Decision guide
SOC 2 Type 1 vs Type 2
A Type 1 asks whether your controls are designed correctly on one specific date. A Type 2 asks whether they actually ran, correctly, across a period of months. Same criteria, same controls, one added dimension: time. That dimension is the whole difference in cost, effort, and credibility.
Side by side
| Type 1 | Type 2 | |
|---|---|---|
| Question answered | Are the controls suitably designed? | Did the controls also operate effectively? |
| Coverage | A single point in time | A period, commonly 3 to 12 months |
| How the auditor tests | Inspects the design and confirms the control exists | Samples instances across the period and tests each one |
| Evidence needed | A snapshot: current configuration, approved policies, the control in place | Records spanning the whole window: every access review, every offboarding, every training completion |
| Time to report | Weeks after you are ready | The window, plus fieldwork |
| Relative cost | Lower examination fee, less evidence work | Higher fee, and continuous evidence effort through the window |
| What a buyer concludes | "They built it correctly" | "They actually run it" |
| Failure mode | A control that looks good on paper and is never run | A gap in the middle of the window that cannot be backfilled |
Type 1 proves the fire extinguisher is mounted on the wall. Type 2 proves it was inspected every month for six months. Buyers want the second one and will accept the first one while you earn it.
Which is your customer actually asking for?
Before planning anything, ask them directly. Security questionnaires are frequently copied between companies and often ask for more than the reviewer needs. Four questions to put to your customer:
- Type 1 or Type 2? Many requests say only "SOC 2".
- Which categories? Security alone is the default and usually sufficient. Availability and Confidentiality come up when your contract commits you to them.
- By when, and for what? A report needed for a security review at contract signature is a different deadline from one needed at renewal.
- Will a Type 1 with a dated Type 2 commitment unblock this? This is the question that most often turns a nine-month problem into a three-month one.
Security reviewers know a first-time vendor cannot produce a Type 2 covering a period that has not happened. The common outcome is conditional approval, sometimes written into the contract as a Type 2 by a specific date.
Why Type 1 comes first
Three reasons, in order of practical weight:
- It unblocks revenue now. The reason you are reading this is usually a contract. A Type 1 can be in hand roughly ten to twelve weeks from kickoff. A Type 2 cannot beat its own window.
- It de-risks the Type 2. A Type 1 is a full dress rehearsal with a real auditor. Anything they push back on gets fixed before the window opens, rather than becoming an exception sampled across six months.
- It sets the window's start line correctly. Opening an observation window before controls are in place guarantees exceptions in the early months. Type 1 first means the window starts on a clean baseline.
The exception: a company that has genuinely been operating mature controls for six months or more, with the records to prove it, can reasonably go straight to Type 2. That is rare at seed stage, and it is worth being honest with yourself about whether the records exist rather than assuming they do.
What the Type 2 window actually demands
This is the part that surprises teams who found the Type 1 straightforward. A Type 2 auditor samples across the period. If your control says quarterly access reviews and the window is six months, they will ask for two reviews, with dates, with evidence, with the reviewer named. A missing one is an exception, and no amount of remediation afterwards removes it from that window.
What has to keep running, every period, without exception:
| Control area | Cadence | What the auditor will ask for |
|---|---|---|
| Access reviews (AWS, source control, core SaaS) | Quarterly, usually | Signed review records for every period in the window |
| Offboarding | Per departure | Tickets with timestamps proving the stated SLA was met, for every leaver |
| Onboarding | Per hire | Completed checklists, training records, policy acknowledgements, for every joiner |
| Security awareness training | Annual plus onboarding | Completion records covering the full personnel population |
| Change management | Continuous | A sample of production changes showing review and approval |
| Vulnerability management | Your stated cadence | Scan results and remediation records proving the cadence held |
| Incident response | Per incident, plus annual tabletop | Incident records and postmortems, or a documented attestation of none |
| Backups | Continuous, with a tested restore | Backup configurations and at least one documented restore test |
Every one of those is a calendar item with an owner. That is precisely what the Type 2 Window Package carries, and it is why "we got the Type 1, we are done" is the most expensive sentence in this process.
The mistake that qualifies more reports than weak security
Over-writing your controls. A policy that promises patching within 24 hours when your team patches monthly does not make you safer. It creates an exception in every single sample the auditor pulls. The same applies to "reviews are performed monthly" when you mean quarterly, or "all access is reviewed" when you mean production access.
Right-sizing stated controls to real, defensible practice costs nothing and is the highest-leverage risk reduction available before a Type 2 window opens. Write what you do, do what you write, and make what you do good enough. In that order.
Frequently asked questions
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 reports on whether controls are suitably designed as of a single date. A Type 2 reports on whether those same controls also operated effectively across a period, commonly three to twelve months. Same criteria and same controls; the difference is whether the auditor tests design only, or design plus operation over time using sampling.
Should we get Type 1 or Type 2 first?
Type 1 first, for almost every startup. It unblocks the deal within weeks of being ready, it de-risks the Type 2 by surfacing auditor pushback early, and it lets the observation window start on a clean baseline.
Will an enterprise customer accept a Type 1?
Usually, when it comes with a dated commitment to a Type 2. Ask the question explicitly rather than assuming the strictest reading of their questionnaire. Conditional approval is the common outcome for a first-time vendor.
Does a SOC 2 report expire?
Not formally, but practically yes. Buyers generally want a Type 2 whose period ended within the last twelve months. A bridge letter from management covers the gap between a report's period end and a customer's later reliance date. Treat SOC 2 as an annual cycle.
Can we go straight to Type 2 to save money?
You can, and it does save one examination fee. It costs you the entire window with nothing to show a blocked customer, and it removes the rehearsal that catches auditor pushback before it becomes an exception. If there is no deal waiting and your controls have genuinely been running with records, it is a defensible choice. Otherwise the saving is false economy.
Get the Type 1 in hand, then start the window on day one
We take you from first scan to audit-ready in six to eight weeks, hand you to an independent CPA firm, and then run the Type 2 observation window: automated evidence, every review and test on schedule, auditor liaison through fieldwork.
Book a 30-minute scoping callIf your Type 1 opinion from one of our partner audit firms is qualified on a control we implemented, we keep working at no charge until it is clean.