In this guide
- The difference in one line
- Side by side
- What "operating effectively" actually means
- Choosing the observation window
- When a control fails: exceptions and opinions
- Does starting with Type I actually help?
- The gap between reports
- Where Singahi fits
- FAQ
- What is the main difference between SOC 2 Type I and Type II?
- How long should the Type II observation period be?
- Do I need Type I before Type II?
- Does an exception mean I failed the audit?
- What is a qualified opinion?
- Can I get a Type II report quickly?
- How long is a SOC 2 report valid?
- Which Trust Services Criteria apply?
When a customer asks for "your SOC 2," they rarely say which kind they mean. There are two, and the difference decides your timeline, the evidence you have to produce, and whether the report will actually satisfy the person reading it.
Most explanations stop at "Type I is a point in time, Type II is over a period." True, and not enough to plan with. Here is what changes underneath that.
The difference in one line
Type I tests design. Type II tests operation.
A Type I report says your controls were suitably designed as of a specific date. The auditor inspects the control, confirms it exists and would achieve the criterion if it ran. It is a snapshot.
A Type II report says your controls operated effectively across a period. The auditor samples evidence throughout that window and reports what they found, including anything that failed.
Side by side
| Type I | Type II | |
|---|---|---|
| Question answered | Are the controls designed correctly? | Did the controls actually run? |
| Covers | A single date ("as of 31 March") | A period ("1 January to 30 June") |
| Evidence | The control as it stands on that date | Samples drawn across the whole window |
| Can you prepare late? | Yes, controls just have to be in place by the date | No, the period has already happened when testing starts |
| Report contains | Description of the system, auditor's opinion on design | The same, plus tests performed and results for each control |
| Typical buyer reaction | Accepted as progress, often with a follow-up | Accepted as assurance |
| Repeatable | One-off, though some issue one yearly | Annually, with each period following the last |
What "operating effectively" actually means
This is the part that surprises first-timers, and it is really a maths problem.
Your auditor does not check every occurrence of a control. They sample. How many samples they need depends on how often the control runs, and the smaller your population, the more each individual sample matters.
A control that runs on every code deployment might have hundreds of occurrences in six months, so a sample of 25 tolerates one miss without much drama. A control that runs quarterly across a three-month window has a population of one. If that single occurrence did not happen, or happened late, or has no evidence, you have a 100% failure rate on that control. There is no averaging it out.
The practical consequences:
- Low-frequency controls carry the most risk. Access reviews, management review meetings, risk assessments, DR tests, vendor reviews. Each is one or two data points across the whole window.
- Evidence has to be contemporaneous. A quarterly access review reconstructed from memory in month five is not evidence that it operated in month two. Auditors look at timestamps.
- "We do that, we just do not write it down" fails. An undocumented control is untestable, and untestable is indistinguishable from absent.
If you fix one thing before a Type II period opens, make it the evidence trail on your low-frequency controls.
Choosing the observation window
You choose the length, within limits, and it is a real decision rather than a formality.
Three months is the shortest window commonly accepted. It gets you a report soonest. The cost is statistical: quarterly and annual controls barely occur inside it, so a single miss is fatal to that control, and some buyers treat a three-month window as thin evidence.
Six months is the usual middle. Enough occurrences to absorb a stumble, short enough to be reachable.
Twelve months is what mature enterprise buyers prefer and what your second and subsequent reports normally settle into, because consecutive annual periods leave no gap to explain.
Two things to get right regardless of length:
- The window opens when your controls are genuinely running, not when you decide to start. Opening it before a control is live guarantees an exception.
- Line the period end up with the deal you are trying to close, allowing for the weeks between fieldwork ending and the report being issued.
When a control fails: exceptions and opinions
Almost nobody explains this, and it is the section a serious buyer turns to first.
An exception is an instance where the auditor's test showed the control did not operate as described. Exceptions are recorded in the report, usually alongside your management response. Exceptions are normal. A Type II with a couple of noted exceptions and sensible responses is not a failed report.
The opinion is the auditor's overall conclusion, and it is a separate matter:
- Unqualified. The controls were suitably designed and operated effectively. This is the clean result, and you can reach it with exceptions in the report, provided they were not severe and compensating controls addressed the risk.
