Enquire Us

SOC 2 Type 1 vs Type 2

SOC 2 is an attestation examination performed by an independent licensed CPA firm under the attestation standards of the American Institute of Certified Public Accountants. It is not a certification: there is no certificate, no accreditation body and no certification body. The examination reports on controls at a service organisation against the Trust Services Criteria. The difference between the two report types is narrow but important. A Type 1 report addresses the suitability of the design of controls as at a specified date. A Type 2 report addresses design and operating effectiveness throughout a specified period.

What is a SOC 2 Type 1 report?

A Type 1 examination looks at management’s description of the service organisation’s system and at whether the controls described are suitably designed to meet the applicable Trust Services Criteria, as at a single specified date. The CPA firm evaluates design. It does not test whether the controls actually operated over time, because there is no period under examination.

That makes a Type 1 useful in a specific situation: the controls are newly implemented, a prospective customer needs something now, and there is not yet enough operating history to test. It is a point in time statement, and a sophisticated buyer will read it as such.

What is a SOC 2 Type 2 report?

A Type 2 examination covers the same description and design questions and then adds the part buyers care most about: whether the controls operated effectively throughout a specified period. The CPA firm selects samples across that period and tests them, and the report includes the tests performed and the results, including any exceptions.

Observation periods are commonly three to twelve months. A shorter first period is often used to get an initial report out, with subsequent periods extended to twelve months so that each report follows on from the last without a gap. Where a gap does exist between the end of the reported period and the date a customer is asking, service organisations commonly issue a bridge letter, which is management’s own representation and not part of the CPA firm’s opinion.

SOC 2 Type 1 vs Type 2 compared

AttributeSOC 2 Type 1SOC 2 Type 2
What is examinedDescription of the system and suitability of design of controlsDescription of the system, suitability of design and operating effectiveness of controls
Time frameAs at a specified dateThroughout a specified period
Testing of operationNot performedPerformed, with samples drawn across the period
Typical duration coveredA single dateCommonly three to twelve months
Contents of the reportPractitioner’s opinion and management’s descriptionPractitioner’s opinion, management’s description, tests performed and results including exceptions
Who performs itAn independent licensed CPA firm under AICPA attestation standardsAn independent licensed CPA firm under AICPA attestation standards
Assurance value to a buyerLower, design onlyHigher, evidence that controls actually ran
Usual triggerNew control environment, a deal that cannot waitEnterprise procurement and vendor risk review
OutputA report, not a certificateA report, not a certificate
Scope categoriesSecurity is required, others optionalSecurity is required, others optional

How the Trust Services Criteria fit in

The scope of either report type is set by the Trust Services Categories selected. There are five: security, availability, processing integrity, confidentiality and privacy. Security, also called the common criteria, is the only category that must be included in a SOC 2 examination. The others are added where they are relevant to the commitments the service organisation makes to its customers.

Two consequences follow. First, two SOC 2 reports are not automatically comparable, because one may cover security alone and another may cover security, availability and confidentiality. Second, the report type and the category selection are separate decisions: a Type 2 report covering only security is narrower in scope than a Type 1 covering four categories, even though it is stronger in assurance.

Which report applies to you?

  • Type 1 if your control environment has just gone live, a deal is waiting, and you need independent evidence that the design is sound while you build up operating history.
  • Type 2 if an enterprise customer, a procurement team or a vendor risk questionnaire is asking for assurance. This is what most buyers mean when they ask for SOC 2, and many will not accept a Type 1 in its place.
  • Type 1 then Type 2 is a common sequence: a Type 1 to unblock a sale, then a Type 2 over a following period, then an annual cycle.
  • Check the wording you use. SOC 2 compliant and SOC 2 certified are both inaccurate. The correct description is that an independent CPA firm has issued a SOC 2 Type 1 or Type 2 report covering named Trust Services Categories for a stated date or period.

Frequently Asked Questions

Is SOC 2 a certification?

No. SOC 2 is an attestation examination carried out by an independent licensed CPA firm under AICPA attestation standards. The output is a report containing the practitioner’s opinion, management’s description of the system and, for a Type 2, the tests performed and their results. There is no certificate and no accreditation body.

What exactly is the difference between Type 1 and Type 2?

A Type 1 report addresses the suitability of the design of controls as at a specified date. A Type 2 report addresses the suitability of design and the operating effectiveness of those controls throughout a specified period, and includes the tests the practitioner performed and the results.

Who is allowed to perform a SOC 2 examination?

An independent licensed CPA firm. A report produced by a firm that is not a CPA firm should not be relied on as a SOC 2 report. The engagement is performed under the AICPA attestation standards, the Statements on Standards for Attestation Engagements, and the practitioner may use specialists within the engagement team.

How long does a Type 2 observation period run?

Commonly between three and twelve months. Many service organisations issue a first report over a shorter period and then move to a twelve month cycle so that consecutive reports leave no gap in coverage.

Does a SOC 2 report expire?

It does not carry a formal expiry date, because it describes a fixed date or a fixed period rather than an ongoing status. In practice, customers expect a current report, which usually means one issued annually with a period ending recently. A bridge letter from management is often used to cover the interval between the end of the period and the date of the request.

Which Trust Services Categories have to be in scope?

Security, known as the common criteria, is the only category required in a SOC 2 examination. Availability, processing integrity, confidentiality and privacy are added where they are relevant to the service commitments and system requirements of the service organisation.

Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.