Live Founding Cohort open, limited seats remaining Back to main site →

Type I vs Type II — which to start with

Type I tests design at a point in time. Type II tests design plus operating effectiveness over a period, usually six to twelve months. Your customer almost always wants Type II. This lesson walks the choice and the timing.

Free preview 9 min read Verified
Legal basis
SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only). Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.

Two flavours of SOC 2 report. Type I and Type II. Your customer almost always wants Type II. But there is a genuine question about whether to do a Type I first as a stepping stone or go straight to Type II. This lesson walks the choice and the timing.

What each report covers

Both types are examination engagements under AT-C 205 [L3-C1]. Both test the same criteria (Common Criteria plus any optional Trust Services Criteria you have added). The difference is what the auditor concludes on.

ReportWhat the auditor testsReporting periodEffort
Type IDesign of controls as of a specified date (a point in time)A single date, e.g. "as of 31 March 2027"Faster, cheaper, less evidence
Type IIDesign of controls PLUS operating effectiveness over a specified periodA period, most commonly 6 or 12 months, e.g. "1 January 2027 to 31 December 2027"Longer, more expensive, full-period evidence

Why customers want Type II, not Type I

A Type I report says: on this specific day, the auditor looked at your controls and they were designed to meet the criteria. It does not say the controls actually worked on the other 364 days of the year. Your enterprise customer's VRM team knows this. They read Type I reports politely and then ask when your Type II will be ready.

A Type II report says: over this specific period, the auditor tested samples of your controls at multiple points and concluded they were operating effectively throughout. That is what evidence-based vendor risk management wants.

Some customers will accept a Type I as an interim measure while you build toward Type II, especially for smaller deals or pilot phases. Larger customers and regulated customers (finance, healthcare, US public sector) will not. They want Type II.

The typical sequence for a first-time filer

You have two viable paths.

Path A: Type I first, then Type II (the traditional path)

  1. Months 1 to 4: Build the control framework, policy pack, evidence collection cadence. Buy a compliance platform if you are going to (Vanta, Drata, Sprinto, Secureframe).
  2. Month 5: Complete a Readiness Assessment (an informal, non-attestation review by the auditor firm or an advisor). Fix everything they flag.
  3. Month 6: Type I audit. Auditor tests design as of the specified date. Report typically issues within 3 to 4 weeks.
  4. Months 7 to 12: Continue evidence collection. This is the Type II observation window.
  5. Month 12 or 13: Type II audit. Auditor tests both design and operating effectiveness for the period covered.
  6. Month 13 or 14: Type II report issued.

Path B: Skip Type I, go straight to Type II (the modern path)

  1. Months 1 to 3: Build the control framework and policy pack. Deploy the compliance platform. Do the Readiness Assessment.
  2. Months 4 to 9 (or 4 to 15): Six-month or twelve-month observation period begins. Auditor is engaged and observing but no report is issued yet.
  3. Month 10 (for a 6-month) or Month 16 (for a 12-month): Type II fieldwork begins.
  4. Month 11 or 17: Type II report issued.

How to choose between the paths

Three questions.

  1. Do you have a live enterprise deal that will accept a Type I as an interim? If yes, Path A gets you a Type I report in month 6 to unblock the deal, while you build toward Type II. If no, skip Type I.
  2. What is your cash position? Path A costs more (two audit engagements). Path B costs less (one). If you are Series A pre-Series B, Path B is often the right call.
  3. How mature was your security posture before you started? If your controls were already largely in place because your engineering team had discipline, Path B with a 6-month observation window is viable. If you are building from a low base, Path A gives you a checkpoint at month 6 and reduces the risk of surprises at Type II fieldwork.

The 6-month versus 12-month Type II decision

Type II reports cover a period. The AICPA does not mandate the length. In practice, most first-time filers pick 6 months. This gets you a report faster and is enough for most US enterprise customers. Subsequent Type II reports typically extend to 12 months on an annual audit cycle so the report always covers a full year.

Some large enterprise customers (Salesforce for example, when they onboard integration partners) require a 12-month Type II from day one. Ask your top three prospect customers what they need before you pick the period.

