SOC 2 Type 1 vs Type 2: which to get
A customer puts SOC 2 in a contract, somebody forwards the clause internally, and within a day the question has narrowed to one fork: Type I or Type II, and does one have to come before the other.
A customer puts SOC 2 in a contract, somebody forwards the clause internally, and within a day the question has narrowed to one fork: Type I or Type II, and does one have to come before the other.
These are not two grades of the same report. They answer different questions, they cost different amounts of calendar time, and one has a hard floor on how fast it can possibly be produced. Picking correctly comes down to what each document asserts and what the person on the other side is actually checking.
What each report actually asserts
Both are attestation engagements performed by an independent licensed CPA firm under the AICPA's SSAE 18 standard against the Trust Services Criteria, and both have the same structure: an auditor's opinion, a management assertion, a system description, and the controls with testing results. The difference sits in the opinion.
A Type I gives an opinion on design, as of a single date. The auditor examines whether the controls you describe are suitably designed to meet the applicable criteria and were in place on one specified date. The auditor inspects your access control configuration, reads your policies, looks at the ticketing workflow, confirms the background check process exists, and forms a view on whether that design, if operated, would satisfy the criteria. What the auditor does not do is test whether you actually operated any of it.
A Type II gives an opinion on design and operating effectiveness, across a period. The auditor covers everything in a Type I, then samples evidence from throughout a stated period to test whether each control actually ran. Access reviews happened quarterly, so show four of them. Changes went through review, so here are twenty-five change tickets from across the period. The report names the period on its face, for example 1 April 2026 to 30 September 2026, and the opinion attaches to that period.
That is the whole distinction: design versus design plus operation, one date versus a span of dates. Everything else is broadly the same, including the effort of building the control environment in the first place. That difference has one consequence that catches people out: a Type I cannot produce an exception for a control you never ran, because it never looks. A Type II can, and routinely does on a first attempt.
Why a Type I unblocks a deal and a Type II proves the program works
A Type I is a deal unblocker. It is what you hand over when a contract is waiting, the customer's security team needs something now, and an interim position is acceptable. It shows you have a real control environment, that a CPA firm has looked at it, and that the remaining work is running the controls rather than inventing them.
A Type II is evidence that the program functions. Over six months, or twelve, the controls were actually performed by real people on a real schedule and a third party sampled the record and agreed. That is a materially stronger claim, and it is the one enterprise vendor risk programs are built around.
The practical read: if a specific deal is waiting and the customer will accept an interim step, the Type I has a job to do. If nothing is waiting, it is optional scaffolding and the money may be better spent going straight to Type II.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The observation window is the long pole
SOC 2 sequencing comes back to one fact: a Type II covers a period, and the period cannot be compressed, backdated, or bought. You choose the start date and the length before the window begins. Common choices:
| Window | When it fits | What you trade |
|---|---|---|
| 3 months | First report, deadline pressure, a customer who accepts a short period | Reviewers notice; few controls get sampled more than once or twice |
| 6 months | The common first-report choice | Six months of calendar before fieldwork can begin |
| 12 months | Steady state for mature programs | Longest wait, but no gap between annual reports afterward |
Three months is the shortest period most audit firms will issue a Type II over. Twelve is where most programs eventually settle, because it lines up with annual renewal and leaves no uncovered gap between consecutive reports.
The part that catches first-timers: the window has to be backed by evidence that genuinely existed during it. You cannot decide in September that your window started in March unless the controls were running in March and produced records that prove it. Access reviews never performed in Q2 cannot be performed in Q3 and presented as Q2 evidence. Auditors look at timestamps and system metadata, and a reconstructed record is both an exception and a much worse conversation than an honest one.
So the sequence is: build and turn on the controls, start the window, run them faithfully for its full length, then fieldwork, then the report. Fieldwork and reporting add roughly four to ten weeks after the window closes, depending on the audit firm's queue and how clean your evidence package is.
Total calendar for a first Type II with a six month window, from a standing start: readiness of roughly eight to sixteen weeks, six months of window, then six to ten weeks to report. Near ten to twelve months. Nothing in that sequence responds to being paid more money. The window is the long pole, and it is the reason the Type I exists at all.
