Two flavours of SOC 2 report. Type I and Type II. Your customer almost always wants Type II. But there is a genuine question about whether to do a Type I first as a stepping stone or go straight to Type II. This lesson walks the choice and the timing.
What each report covers
Both types are examination engagements under AT-C 205 [L3-C1]. Both test the same criteria (Common Criteria plus any optional Trust Services Criteria you have added). The difference is what the auditor concludes on.
| Report | What the auditor tests | Reporting period | Effort |
|---|---|---|---|
| Type I | Design of controls as of a specified date (a point in time) | A single date, e.g. "as of 31 March 2027" | Faster, cheaper, less evidence |
| Type II | Design of controls PLUS operating effectiveness over a specified period | A period, most commonly 6 or 12 months, e.g. "1 January 2027 to 31 December 2027" | Longer, more expensive, full-period evidence |
Why customers want Type II, not Type I
A Type I report says: on this specific day, the auditor looked at your controls and they were designed to meet the criteria. It does not say the controls actually worked on the other 364 days of the year. Your enterprise customer's VRM team knows this. They read Type I reports politely and then ask when your Type II will be ready.
A Type II report says: over this specific period, the auditor tested samples of your controls at multiple points and concluded they were operating effectively throughout. That is what evidence-based vendor risk management wants.
Some customers will accept a Type I as an interim measure while you build toward Type II, especially for smaller deals or pilot phases. Larger customers and regulated customers (finance, healthcare, US public sector) will not. They want Type II.
The typical sequence for a first-time filer
You have two viable paths.
Path A: Type I first, then Type II (the traditional path)
- Months 1 to 4: Build the control framework, policy pack, evidence collection cadence. Buy a compliance platform if you are going to (Vanta, Drata, Sprinto, Secureframe).
- Month 5: Complete a Readiness Assessment (an informal, non-attestation review by the auditor firm or an advisor). Fix everything they flag.
- Month 6: Type I audit. Auditor tests design as of the specified date. Report typically issues within 3 to 4 weeks.
- Months 7 to 12: Continue evidence collection. This is the Type II observation window.
- Month 12 or 13: Type II audit. Auditor tests both design and operating effectiveness for the period covered.
- Month 13 or 14: Type II report issued.
Path B: Skip Type I, go straight to Type II (the modern path)
- Months 1 to 3: Build the control framework and policy pack. Deploy the compliance platform. Do the Readiness Assessment.
- Months 4 to 9 (or 4 to 15): Six-month or twelve-month observation period begins. Auditor is engaged and observing but no report is issued yet.
- Month 10 (for a 6-month) or Month 16 (for a 12-month): Type II fieldwork begins.
- Month 11 or 17: Type II report issued.
How to choose between the paths
Three questions.
- Do you have a live enterprise deal that will accept a Type I as an interim? If yes, Path A gets you a Type I report in month 6 to unblock the deal, while you build toward Type II. If no, skip Type I.
- What is your cash position? Path A costs more (two audit engagements). Path B costs less (one). If you are Series A pre-Series B, Path B is often the right call.
- How mature was your security posture before you started? If your controls were already largely in place because your engineering team had discipline, Path B with a 6-month observation window is viable. If you are building from a low base, Path A gives you a checkpoint at month 6 and reduces the risk of surprises at Type II fieldwork.
The 6-month versus 12-month Type II decision
Type II reports cover a period. The AICPA does not mandate the length. In practice, most first-time filers pick 6 months. This gets you a report faster and is enough for most US enterprise customers. Subsequent Type II reports typically extend to 12 months on an annual audit cycle so the report always covers a full year.
Some large enterprise customers (Salesforce for example, when they onboard integration partners) require a 12-month Type II from day one. Ask your top three prospect customers what they need before you pick the period.
What the auditor is testing
For Type I: design. Does the control exist? Is it documented? Is the owner named? Does it match the description of the system? Sample size is typically 1 (the control exists or it does not).
For Type II: design plus operating effectiveness. Did the control operate as designed throughout the period? Sample size varies. Auditors typically sample 25 to 45 items for a control that operates continuously (like a change ticket flow), fewer for monthly controls (like a monthly access review), one for annual controls (like an annual risk assessment). Sampling methodology follows AICPA Audit Guide guidance and the auditor's own firm methodology.
Next lesson: the five Trust Services Criteria. Security as the Common Criteria mandatory, plus the four optional categories. Which to add, when, and why the decision has revenue consequences.