Playbook · Track 1 · Lesson 3 of 10 · 2 min

SOC 2 Type I vs Type II: which should a startup do first?

Short answer

A Type I report covers whether your controls are suitably designed at one point in time. A Type II report also covers whether they operated effectively over a period. If a customer needs something soon, a Type I followed by a Type II is a common route; if you have time, many startups go straight to Type II.

What does a Type I report cover?

A Type I report gives the auditor's opinion on your system description and on whether your controls are suitably designed as of a specific date. It says your controls exist and make sense on that day. It does not say they worked over time.

What does a Type II report cover?

A Type II report covers the same ground plus the operating effectiveness of your controls throughout a stated period. The auditor samples evidence from across that period, for example access reviews, onboarding and offboarding records, change approvals and incident tickets, and reports the tests and results, including any exceptions.

What is the observation period?

The observation period, also called the review or audit period, is the stretch of time a Type II report covers. You and your auditor agree its start and end dates. Controls must be operating from the first day of the period, so readiness work comes first. Ask your auditor what period length your customers are likely to accept.

Which one do customers want?

Many security teams prefer a Type II because it shows controls working over time. Some accept a Type I as a first step, especially from a young company, often with a commitment to deliver a Type II later. The fastest way to know is to ask the customer what they will accept.

When does Type I first make sense?

When a deal depends on having a report soon and the customer accepts a Type I. It gives you a report while the Type II observation period runs. The cost is doing two examinations instead of one.

When should you go straight to Type II?

When there is no urgent deadline, or the customer has said a Type I will not do. You spend the first months on readiness, start the observation period, and receive one report that most buyers accept.

Where does this fit on the trail?

This is stop 4 of the journey: after you have picked a tool and done the readiness work, and before the audit itself.

Further reading

What should you read next?

Next lesson · 4 of 10

Expert-guided vs self-serve SOC 2: choosing your path

Questions founders ask

Is a SOC 2 Type I worth it?

It is worth it when a customer accepts it and you need a report before a Type II period could finish. Otherwise it adds a second examination.

Can we skip Type I?

Yes. There is no requirement to do a Type I before a Type II.