What happens if you skip Type I and go straight to Type II
Plenty of companies should, and do. Going straight to Type II means you finish readiness, pick a window start date, and begin. You save the Type I audit fee and the three to six weeks of fieldwork it consumes, and your first external document is the stronger one. The risks are real but manageable.
No external check on design before you commit. With a Type I, an auditor tells you your design is sound before you spend six months operating it. Without one, a design flaw discovered in month five of the window is expensive, because the control was operating wrongly for five months and sampling will find it. Mitigation: a thorough readiness gap assessment, and a scoping conversation with the audit firm before the window starts.
Nothing to hand a customer in the meantime. For six to twelve months you have no auditor-issued document. If a deal depends on one, that is a revenue problem, not a compliance problem.
First-window exceptions. New control environments generate exceptions in their first period: a missed quarterly review, an onboarding record without a signed acknowledgement, a change deployed outside process during an incident. A Type I would not have surfaced these, so skipping it does not create them, but it does mean your first external report carries them.
If no customer is waiting and you can operate the controls faithfully from day one of the window, straight to Type II is usually the better use of money. If a deal is waiting, the Type I buys time that nothing else can buy.
The bridge letter, and what it does not cover
A Type II report covers a period that has already ended, so from the day it is issued the gap between its period end date and today grows.
A bridge letter, sometimes called a gap letter, is a short signed statement from your management covering that interval. It states the period of the last report, confirms no material changes to the control environment since that period ended, and confirms management is not aware of any control failures in the interim. Usually one page. What it is not:
- It is not an audit product. No auditor signs it, no testing supports it, no opinion attaches. It is your own management's representation.
- It does not extend the report's coverage. The opinion still covers only the stated period. A bridge letter is an assurance about the gap, not evidence about it.
- It does not stretch indefinitely. Most buyers accept a bridge letter for roughly three months past the report period, and many will take six. Past that, vendor risk programs generally want a current report. Some enterprise programs will not accept one at all.
- It cannot paper over a change. If you migrated cloud providers, changed your identity provider, acquired a company, or had a reportable incident since the period ended, the honest bridge letter says so. That is precisely the information the reader wants.
Bridge letters are routine when used for their actual purpose, smoothing the administrative gap between annual reports. They become a problem when a company leans on one to avoid commissioning a second report.
Renewal, and why year two is a different exercise
The first SOC 2 is a construction project. The second is an operations review, and the shape of the work changes.
What gets easier: the policies, control descriptions and system description exist, the auditor already understands your architecture, and everybody knows what evidence looks like. Readiness effort in year two is typically a fraction of year one. What gets harder, or at least different:
Continuity of coverage. Buyers dislike gaps between report periods. If your first report covered 1 January to 30 June, the second ideally starts 1 July, which means the second window begins before the first report is even issued. Companies that treat SOC 2 as a project rather than a program discover this when they take a two month breather and put a two month hole in their coverage history.
Longer windows. Year two is usually when a three or six month first window becomes twelve, which means four quarterly access reviews instead of one, more change tickets sampled, and more people onboarded and offboarded inside the period.
The comparison. A buyer reading your year two report often has year one in hand. An exception that appears in both reads very differently from one that was closed; a repeat finding suggests the remediation was cosmetic.
How a buyer actually reads each report
A Type I arriving in a vendor review is filed as an interim artifact. The reviewer notes that a report exists, notes that it is design only, and asks one of two questions: when does the Type II period start, and when will the report be available. In many programs the vendor is then approved conditionally with a diary entry to check back, which is exactly the job the Type I was commissioned to do.
A Type II is read to close the review. The reviewer wants a period that ended recently, an unqualified opinion, a scope covering the systems that will actually handle their data, and a manageable exceptions section. A clean Type II normally ends the security review with follow-up limited to a handful of questionnaire items.
What a security reviewer looks at first
Experienced reviewers do not read a SOC 2 report front to back. They check, roughly in this order.
- The opinion. Unqualified, qualified, adverse, or a disclaimer. This takes ten seconds and determines everything after it.
