Type I is an auditor's opinion on control design at a single date. Type II covers design and operating effectiveness across a window of three to twelve months. A contract naming only "a SOC 2 report" almost always means Type II, and Sorami confirms which one the customer wants before scoping readiness.
What each report attests
Type I is an opinion on control design at a single date. The auditor checks that the controls you selected are suitably designed to meet the criteria, and says so as at that date. Nobody tests whether the controls actually ran.
Type II is an opinion on design and operating effectiveness across a window. The auditor samples evidence from that window, usually three to twelve months, and reports exceptions where a control did not operate.
Type 1 vs Type 2 in one table
| Type I | Type II | |
|---|---|---|
| Auditor opinion covers | Design of controls. | Design and operating effectiveness. |
| Period | One date. | A window, commonly three to twelve months. |
| Evidence | Policies, configuration and system descriptions as they stand. | Samples pulled across the window. Access reviews, tickets, alerts, onboarding and offboarding records. |
| Exceptions | Not applicable. Nothing is tested over time. | Listed individually. A clean report is not guaranteed. |
| Usual buyer | A deal that needs unblocking this quarter. | A mature security team, or a renewal the following year. |
| Time to first report | Weeks after readiness closes. | Readiness, then the full window, then fieldwork. |
| What it does not do | Prove anything operated. | Cover systems you left out of scope. |
What the contract usually says
- "A SOC 2 report" with no type named. Ask. Usually Type II.
- "Type II within 12 months." Type I now, Type II on the clock.
- "A current SOC 2 report." They mean an unexpired Type II.
- "SOC 2 or equivalent." ISO 27001 may satisfy it. Ask before you commit.
Which one to do first
- Deal closes this quarter and they accept Type I. Do Type I.
- They named Type II with a deadline. Start the window now.
- Controls are new or undocumented. Type I first, before exceptions land.
- You already run access reviews and alerting. Go straight to Type II.
What people get wrong
- Scoping to the whole company rather than the product bought.
- Starting the Type II window before the controls actually operate.
- Collecting evidence by hand in the last fortnight.
- Assuming Type I satisfies a request that named Type II.
What to do next
Read the exact wording the customer sent, then decide. If you want to know how far off you are, the SOC 2 readiness self-check scores it in your browser, and the SOC 2 readiness page sets out what the work covers and excludes.
If a penetration test is also on the evidence list, read what a penetration test report should contain before you buy one. Everything else is in the guides index.