on a completed period.
  • Periods that abut cleanly year over year avoid coverage gaps a vendor-risk reviewer will ask about. Best practice.
  • A bridge letter — sometimes called a gap letter — is a management-signed statement covering the time between the period end and the buyer's review date, usually confirming no material change to the control environment. It is a management representation, not an auditor's opinion, and no attestation standard obliges anyone to accept one. Market observation plus best practice, never a legal requirement.

Kinds of text on this page

Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.

How to read the claims on this page (not a ranking; not legal advice; last verified 10 September 2026)
Kind of textWhat it meansWhat it is not
Attestation-standard requirementSSAE 18 — AT-C sections 105 and 205 — governs how the CPA firm plans, performs, and reports the examination.Not a statute, and it binds the practitioner rather than you.
Trust Services Criteria referenceA pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100.Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase.
Best practiceWhat experienced practitioners commonly do to be ready and to keep a period evidenced.Not required by any attestation standard. Skipping it is not an exception.
Market observationWhat buyers, contracts, and firms are commonly observed to do — including typical period lengths.Not a rule, not a quote, and not a promise about YOUR deal, timeline, or price.
SRM recommendationSomething this product suggests doing.Not a legal requirement, not an attestation requirement, and not an audit opinion.

What to do now

Sequence the decision so you do not pay for an artefact you will discard, and do not promise a date you cannot hold.

  • Get the buyer's requirement in writing before choosing a type. Ask specifically whether a Type I plus a committed Type II date is acceptable.
  • Fix the criteria categories in scope first. Type choice is cheap to change; scope is not.
  • Pick a period start date you can actually evidence from day one, then verify a week later that evidence is really landing.
  • Ask candidate CPA firms for their fieldwork lead time and report turnaround before you commit to a period end.
  • If you go Type I first, write down internally that it is a snapshot of design, so nobody in sales describes it as covering a period.
  • Plan the bridge-letter question early: know that it is a management representation your buyer may or may not accept.

Checklist

A pre-decision question list, labelled by kind of text. Not an audit programme, not a determination.

  • Is the required report type documented by a customer or contract? Market observation.
  • For Type II, is the period start and end written down and agreed with the CPA firm? Attestation-standard requirement that the report state the period.
  • Can we produce dated evidence for every in-scope control from the first day of the period? Attestation-standard requirement that operating effectiveness be tested across the period.
  • Do we know which populations the auditor will sample from, and can we produce them completely? Attestation-standard requirement — completeness of populations is tested.
  • Have we avoided promising a report date before fieldwork is booked? SRM recommendation.
  • Do we understand that a bridge letter is our representation and not an opinion? Best practice.
  • Is a named human accountable for keeping the period evidenced, not just for the kickoff? SRM recommendation.

Where this shows up in ShipReady Metrics

The bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus. Its control-set is a starter subset — an illustrative readiness mapping to be tailored by a compliance owner, not the criteria themselves. Readiness in this product is not an attestation opinion, and a green readiness view does not mean a period is evidenced.

If you already have a session: evidence collection runs continuously, which is what a Type II period needs — dated artefacts across the window rather than a screenshot taken the week before fieldwork. Evidence review with the met-verdict overlay records a human's judgement on whether an item supports a control. The crosswalk maps SOC 2 to this product's canonical controls by criteria series reference only, without reproducing Trust Services Criteria text. ShipReady Passport and the auditor share token hand a reviewer a scoped view; that share is not a report and not a bridge letter.

The obligation map lists frameworks the organisation has marked in-scope, including soc2 if that mark is set. Marking soc2 in-scope is not a determination that a buyer requires SOC 2 and is not a scope or period decision. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.

Primary sources (last verified 10 September 2026)

Every claim about the examination on this page comes from one of these. Period lengths and buyer expectations are labelled as market observation because no attestation standard fixes them.

AICPA Trust Services Criteria, TSP section 100 — 2017 Trust Services Criteria with the 2022 revised points of focus. Proprietary AICPA material: cited by reference and paraphrased, never reproduced. AICPA attestation standards SSAE 18, AT-C section 105 and AT-C section 205, which distinguish an examination of design from an examination of operating effectiveness over a period. AICPA SOC 2 guidance for service organisations. These are not a complete list, and none of them is legal advice.

The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.

Frequently asked questions