- The report type and period. Type I or Type II, and for a Type II, the exact dates. A period that ended fourteen months ago is treated as stale regardless of how clean it is.
- Scope. Which Trust Services Criteria are covered, Security alone or Security plus Availability, Confidentiality, Processing Integrity or Privacy, and which systems and entities. A report scoped to a product the reviewer is not buying does nothing for them.
- The exceptions. Section 4, where testing results live. What failed, how many instances, and what management said about it. A small number of well explained exceptions with clear remediation is normal and rarely fatal. Repeat exceptions and vague management responses generate questions.
- Complementary user entity controls. The things the report says the customer is responsible for. Reviewers check these because they create work on their side.
- Subservice organizations, and the carve-out or inclusive method. Which providers you rely on, and whether their controls were tested here or excluded.
To predict how your report will land, read your own draft in that order.
Cost and timeline consequences of each path
Audit fees are paid to the CPA firm and are separate from readiness work. On the Canadian market a Type I commonly runs roughly $15,000 to $55,000 CAD and a Type II roughly $20,000 to $100,000 CAD, driven by scope, number of criteria, system complexity, entity count and how clean your evidence is. Readiness is a separate contract with a separate provider, and tooling is a third line item. The three practical paths:
Type I, then Type II. Readiness, a Type I in three to six weeks, then the window, then the Type II. Two audit fees, but an auditor-issued document months earlier, and total calendar to the Type II is not meaningfully longer as long as Type I fieldwork runs just before or alongside the start of the window. The right path when revenue is waiting.
Straight to Type II. One audit fee, one fieldwork cycle, nothing to show for six to twelve months. Cheaper and simpler when nothing is blocked.
Type I only, indefinitely. Rarely defensible past the first year. Buyers notice a company that keeps producing design-only reports, and a second Type I invites the question of why the program has never been tested in operation.
Choosing: four questions that settle it
- Is a specific deal blocked right now, and has that customer said in writing whether a Type I is acceptable? Ask them directly. The answer decides whether the Type I fee is an investment or a donation.
- When do the controls actually start running? Not when you sign a readiness contract. The window cannot start before the controls produce evidence, and that date sets everything downstream.
- What window length can you operate honestly? A three month window you run properly beats a twelve month window with a two month hole in it.
- Who is scoping it, and is remediation priced before or after the gap is known? Nobody can price the fix before they know what is broken. A firm quoting full remediation before a gap assessment is quoting a guess.
Worth asking any provider: have they completed Canadian engagements they can show; who signs the audit and can that firm be referenced; which entity signs your contract and under which province's law; where your engagement data will be stored. If Canadian personal information is in scope, your PIPEDA obligations, and Quebec Law 25 obligations where you handle Quebec residents' data, run alongside SOC 2 rather than being satisfied by it.
Next step
For quotes from Canadian firms on either path, the get quotes form takes a few minutes and puts your requirements in front of firms that match what you asked for. There is no charge to you. Listed firms include TrazTech, which works as a readiness partner rather than an auditor; each directory listing sets out what that firm covers.
Common questions
Can we start with Type 1 and move to Type 2?
Yes, and it is the common path. Type 1 unblocks the deal in front of you, then the observation window for Type 2 starts and runs while you keep selling. The work you did for Type 1 is not wasted; the controls are the same ones being tested over time.
How long does the observation window have to be?
Three months is the shortest most auditors will issue over, and twelve is common once you are on an annual cycle. The window length is a decision you make with the auditor, and it is the single biggest driver of when the report lands.
What is a bridge letter and when do we need one?
It covers the gap between the end of your report period and the date a customer is asking. It is a statement from management, not an audit product, and it is generally accepted for three to six months. Beyond that the customer will want the next report.
Get both priced before you decide
The choice is usually settled by what your buyer will accept and when. Send your scope and compare firms that will quote the path that closes your deal.
Get matchedWhere to go from here
- The SOC 2 observation window explained. The window is what makes a Type II take months rather than weeks.
- SOC 2 audit cost. What each report costs, and why the gap is smaller than people expect.
- A customer asked for our SOC 2 report. What to say to the buyer while you are still deciding.
- SOC 2 bridge letter. How to cover the gap between reports once you have one.