skip to content

What is the difference between a SOC 2 Type I and a SOC 2 Type II report, and which does an enterprise customer usually want?

level: juniorimportance: must knowfreq 65%

answer

  1. a date versus a period
  2. design versus operating effectiveness
  3. tests and results section
  4. first-year stepping stone
  5. attestation, not certificate

basics

~20 s

A SOC 2 Type I report gives the auditor's opinion on whether controls were suitably designed as of a date. A Type II adds an opinion on operating effectiveness over a period, with the tests and results. Enterprise customers usually want Type II.

solid answer

~50 s

Both are **attestation reports** issued by a CPA practitioner under the AICPA attestation standards, using the Trust Services Criteria as the criteria. A **Type I** (the AICPA writes "type 1") covers the fairness of management's system description and the **suitability of design** of controls **as of a specific date**. A **Type II** covers the same plus the **operating effectiveness** of those controls **throughout a period**, and includes a detailed description of the auditor's tests of controls and their results. The TSC text is explicit that a type 1 report contains neither an operating-effectiveness opinion nor the description of tests. Enterprise procurement teams usually require Type II, because only it shows controls actually worked over time. A Type I is common as a first report, giving a date-point opinion while the first Type II period runs.

go deeper

for a junior

Recall that Type I covers design as of a date and Type II adds operating effectiveness over a period, with tests and results. Know SOC 2 is an attestation, not a certificate.

for a middle

Explain what each report lets a customer conclude and why procurement usually insists on Type II, including how period length and gaps matter.

for a senior

Show how you would sequence a first Type I and Type II for a vendor under procurement pressure, and how to keep reports back to back afterwards.

for a principal

Discuss when a SOC 2 is the right assurance product versus ISO 27001 or a SOC 3 for a vendor's market, and what each costs to sustain.

## What a SOC 2 report is A **SOC 2 report** is an examination report on controls at a **service organization** relevant to one or more of the AICPA **Trust Services Categories**: security, availability, processing integrity, confidentiality and privacy. It is produced by a licensed CPA firm acting as the **service auditor** (the attestation standards call it the *practitioner*) under the AICPA's attestation standards, using the 2017 **Trust Services Criteria (TSC)** as the evaluation criteria. It is an **attestation** — an opinion on management's description and controls — not a certification, and there is no pass mark or certificate. ## Type I versus Type II | | Type I | Type II | |---|---|---| | **Time** | As of a specified date | Throughout a specified period | | **Opinion on description** | Yes | Yes | | **Opinion on design suitability** | Yes | Yes | | **Opinion on operating effectiveness** | No | Yes | | **Description of tests and results** | No | Yes | | **What it lets a customer conclude** | Controls, as designed, could meet the criteria | Controls actually operated as designed across the period | The AICPA's own text puts it directly: a type 1 SOC 2 report "does not contain an opinion on the operating effectiveness of controls nor a detailed description of tests of controls performed by the service auditor and the results of those tests." The AICPA writes "type 1" and "type 2"; industry usage often uses Roman numerals, and they mean the same. ## Why customers want Type II An enterprise customer's procurement or security team wants to know whether it can rely on the vendor's controls. A design opinion says the controls look right on a given day; it says nothing about whether access reviews ran every quarter, whether changes were approved all year, or whether backups were tested. A Type II answers that, and its tests-and-results section shows any **exceptions** — instances where a control did not operate as described. ## The period The attestation standards do not fix a minimum period length. In practice: - Periods of **six to twelve months** are common for mature programmes, usually renewed annually so reports are back to back. - A **shorter first period**, such as three months, is common when a vendor needs a Type II quickly. - Coverage gaps between the end of one period and the start of the next weaken the report's value and invite questions. ## A typical path for a B2B SaaS vendor 1. **Readiness**: define the system boundary, choose categories, map controls to the criteria. 2. **Type I** as of a date, to answer procurement questionnaires quickly. 3. **First Type II** over a short period starting soon after. 4. **Annual Type II** reports covering consecutive twelve-month periods, with a bridge letter covering the gap between the period end and a customer's request date. ## How SOC 2 relates to SOC 1 and SOC 3 - **SOC 1** reports on controls relevant to a user entity's internal control over financial reporting, for example a payroll processor. - **SOC 3** covers the same TSC subject matter as SOC 2 and contains an opinion on operating effectiveness, but no detailed description of tests and results; it is designed for general distribution. - **SOC 2** is intended for users with enough knowledge of the system to understand it, such as customers and their auditors, which is why vendors share it under a non-disclosure agreement. ## Misreadings to avoid - "We passed SOC 2": there is no pass; there is an opinion, which may be unmodified or modified. - "Type II is a stricter set of criteria": both types use the same criteria; the difference is time and testing. - "A Type I proves controls work": it proves they were suitably designed on one date.

  • Is a Type I report of any use to a customer?
    Limited but real. It shows an auditor examined the system description and found the controls suitably designed as of a date, which is better than a questionnaire alone. It cannot show the controls operated over time, so customers usually accept it only as an interim step, often with a commitment to a Type II period that has already started.
  • What does an exception in a Type II report mean?
    The auditor tested a control and found at least one instance where it did not operate as described, for example an access removal done late. The tests-and-results section lists it, and management may add a response. An exception does not by itself make the opinion modified; the auditor judges whether the control still met the criterion across the period.

saying these in an interview costs you the question

  • A SOC 2 Type I is an easier set of criteria than a Type II.
  • A SOC 2 report is a certificate the vendor passed.
  • A Type I shows controls worked across the year.
  • Type I and Type II use different Trust Services Criteria.
  • A Type II report must cover exactly twelve months.