home / frameworks / soc-2 / type-1-vs-type-2

// SOC 2 hub

SOC 2 Type 1 vs Type 2 reports

The difference between a point-in-time Type 1 report and a period-of-time Type 2 report, and which one customers expect.

What each report covers

A Type 1 report gives the auditor's opinion on whether the system description is fair and whether controls were suitably designed to meet the chosen criteria as of a specific date. It says nothing about whether the controls worked before or after that date.

A Type 2 report covers the same ground and adds an opinion on whether the controls operated effectively throughout a period. The auditor samples evidence across the period: access reviews, change tickets, backup logs, incident records, and so on. Periods usually run 6 to 12 months. A first Type 2 sometimes uses a shorter window, such as 3 months, so a company can get a report into customers' hands sooner.

What's in the report

Both types follow the same basic layout. A Type 2 adds the fourth part, which is often the longest section and the one customers read most closely.

  • The independent service auditor's report, which holds the opinion
  • Management's assertion about the description and controls
  • The description of the system, including services, infrastructure, software, people, procedures, and data
  • For Type 2, the controls, the auditor's tests, and the results, including any exceptions
  • Complementary user entity controls that customers are expected to operate
  • Subservice organizations, such as cloud hosting providers, and how they are treated

Which one customers expect

Most enterprise buyers want a Type 2. It shows controls working over time, which is the question a risk team is trying to answer. A Type 1 is useful as a first step. A company that has just finished its readiness work can get a Type 1 quickly, share it with prospects, and start the Type 2 period at the same time.

Some procurement teams will accept a Type 1 together with a commitment to deliver a Type 2 by a set date. Others won't. Ask the customers that matter most before deciding how to sequence the work, since the answer shapes the timeline and budget.

Exceptions and qualified opinions

SOC 2 has no pass or fail. In a Type 2, the auditor lists every exception found in testing, such as a terminated user whose access was removed late or a change deployed without recorded approval. Management can add a response explaining the cause and the fix.

If exceptions are serious enough that a criterion wasn't met, the auditor issues a qualified opinion for that criterion. Adverse opinions are rare. Readers should look past the opinion paragraph and read the test results, because a clean opinion can still sit alongside exceptions that matter to a particular customer.

Report freshness

SOC 2 reports have no expiry date. Customers treat it as current for roughly 12 months after the period ends. That is why most companies run back-to-back annual periods with no gap, so there's always a recent report to share. If a customer asks about the months since the last period ended, the company can provide a bridge letter, which is a management statement and not an auditor opinion.

Canadian vendors that want to sell cloud services to the Government of Canada should note that the Canadian Centre for Cyber Security names SOC 2 Type II reports, not Type I, among the attestations it compares with ITSG-33 controls in its cloud service provider assessment process.

Resources

All SOC 2 resources

References

  1. SOC 2: SOC for Service Organizations: Trust Services Criteria, AICPA and CIMA
  2. Reports on Controls at Service Organizations FAQs, Chartered Professional Accountants of British Columbia
  3. Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Security