Hael
Book a meeting
SOC 2 · Reports

SOC 2 Type 1 versus Type 2

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Type 1 examines whether your controls were designed properly on one specific date. Type 2 examines whether they actually operated over a period.
  • Enterprise buyers almost always want Type 2. Type 1 is a staging post, not a destination.
  • The observation period for a Type 2 is normally three to twelve months, and it cannot be shortened once it has started.
  • Type 1 auditor fees typically run $5,000 to $25,000. Type 2 fees typically run $15,000 to $60,000.
  • Going straight to Type 2 is usually the cheaper route overall if your buyer will wait. Doing Type 1 first pays for two examinations.

The difference is time

The difference is time. A SOC 2 Type 1 report says your controls were designed properly on one particular date. A SOC 2 Type 2 report says those controls actually ran, as described, across a period of months. Enterprise buyers want the second one, because a control that exists on paper is not the same as a control that runs every Tuesday.

Everything else about the two reports is the same. Same criteria, same auditor, same evidence categories, same report structure. Only the question being answered changes.

What does a Type 1 report actually examine?

A Type 1 examination is a point in time. The auditor looks at your control descriptions, your policies and the configuration of your systems on a single date, and forms an opinion on whether those controls were suitably designed to meet the criteria you selected.

The auditor does not test whether the controls have been running. If your access review procedure was written the week before the examination date, a Type 1 can still be clean, provided the procedure itself is sound and the supporting configuration is real.

That is the strength and the limit of a Type 1. It proves the design is credible. It proves nothing about operation.

What does a Type 2 report examine?

A Type 2 examination covers a period, called the observation period. The auditor selects samples from across that period and tests whether each control operated as described throughout. If your policy says access is reviewed quarterly, the auditor will ask for the evidence of each quarterly review inside the window and will notice if three of them happened in the final fortnight.

This is why Type 2 is the report that carries weight with buyers, and why it cannot be rushed. The period has to elapse.

Type 1 and Type 2 compared

Type 1Type 2
Question answeredWere the controls designed properly on a given date?Did the controls operate as described over a period?
CoverageOne dateA period, normally 3 to 12 months
Auditor testingDesign onlyDesign and operating effectiveness, using samples
Typical auditor fee$5,000 to $25,000$15,000 to $60,000
Time from a standing start6 to 12 weeks9 to 12 months for a first report
Accepted by enterprise buyersSometimes, often with conditionsYes, this is the standard expectation
RepeatsRarely repeated once Type 2 is in placeAnnually

Should you do Type 1 first?

There is one good reason to do a Type 1 first, and it is commercial rather than technical. If a deal is live now and the buyer will accept a Type 1 as evidence that a real programme is underway, the report buys you the months you need to complete a Type 2 observation period. Used that way, a Type 1 is a sales instrument.

If no deal is waiting, going straight to Type 2 is usually the better economics. You pay one auditor fee instead of two, and you spend your preparation effort once. The build work is identical either way, so a company that prepares properly for a Type 1 has already done most of what a Type 2 requires.

The judgement call is worth making deliberately rather than by default, because the decision sets your cost and your timetable for the next year. It is one of the first things we settle in a readiness and gap assessment.

How long should the observation period be?

Three months is the shortest period most auditors will accept, and it is a legitimate choice for a first report. Six months is more common. Twelve months is the standard once a company is in an annual cycle.

A shorter first period gets a report into buyers' hands sooner. The trade-off is that a three-month window contains fewer instances of anything quarterly, so the sample sizes are small and a single missed review is proportionally more visible. If your control cadence is monthly or weekly, a three-month period tests it fairly. If it is quarterly, six months is safer.

What happens between reports

A Type 2 report covers a period that has ended. The day it is issued, the next period has already started. Controls that stop running in month two of that new period will show up in the next examination, and the company will be repairing the gap under time pressure a year later.

This is the part of SOC 2 that generic advice tends to skip, and it is where the recurring cost sits. Access reviews, vendor reviews, change approvals and incident records have to keep happening on schedule, and someone has to notice when they do not. That is the work our continuous governance and assurance service is built around.

What to do next

Ask your buyer, in writing, which report they will accept and by when. That answer determines whether Type 1 has any value for you at all.

Then decide the scope and the observation period together, because they interact. Our free readiness diagnostic will give you a first view, and the SOC 2 service page sets out how we run the programme end to end.

References

FAQ

Can I get a SOC 2 Type 2 without a Type 1 first?

Yes, and most companies do. Type 1 is optional and only worth the fee when a live deal needs something sooner.

Can the observation period be backdated?

No. The period must run forward from a date agreed with your auditor, and evidence has to exist across it. Assembling records afterwards is exactly what the sampling is designed to detect.

Does a Type 1 report satisfy enterprise procurement?

Sometimes, usually with a condition attached such as a commitment to produce a Type 2 within a stated number of months. Ask before you commission one.

How often do I need a new Type 2 report?

Annually. Most buyers treat a report as stale once it is more than twelve months old.

Is a Type 2 report harder to pass?

It is not harder in principle, but it is unforgiving about consistency. The design work is the same. The difference is whether the controls kept running when nobody was watching.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act, from first assessment to report, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.