- Qualified. Something was significant enough that the auditor cannot give a clean opinion, but the system is otherwise sound. The report says which criteria are affected.
- Adverse or disclaimer. Rare, and a serious problem.
What this means in practice: do not panic at an exception, and do write a real management response. "Control failed in March because the reviewer left; ownership reassigned and the April review completed on time" reads far better to a vendor-risk team than silence. They are assessing whether you notice and fix things, which is most of what a management system is.
Does starting with Type I actually help?
Sometimes. Be honest with yourself about which situation you are in.
It helps when a specific deal is waiting on something credible, and the buyer has said a Type I clears their gate for now. You get a document while the Type II window runs behind it. It also forces your controls into a defined state early, which makes the Type II period cleaner.
It does not help when the buyer has already said they need a Type II. Then a Type I is a second engagement that delays the thing they asked for. Ask before you scope, not after.
There is no rule that you must do Type I first. Plenty of companies go straight to Type II, especially if no deal is blocked and they would rather spend the effort once.
The gap between reports
A Type II covers a period that ended in the past, so there is always a gap between the period end and today. Buyers generally expect a report covering the last 12 months, and for the uncovered stretch you provide a bridge letter: a management-signed statement that nothing material has changed since the period end. It is your assertion, not the auditor's, and reviewers typically accept it for around 90 days.
Which is the real argument for annual, back-to-back periods. Let a report age past the year and the bridge letter has to stretch further than anyone is comfortable with, and you are answering questions in exactly the review you bought the report to clear.
Where Singahi fits
We scope the criteria with you, close the gaps, and stand up the evidence collection your auditor needs, for Type I or Type II. That includes the unglamorous part that decides the outcome: making sure your low-frequency controls actually generate dated evidence before the window opens.
An independent CPA firm issues the attestation. We get you ready and keep you ready. See our SOC 2 service, or ISO 27001 vs SOC 2 if you are still deciding which framework the buyer wants.
FAQ
What is the main difference between SOC 2 Type I and Type II?
Type I attests that your controls were suitably designed as of a single date. Type II attests that they operated effectively across a period, with the auditor sampling evidence throughout and reporting what they found. Type I tests design; Type II tests whether the design was actually followed.
How long should the Type II observation period be?
Three months is the shortest commonly accepted window and gets you a report soonest, but quarterly and annual controls barely occur within it, so one miss becomes a total failure for that control. Six months is the usual middle ground. Twelve is what enterprise buyers prefer and what most organisations settle into, because consecutive annual periods leave no gap to explain.
Do I need Type I before Type II?
No. Type I is optional. It is worth doing when a deal needs something credible immediately and the buyer has confirmed a Type I clears their gate, since you get a document while the Type II period runs. If the buyer has already said they want Type II, going straight there is usually the better use of the effort.
Does an exception mean I failed the audit?
No. An exception is a single instance where a test showed the control did not operate as described, and exceptions appear in plenty of clean reports. What matters is the auditor's overall opinion. You can receive an unqualified opinion with exceptions noted, provided they were not severe and compensating controls addressed the risk. Write a substantive management response for each one.
What is a qualified opinion?
A qualified opinion means the auditor found something significant enough that they cannot give a clean conclusion, though the system is otherwise sound. The report identifies which criteria are affected. It is more serious than a noted exception and less serious than an adverse opinion, and buyers will ask about it.
Can I get a Type II report quickly?
Not retroactively. Type II tests a period that has to have already elapsed with controls running and evidence accumulating throughout it. You cannot compress that after the fact, which is why controls and evidence collection should be live before the window opens rather than the week testing begins.
How long is a SOC 2 report valid?
There is no formal expiry, but buyers generally expect one covering the last 12 months. For the gap between the period end and today you supply a bridge letter, a management-signed statement that nothing material has changed, which reviewers typically accept for around 90 days.
Which Trust Services Criteria apply?
Security is mandatory for every SOC 2 and consists of the 33 common criteria. Availability, Confidentiality, Processing Integrity and Privacy are added based on what you have committed to customers. Adding categories you do not need makes the audit harder for no benefit, so confirm what the buyer actually wants before scoping.