ZF/blog/soc-2-type-1-vs-type-2
SOC 26 min readMay 8, 2025

SOC 2 Type I vs Type II

Type I tests control design at a point in time. Type II tests operating effectiveness across an audit period. Here is what each one proves and which one matters to your customers.


What Each Report Tests

The two SOC 2 report types test different things. Type I tests design effectiveness. The auditor reviews your controls as designed at a specific point in time and concludes whether they would, if operating, address the Trust Services Criteria. Type II tests operating effectiveness. The auditor tests whether the controls actually worked across an audit period, typically 3-12 months.

Practical implication: Type I is a snapshot. Type II is a movie. Customers and prospects who want assurance that your controls work in practice want Type II. Customers who just want to know controls exist accept Type I.

Both reports cover the same Trust Services Criteria you selected. The difference is depth of testing, not scope of criteria. Refer to the SOC 2 framework details for criteria definitions.

Evidence and Sampling Differences

Type I evidence is point-in-time. The auditor verifies the control exists, is documented, and is operating as of the audit date. Walk-throughs, configuration reviews, and one or two sample tests per control.

Type II evidence is period-based. For each control, the auditor selects samples from across the audit period (often 25-40 samples per control depending on frequency) and tests whether the control operated as designed for each sample. This is why Type II audits are evidence-heavy.

Common Type II sampling patterns:

  • Daily controls: Sample 25-40 days from the audit period
  • Weekly controls: Sample every week or 25-40 weeks
  • Monthly controls: Test every month in the audit period
  • Event-driven controls: Sample 25-40 events (changes, incidents, access requests)

If your evidence repository does not preserve timestamps and history, Type II testing exposes the gap immediately.

Timeline and Cost

Type I runs on a compressed timeline. Once your controls are designed and documented, fieldwork takes 2-4 weeks and the report issues 4-8 weeks after that. Total: 6-12 weeks from start to delivered report.

Type II requires the audit period to elapse first. If you need a Type II covering Q1-Q2, the earliest you can finish fieldwork is mid-July (after Q2 ends). Add 4-8 weeks for fieldwork and 4-8 weeks for report issuance. Total: 4-6 months from audit period end to delivered report.

Cost differences are smaller than people expect. Type I might cost $20K-$40K. Type II covering 6 months runs $30K-$60K. Type II covering 12 months runs $40K-$80K. The marginal cost of extending the audit period is modest.

For first-year SOC 2 programs, the most common pattern is Type I in month 4-6 (to have something to share early), followed by a Type II covering months 6-12 or months 7-12 of year 1.

What Customers Actually Want

Most enterprise customers explicitly require Type II in their security questionnaires. "Provide your latest SOC 2 Type II report" is the standard ask. Type I is acceptable as a stopgap for the first 6-9 months while you accumulate the audit period.

Customers care about Type II because:

  • It proves controls operated for sustained periods, not just on audit day
  • It covers a recent timeframe (12 months back from report date)
  • It includes detailed test results and exceptions, not just opinion
  • It is what their procurement and security teams trained on

Some smaller customers, particularly those new to vendor security review, accept Type I. But if you sell to companies with mature procurement teams, plan for Type II as the long-term deliverable.

The pattern that works: Type I as soon as controls are ready, then continuous Type II audits with no gap in coverage thereafter.

Transitioning from Type I to Type II

The Type I to Type II transition is mostly an evidence problem. Type I proved your controls are designed correctly. Type II proves they operate. The work between the two reports is:

  1. Operate the controls consistently: Every monthly access review, every change approval, every quarterly vulnerability scan happens on schedule with documentation.
  2. Capture evidence continuously: Logs, reports, screenshots, ticketing data preserved in your evidence repository.
  3. Address Type I observations: Anything noted in the Type I report (even informal observations) should be remediated before the Type II audit period begins.
  4. Run interim reviews: Halfway through the Type II period, do an internal review or have your auditor do an interim test to catch problems early.

Most teams stumble in the first three months because controls were "in place" for the Type I but not really operating consistently. The Type II audit period reveals the gap. Start operating controls daily as if Type II testing is happening today.

Frequently Asked Questions

SOC 2Type IType IIAudit

Related Articles