What the auditor is testing

For Type I: design. Does the control exist? Is it documented? Is the owner named? Does it match the description of the system? Sample size is typically 1 (the control exists or it does not).

For Type II: design plus operating effectiveness. Did the control operate as designed throughout the period? Sample size varies. Auditors typically sample 25 to 45 items for a control that operates continuously (like a change ticket flow), fewer for monthly controls (like a monthly access review), one for annual controls (like an annual risk assessment). Sampling methodology follows AICPA Audit Guide guidance and the auditor's own firm methodology.

Next lesson: the five Trust Services Criteria. Security as the Common Criteria mandatory, plus the four optional categories. Which to add, when, and why the decision has revenue consequences.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
AICPA AT-C Section, AT-C 205 Examination Engagements (Examination engagement standard (SOC 2)) L3-C1
AT-C 205 governs Examination Engagements. This is the standard SOC 2 examinations are performed under. The practitioner obtains sufficient appropriate evidence to conclude on management assertion that (a) description of the service organization system is accurate (both Type I and Type II) and (b) controls are suitably designed (Type I) and operating effectively (Type II) throughout the specified period.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The story of SOC 2
Module 2: Common Criteria Part 1: CC1 to CC5, governance and risk
  • CC1 Control Environment: tone at the top, board oversight, org structure
  • CC2 Communication and Information: internal comms, external commitments, the Trust Portal
  • CC3 Risk Assessment: asset inventory, threat identification, likelihood, impact, residual risk
  • CC4 Monitoring Activities: continuous monitoring, deficiency reporting, remediation tracking
  • CC5 Control Activities: selection, technology-general controls, segregation of duties
Module 3: Common Criteria Part 2: CC6 to CC9, operations
  • CC6 Logical and Physical Access Controls: IAM, MFA, provisioning, remote access, keys
  • CC7 System Operations: detection tooling, incident response, backup and recovery
  • CC8 Change Management: dev lifecycle, code review, testing, approval, deployment, rollback
  • CC9 Risk Mitigation: vendor risk, third-party risk, business continuity, insurance
  • The 2022 Revised Points of Focus: what auditors now specifically look for
Module 4: The optional four Trust Services Criteria
  • Availability TSC — the uptime criterion
  • Processing Integrity TSC — the transaction criterion
  • Confidentiality TSC — the trade-secret criterion
  • Privacy TSC — and the GDPR / DPDP Act 2023 / CCPA overlap
  • TSC decision matrix — which to add and when, by industry
Module 5: The Control Framework and Policy Pack
  • The Control Matrix — mapping TSC clauses to controls, owners and evidence
  • The 10-Policy Pack — draft skeletons your auditor will ask to see
  • Risk Assessment Framework — asset, threat, likelihood, impact, residual risk
  • Vendor Risk Register — the working register your auditor tests against CC9.2
  • Incident Response Plan and Tabletop Runbook
Module 6: Evidence Collection Operating Model
  • Continuous vs point-in-time evidence, and how the auditor samples
  • Buy vs Build: Vanta, Drata, Sprinto, Secureframe, Comply.ai, or in-house
  • Evidence types: what makes evidence auditor-quality vs unusable
  • The Evidence Collection Calendar, a twelve-month template
  • Audit trail hygiene: organising the evidence pack for the first 48 hours of fieldwork
Module 7: Selecting the Auditor and the Audit Cycle
  • What makes a SOC 2 auditor: licensing, independence, sector experience
  • The Auditor RFP and Selection Matrix: running Big 4 against mid-tier against boutique
  • The SOC 2 Engagement Letter, full SSAE 18 template
  • The audit cycle week by week, kickoff to report issuance
  • Auditor opinion types: unqualified, qualified, adverse, disclaimer
Module 8: Post-Audit and Continuous Compliance
  • Publishing the SOC 2 report on your customer trust portal
  • Answering vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report
  • The annual re-audit cycle and the bridge letter
  • Adding TSCs beyond Security: Availability, then Confidentiality, then Privacy
  • SOC 2 to ISO 27001 upgrade path and emerging AI controls