SOC 2 Type 1 vs SOC 2 Type 2
A SOC 2 Type 1 report attests to control design at a point in time; a Type 2 report additionally attests to operating effectiveness over a period (typically 6–12 months).
A SOC 2 report is an attestation report issued by a licensed CPA firm under AICPA standards on a service organisation's controls relevant to security, availability, processing integrity, confidentiality and privacy (the five Trust Services Categories). The distinction between Type 1 and Type 2 is what the CPA is attesting to.
A Type 1 report attests that the controls were suitably designed as at a specific point in time — the "as of" date. The CPA reviews the description of the system and the design of the controls; it does not test whether the controls actually operated. Type 1 is typically used as an interim milestone by a first-time filer, or when a Type 2 audit period is too short for meaningful testing.
A Type 2 report additionally attests that the controls were operating effectively throughout a specified period, typically 6 to 12 months. The CPA samples and tests actual control operation over the period. Enterprise US customers almost always require Type 2 in procurement — Type 1 is treated as evidence of intent rather than of operational compliance. The dcomply Academy SOC 2 Readiness Practitioner Certification walks the readiness workflow to Type 2 from initial gap analysis onwards.