If you sell software or services to banks, broker-dealers, or enterprise fintech, the first security question is usually some version of “do you have a SOC 2?” The honest answer depends on which report type they mean — and the difference between Type I and Type II is exactly where first-time vendors get caught out.
SOC 2 is an attestation, not a certification
A SOC 2 report is an attestation issued by an independent CPA firm under the AICPA’s attestation standards (SSAE 18, AT-C Section 205). The auditor examines your controls against the AICPA Trust Services Criteria and issues an opinion. There is no certifying body, no badge, and no “SOC 2 certified” status — vendors who use that phrase in security questionnaires signal that they have not been through the process. The accurate language is that you have “completed a SOC 2 examination” or “hold a SOC 2 report.”
Every SOC 2 covers the Security criteria (the “common criteria”) as a mandatory baseline. Availability, confidentiality, processing integrity, and privacy are optional categories you scope in based on what your customers care about. Most SaaS vendors start with Security plus availability and confidentiality.
Type I: control design at a point in time
A Type I report answers one question: as of a specific date, were your controls suitably designed and implemented? The auditor looks at your control environment on that day. Because there is no observation period, a Type I can be completed relatively quickly once your controls are in place, which makes it a useful milestone for an early-stage company that needs to show progress to a prospect.
The limitation is obvious once you say it out loud: a Type I proves your controls existed on one day. It says nothing about whether anyone actually followed them.
Type II: operating effectiveness over a window
A Type II report covers a review period — commonly three to twelve months — during which the auditor tests whether your controls actually operated effectively throughout the window. Access reviews that happened on schedule, offboarding tickets closed on time, change management followed for every release. This is the report that answers the question buyers are really asking: not “do you have policies?” but “do you follow them?”
Which one procurement actually accepts
Enterprise security teams, sponsor banks, and most regulated-industry buyers expect a Type II. A Type I is often accepted as a stopgap — typically alongside a contractual commitment to deliver a Type II within an agreed window. If your report period ended months before the contract date, expect to be asked for a bridge letter (also called a gap letter): a management assertion, typically covering a gap of up to about three months, that controls remain in place and no material incidents or control changes occurred between the report’s end date and today.
Type I vs. Type II at a glance
Type I
Control design, at a point in time
- Answers: were controls suitably designed and implemented as of one date?
- No observation period — can be completed relatively quickly.
- A useful early milestone; often accepted as a stopgap.
- Proves controls existed on one day — not that anyone followed them.
Type II
Operating effectiveness, over a window
- Answers: did controls operate effectively throughout a review period?
- Review window commonly three to twelve months.
- What enterprise buyers, sponsor banks, and regulated industries expect.
- Tests evidence over time — access reviews, offboarding, change management.
A Type I is often accepted alongside a contractual commitment to deliver a Type II within an agreed window.
A realistic first-time timeline
First-time SOC 2 Type II — the four phases
- 1Readiness / gap assessment — a few weeks
- 2Remediation — the longest, least predictable phase
- 3Observation window — 3–6 months for a first Type II
- 4Fieldwork & report issuance — several more weeks
Illustrative summary of the article's timeline.
- Readiness or gap assessment — typically a few weeks to inventory controls against the Trust Services Criteria and find the holes.
- Remediation — usually the longest and least predictable phase; closing gaps in access control, vendor management, change management, and evidence collection.
- Observation window — for a first Type II, most firms run three to six months with controls operating and evidence accumulating.
- Fieldwork and report issuance — the auditor samples evidence from the window and drafts the report, typically several more weeks.
End to end, a first Type II is realistically a six-to-twelve-month project. The single biggest driver of that timeline is whether evidence exists when the auditor asks for it — which is a workflow and ownership problem long before it is an audit problem.
Sources
This article is general information for compliance professionals, not legal, audit, or regulatory advice. Confirm requirements that apply to your firm with counsel or your examiner.