GetSOC2

SOC 2 Type 1 vs Type 2: which to get

A Type 1 report tests whether your controls were designed properly on one date. A Type 2 tests whether they actually worked over a period. The period is the whole difference, and it is the part you cannot rush.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

A SOC 2 Type 1 report gives an auditor's opinion on whether your controls were suitably designed as of a single date. A SOC 2 Type 2 report gives an opinion on whether those same controls also operated effectively across a period of time, usually three to twelve months. Type 2 is what buyers want. Type 1 exists mainly to buy you time while the period for the Type 2 runs.

If a customer has asked for SOC 2 without saying which, they mean Type 2.

The difference in one table

SOC 2 Type 1 compared with Type 2
Type 1Type 2
Question answeredAre the controls designed to meet the criteriaWere they designed properly and did they operate
CoversOne dateA period, typically 3 to 12 months
Auditor testsDesign, by inspecting configuration and documentsDesign and operating effectiveness, by sampling across the period
Time to obtain3 to 6 weeks once you are readyWindow length plus 4 to 10 weeks of fieldwork and reporting
Fee, CAD$15,000 to $55,000$20,000 to $100,000
Buyer reactionAccepted as an interim step, sometimes with conditionsCloses the security review
Can be repeatedRarely worth it more than onceAnnually, indefinitely

The observation window is the whole point

The observation window is the period a Type 2 report covers. You pick the start date and the length, then the auditor samples evidence from inside it. A control that was performed diligently for the last three weeks and ignored for the previous eleven months will produce an exception, because sampling looks across the whole window.

Three months is the shortest window most auditors will issue a Type 2 over, and it is the normal choice for a first report. Twelve months is the steady state that mature companies settle into, because it lines up with annual renewals and leaves no gap between reports.

Choosing a first observation window
WindowWhen it fitsTrade-off
3 monthsFirst report, deal pressure, controls only recently in placeSome enterprise buyers ask why it is short, and you repeat the audit sooner
6 monthsA middle path when controls have been running a whileCosts slightly more to audit than three months
12 monthsRenewal years, and companies with no immediate deadlineA year before you have anything to show a buyer

You cannot backdate a window

The window can only cover time during which the controls existed and you have evidence for them. A company that implements access reviews in March cannot run a window from January. This is the single most common reason a SOC 2 timeline slips, and it is why the useful first move is to turn the controls on now, even before you have chosen an auditor.

When a Type 1 is the right call

A Type 1 is worth its fee in one situation: a contract is waiting, the buyer will accept a Type 1 plus a dated commitment to a Type 2, and the revenue at stake exceeds the extra cost of running two engagements. That situation is common enough that Type 1 reports are a normal part of the market.

It is also reasonable when your control environment is new and you want an auditor's read on the design before you commit to a window. A Type 1 that finds a design flaw in February is much cheaper than a Type 2 that finds the same flaw in November, after eleven months of evidence collected against a control that was never going to satisfy the criteria.

When to skip it

Skip the Type 1 when no deal is waiting on it. Doing both in one year costs more in total than going straight to Type 2, and a Type 1 has no standing value once the Type 2 exists. If your buyer's timeline is nine months out, put the Type 1 fee into readiness work and start a longer window instead.

Also skip it if the buyer has already said a Type 1 will not satisfy them. Some enterprise security teams and most financial services buyers accept only Type 2, and paying for a Type 1 to hand to a buyer who has ruled it out is straightforwardly wasted money. Ask before you scope.

The usual sequence, with dates

Here is how a company starting in January with a customer asking for a report typically runs it.

A realistic first-year SOC 2 sequence
WhenWhat happens
JanuaryConfirm with the customer which report and which criteria. Scope the system. Start the gap assessment.
February to AprilRemediate. Turn on the controls. Book the penetration test.
MayType 1 fieldwork against a date in May, if a deal needs it.
JuneType 1 report issued. Observation window for the Type 2 starts.
June to AugustThree month window. Evidence collected consistently, not in a burst at the end.
SeptemberType 2 fieldwork.
October or NovemberType 2 report issued.

Without the Type 1 detour, the same company reaches a Type 2 report at about the same time, having spent less. The Type 1 buys a document to show a customer in June, and that is its entire value.

Bridge letters and the gap between reports

A Type 2 report covers a period that ends on a date, and a buyer reading it in month four after that date will ask what happened since. The answer is a bridge letter: a short statement from management confirming that no material changes have occurred to the control environment since the period end. It is written by you, not the auditor, and buyers generally accept it for three to six months.

Beyond about six months a bridge letter starts getting questioned, which is the practical reason the audit becomes annual.

What each costs in Canada

Canadian dollars, ranges, Security criteria only. A Type 1 runs roughly 60 to 75 percent of the Type 2 fee for the same scope, because the auditor tests design but not operation.

Type 1 and Type 2 audit fees in Canada, CAD
Company sizeType 1Type 2Both in year one
Under 25 staff$15,000 to $25,000$20,000 to $35,000$32,000 to $55,000
25 to 100 staff$20,000 to $35,000$30,000 to $60,000$45,000 to $85,000
Over 100 staff$30,000 to $55,000$45,000 to $100,000$70,000 to $140,000

Doing both is cheaper than two separate engagements because the auditor reuses the system description and much of the design testing, which is why the combined column is less than the sum. The full cost picture including readiness, platform and internal hours is on the SOC 2 cost page.

Preparing for either one

The preparation is identical up to the point where the window starts. Scope the system, run a gap assessment against the Trust Services Criteria, remediate, and get evidence collection into a routine that survives a busy quarter. Readiness material is on SOC2Prep, and the penetration test your auditor will expect is covered on GetPentest.

Get quotes for both

Ask Canadian firms to price a Type 1 and a Type 2 against the same scope, then decide with real numbers rather than ranges.

Get matched

Common questions

Do we need a Type 1 before a Type 2?

No. You can go straight to a Type 2 and many companies should. A Type 1 is worth doing only when a customer will accept it as an interim step and there is revenue waiting on it, or when you want an auditor to check your control design before you commit to an observation window.

How long does the SOC 2 observation window have to be?

Three months is the shortest most auditors will issue a Type 2 over. Six and twelve months are the other common choices. Twelve is the usual steady state because it leaves no gap between annual reports. You choose the length before the window starts, and you cannot shorten it afterwards.

Will a customer accept a Type 1?

Often, as an interim step with a dated commitment to a Type 2. Enterprise security teams and financial services buyers are the most likely to insist on Type 2. Ask the specific customer before you scope anything, because the answer decides whether the Type 1 fee is an investment or a waste.

Can we cover a period before the audit started?

Only if the controls existed and produced evidence during that period. The window has to be backed by real records, so a company that implemented its controls in March cannot run a window from January. This is why turning controls on early matters more than choosing an auditor early.

What is a bridge letter?

A short statement from your management confirming no material changes to the control environment since the report period ended. It covers the gap between your last report and your next one. Buyers typically accept it for three to six months, after which they want a current report.

Does a Type 2 report ever expire?

Not formally, since it describes a period that has already happened. In practice buyers treat a report as stale once the period end date is more than twelve months old, and many vendor management programs enforce that automatically at renewal.