Question

SOC 2 Type I or Type II first?

GRC Review editorial desk · · AI-assisted draft, human-checked. Methodology
Short answer

Start with Type II if you can wait 6–12 months — it's what enterprise customers actually want and it covers operating effectiveness over time, not just design. Go Type I first only if a specific deal or contract is blocked right now and you need something to show within 8–12 weeks. Type I is a point-in-time attestation that your controls are designed correctly; Type II proves they worked consistently over a 3–12 month observation period. Most auditors and customers treat Type I as a stepping stone, not a destination.

What the two reports actually attest to

A SOC 2 Type I report is an attestation by a CPA firm that, at a specific point in time, your controls are suitably designed to meet the AICPA Trust Services Criteria you've selected (Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are optional). It says nothing about whether those controls actually ran consistently.

A SOC 2 Type II report covers the same design question but adds an opinion on operating effectiveness over an observation period — typically 3, 6, or 12 months. Auditors will sample evidence (access logs, change tickets, vendor reviews, incident records) across that window. Enterprise procurement and security teams know the difference, and most will ask for Type II before signing a significant contract.

When Type I makes sense

Type I is worth pursuing when a specific deal is stalled because a prospect's security team has asked for a SOC 2 report and you have nothing to show. A Type I can be completed in 4–8 weeks with a compliance automation tool already in place, versus the 3–12 month observation window that Type II requires. It buys you credibility while the clock runs on your Type II observation period.

It also makes sense if you're very early — under 20 people, controls barely documented — and you need to prove to yourself and your auditor that your control environment is coherent before committing to a longer observation period. Think of it as a structured dress rehearsal.

Why most founders should target Type II directly

If no deal is actively blocked and you have 9–12 months before you expect enterprise procurement scrutiny, skip Type I entirely and start your Type II observation period now. You'll spend roughly the same amount on auditor fees either way — Type I plus Type II costs more in total than going straight to Type II — and you'll end up with the report customers actually want.

With a compliance automation platform handling continuous evidence collection, the observation period is less painful than it sounds. The platform collects logs, access reviews, and configuration snapshots automatically; you review and remediate gaps as they surface rather than scrambling at audit time. A 3-month observation window is achievable for a first Type II; 6 months is more common and gives auditors more comfort.

Timelines and costs to plan around

Type I readiness: 4–8 weeks of control implementation and documentation, then 1–3 weeks for the auditor's fieldwork. Auditor fees typically run $8,000–$20,000 for a straightforward startup scope. Compliance automation tools add $7,000–$30,000 per year depending on the platform.

Type II readiness: 3–12 month observation period (3 months is the minimum most auditors will accept; 6–12 months is standard for a first report). Auditor fees for a first Type II typically run $15,000–$40,000. If you do Type I first and then Type II, expect to pay auditor fees twice. Going straight to Type II with a 6-month window and a single auditor engagement is usually the most cost-efficient path.

Note that the observation period clock starts the day your controls are operating, not the day you sign with an auditor. Start collecting evidence as soon as your controls are in place.

What auditors actually ask for during a Type II

During fieldwork, auditors will request evidence samples across your observation period. Common requests include: user access provisioning and deprovisioning records (every joiner and leaver), change management tickets showing approval before deployment, vulnerability scan results and remediation timelines, security awareness training completion records, incident response logs, vendor risk assessments, and business continuity test results.

Compliance automation platforms pull most of this from your existing tools — AWS CloudTrail, GitHub, Okta, Google Workspace — automatically. The gaps that cause audit delays are usually process gaps: a change deployed without a ticket, an offboarding that wasn't logged, a vendor that was never formally assessed. Fixing those during the observation period is normal and expected; auditors want to see you catch and remediate issues, not that you never had any.

The Type I-then-Type II path vs. going straight to Type II

If you do Type I first, the Type II observation period can start immediately after — you don't have to wait for the Type I report to be issued. Some founders use the Type I audit as a forcing function to get controls in place, then roll straight into the observation period. This is a reasonable approach if your control environment is genuinely immature and you need the external pressure of an audit to drive internal alignment.

If your controls are already reasonably documented and you have automation in place, starting the Type II observation period directly is faster and cheaper overall. Discuss the starting date explicitly with your auditor before you begin — the observation period start date is a formal decision that affects what evidence you need to retain.

Bottom line

If a deal is blocked today, do Type I now and start your Type II observation period immediately after. In every other situation, go straight to Type II — it's what customers want, and doing both sequentially costs more than doing Type II once.

Related questions

Can I start my Type II observation period before I have a CPA firm engaged?
Yes — the observation period is defined by when your controls are operating, not when you sign with an auditor. Start collecting evidence as soon as your controls are live. Engage your auditor 4–6 weeks before you want fieldwork to begin so they can confirm the observation start date and scope.
Will enterprise customers accept a Type I report?
Some will, temporarily, especially if you're early-stage and the deal isn't enormous. Most enterprise security teams will note it in their vendor risk assessment and ask for Type II within 12 months. Financial services and healthcare buyers typically won't accept Type I at all.
How long does the Type II observation period have to be?
The minimum most CPA firms will accept is 3 months, but 6 months is the most common for a first report. A 12-month period is standard for renewals and is what sophisticated buyers prefer. Discuss the period length with your auditor before you start — it's a formal decision.
Does getting SOC 2 Type II mean I don't need ISO 27001?
For US customers, SOC 2 Type II is usually sufficient. For EU customers, especially in Germany, France, or the Netherlands, ISO 27001 certification is often expected alongside or instead of SOC 2. If you're selling into both markets, plan for both frameworks from the start — the control overlap is around 70% and a compliance platform can map evidence across both.
What's the difference between the AICPA Trust Services Criteria and ISO 27001 controls?
SOC 2 is an attestation against the AICPA's Trust Services Criteria — a CPA firm issues an opinion, not a certification body. ISO 27001 is a certification issued by an accredited certification body against the ISO/IEC 27001 standard. They overlap significantly in substance but differ in structure, terminology, and what the resulting report or certificate signals to buyers.

Editorial guidance, not legal or audit advice. Product mentions follow the same rubric as every review; promoted placement is labelled and never changes the analysis (disclosure).