Knowledge Hub

SOC 2 Type I or Type II:What your first enterprise deal actually requires

A SOC 2 report is an accountant's opinion, not a certificate. This guide explains the difference between a Type I and a Type II, why the timing of each is what really decides your choice, how to scope the Trust Services Criteria to what you have actually promised, and how to pick a CPA firm your enterprise buyer will trust.

Louis Sieg

By Louis Sieg

Founder of ReadySecGoISO/IEC 27001 Lead Auditor for UKAS/DAkkS-accredited bodies

7 min read

Your first big enterprise prospect sends over a security questionnaire, and one line stops the deal: "Provide your SOC 2 report." You don't have one yet. Now you have to pick between a Type I and a Type II, with a close date looming and no clear idea which one the deal actually needs.

Here is the short version. Your buyer almost certainly wants a Type II. You should still probably do a Type I first. And the report is only worth as much as the auditor who signs it, so that choice matters as much as the report type. The rest of this guide explains why, in plain terms, so you can spend money once and in the right order.

What a SOC 2 report actually is

SOC 2 is not a certificate. It is an attestation. An independent accountant examines how you protect customer data and then writes up what they found. That write-up is the report. There is no badge and nothing to frame. Your prospect's security team reads the report and decides whether to trust you.

The accountant who does this is a CPA, a Certified Public Accountant, and that is the important part. SOC 2 checks your security the same way a financial audit checks your books: methodically, by sampling evidence, to reach reasonable confidence that what you claim is true. That is the real difference from certifications like ISO 27001. The criteria differ too, but the bigger distinction is who runs the audit and how.

What the auditor measures against is a set of five areas called the Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. Security is always included. The other four are optional, and each one you add brings its own controls, evidence and audit hours, every year it stays in your report. So add one only when a promise you have already made requires it. An uptime commitment points at Availability, a contractual confidentiality obligation at Confidentiality.

If a prospect asks for all five, ask what they are actually worried about. It is usually one thing. And remember you produce one report, not one per customer: the same report goes to everyone who asks. Scope it to what you have genuinely promised, not to whoever asks for the most. Most companies start with Security alone, or Security with Availability and Confidentiality, and widen later if buyers keep asking.

Enterprise buyers are the ones asking. They want proof, not promises, before handing over their data. SOC 2 began as a mostly American request but is now common in Europe too.

Type I and Type II: a photo and a video

With that in place, the two report types are easy to tell apart. Think of a Type I as a photo and a Type II as a video.

A Type I is the photo. It shows that your security controls are set up correctly on one specific day. The auditor looks at your policies and settings as they stand and gives an opinion on whether they are well designed. It is a snapshot, and it says nothing about what happens the day after.

A Type II is the video. It shows your controls actually running, day after day, across a stretch of time. The auditor picks a period, usually three to twelve months, and tests evidence that the controls worked the whole way through. Not "we have a policy for reviewing access," but the actual access reviews you ran during the period, with dates and sign-offs. Buyers trust the video, because it proves you live your security rather than staging it for a day.

It comes down to timing

Before you choose between them, look at what each one costs you in calendar time, because that is usually what decides it.

The slow part is the same for both reports. Writing your policies, configuring your systems, running access reviews, setting up monitoring: that work takes most teams a few months, and neither report lets you skip it. No auditor can turn up next week and grade whatever you happen to have. There has to be something built, and running, before there is anything to look at.

Where the two differ is only what happens afterwards. A Type I can be issued soon after the controls are ready, because the auditor is judging design on a date. A Type II cannot be rushed, because the controls have to actually run before there is anything to test. A six-month Type II takes six months, and no amount of budget shortens it.

That gap is the whole decision.

Why do a Type I first

Start with the practical reason. Between the day your controls are ready and the day your first Type II lands, there are at least three months and usually six. A Type I is the only report you can put in a buyer's hands during that window. If a deal is waiting on paperwork, that on its own is often the answer.

A Type I is a cheap rehearsal before the stakes are high. It gets your auditor on board and pins down exactly what they will expect from you. It lets you hand over one clean piece of evidence for each control, which is the very thing you will then have to produce again and again across the Type II period. Far better to find a gap now, in the photo, than halfway through the video. And because auditors often price the Type II lower once they have already done your Type I, buying both usually costs only a little more than buying the Type II alone. You get a safe first run for that small difference.

