SOC 2 Type I vs Type II: which one your customer is actually asking for.

A customer asked for a SOC 2 report. Type I and Type II attest different things, and the contract usually says which.

Last reviewed: · 4 min read

Type I is an auditor's opinion on control design at a single date. Type II covers design and operating effectiveness across a window of three to twelve months. A contract naming only "a SOC 2 report" almost always means Type II, and Sorami confirms which one the customer wants before scoping readiness.

What each report attests

Type I is an opinion on control design at a single date. The auditor checks that the controls you selected are suitably designed to meet the criteria, and says so as at that date. Nobody tests whether the controls actually ran.

Type II is an opinion on design and operating effectiveness across a window. The auditor samples evidence from that window, usually three to twelve months, and reports exceptions where a control did not operate.

Type 1 vs Type 2 in one table

 Type IType II
Auditor opinion coversDesign of controls.Design and operating effectiveness.
PeriodOne date.A window, commonly three to twelve months.
EvidencePolicies, configuration and system descriptions as they stand.Samples pulled across the window. Access reviews, tickets, alerts, onboarding and offboarding records.
ExceptionsNot applicable. Nothing is tested over time.Listed individually. A clean report is not guaranteed.
Usual buyerA deal that needs unblocking this quarter.A mature security team, or a renewal the following year.
Time to first reportWeeks after readiness closes.Readiness, then the full window, then fieldwork.
What it does not doProve anything operated.Cover systems you left out of scope.

What the contract usually says

  • "A SOC 2 report" with no type named. Ask. Usually Type II.
  • "Type II within 12 months." Type I now, Type II on the clock.
  • "A current SOC 2 report." They mean an unexpired Type II.
  • "SOC 2 or equivalent." ISO 27001 may satisfy it. Ask before you commit.

Which one to do first

  • Deal closes this quarter and they accept Type I. Do Type I.
  • They named Type II with a deadline. Start the window now.
  • Controls are new or undocumented. Type I first, before exceptions land.
  • You already run access reviews and alerting. Go straight to Type II.

What people get wrong

  • Scoping to the whole company rather than the product bought.
  • Starting the Type II window before the controls actually operate.
  • Collecting evidence by hand in the last fortnight.
  • Assuming Type I satisfies a request that named Type II.

What to do next

Read the exact wording the customer sent, then decide. If you want to know how far off you are, the SOC 2 readiness self-check scores it in your browser, and the SOC 2 readiness page sets out what the work covers and excludes.

If a penetration test is also on the evidence list, read what a penetration test report should contain before you buy one. Everything else is in the guides index.

Questions before you book

Practical answers.

Which one does a customer usually mean?

If the contract just says "a SOC 2 report" they usually mean Type II. Ask before you scope, because the difference is months of evidence.

Can we skip Type I?

Yes, and plenty of companies do. Going straight to Type II saves one audit fee but delays the first report by the length of the observation window.

Does Type I expire?

It describes one date, so it ages immediately. Buyers treat a Type I older than about a year as stale and ask for the Type II.

Who issues the report?

A licensed CPA firm. Readiness work prepares you for that firm and we cannot attest for them.

Let’s scope it

Working out which report you need?

Send the customer wording and the deadline. We will tell you which report fits and what readiness would involve.

Request a quote