What the enterprise deal really wants

So the Type I is useful, but it is not what closes the deal. What the enterprise buyer wants is a Type II. Some go further and ask for a period of at least six months, though the shortest a Type II can cover is three.

Here is the part worth remembering. That request is usually more flexible than it looks. A line in a questionnaire is a starting position, not a locked gate, and it does not become a hard rule just because someone typed it into a spreadsheet. So talk to the buyer. A normal conversation goes like this: you tell them you will send a Type I now, so they have a report in hand, and then run a six-month Type II, which gives them more evidence and stronger assurance than a rushed three-month one. Most buyers say yes, because they end up with better proof, not less. After that first six-month report, you move to a twelve-month cycle and stay there.

Choosing the auditor

The report type is only half the decision. The other half is who signs it, and first-timers often forget it.

You cannot fail a SOC 2 audit the way you fail an exam, because there is no pass mark. The auditor just states an opinion, and there are four. An unqualified opinion means your controls held up. A qualified opinion means they mostly held up, with a few exceptions noted. An adverse opinion means they did not. A disclaimer means the auditor could not gather enough to judge at all. You are aiming for an unqualified opinion, but a qualified one can still be perfectly usable, as long as you can explain what the exception was and what you did about it.

Because there is no badge, the report's value comes entirely from the firm that signs it. Any accountant can technically write a SOC 2 report. You want one your buyer will actually trust. In practice that means a CPA firm registered with the AICPA, the American Institute of Certified Public Accountants, and active in its peer review program, where other auditors regularly check that its audits were done properly. Both facts are public, so look them up before you sign. You can confirm a firm's license and standing on CPAverify. You do not need a Big Four name. They are excellent and expensive but a smaller registered firm is fine. What you should not do is pick on price alone, because a cheap report from a firm the buyer does not recognize is worth very little.

Do's and don'ts

  • Do ask the buyer what they actually need before you scope anything, and treat the period as negotiable.
  • Do run a Type I first as a low-stakes rehearsal.
  • Do check that your auditor is AICPA-registered and peer-reviewed before you sign.
  • Do start the security work now, because it is the slow part.
  • Don't pick an auditor on price alone.
  • Don't treat the questionnaire wording as final.
  • Don't promise a Type II faster than its period allows, because a six-month report takes six months.
  • Don't let your controls lapse once the audit is over, or the next report will show it.

After your first report

Getting the first report is not the finish line, so plan for what comes next. A SOC 2 report covers a set period and is generally trusted for about twelve months after it ends. In the gap between that end date and the day a new prospect asks, buyers often want a bridge letter. That is a short note signed by your own management confirming nothing important has changed since the report closed. It buys you a few months, but it is your word, not the auditor's, so it does not replace a fresh audit. This is why the Type II becomes a yearly rhythm. Your first report wins the deal. Keeping the controls running is what secures every report after it and keeps them clean.

Where to start

If a SOC 2 request just landed, the order matters more than the speed. Begin by asking the buyer which report they need and over what period, because that single answer shapes everything else and is often negotiable. Once you know the target, line up a credible auditor, a CPA registered with the AICPA and active in its peer review program, since the report is only worth what their name carries. With the auditor chosen, scope your report to Security plus only what you have actually promised customers, and start the security work straight away, because it is the part that takes longest. From there you run the ladder: a Type I first, then a six-month Type II, then a twelve-month cycle each year.

What's next?

Two things are worth getting right before fieldwork starts. The first thing auditors ask for is a list of what you have and who has access to it, so your asset inventory needs to hold up. And because a Type II tests incidents across the whole period, not on one date, you need an incident process you'll actually follow rather than one that only exists on paper.

ArticleGlobalGovernance & ComplianceSOC 2
SOC 2 Type I & Type II

Not sure which SOC 2 report your deal actually needs?

A six-month Type II takes six months, and no budget shortens it. We help you scope the right report, get the controls running, and pick an auditor your buyer will recognise.

  • By active auditors
  • 50+ Compliant clients
  • Type I to Type II in one plan
Book a free consultation