SOC 2 timeline: a realistic month by month
Six to nine months from a standing start to a first Type 2 report. The part people plan around wrongly is the observation window, which is calendar time and cannot be bought.
From a standing start, a first SOC 2 Type 2 report takes six to nine months: roughly two to four months of preparation, a three month minimum observation window, then four to eight weeks of fieldwork and report writing. A Type 1 is much faster, two to four months, because it tests design at a single date and needs no window at all.
Companies with an existing security program, one cloud provider and single sign-on already in place can compress the preparation to six weeks. Nobody compresses the window.
Month by month, from nothing
| Month | What happens | What has to be true at the end |
|---|---|---|
| 1 | Scope, criteria, gap analysis, named owner assigned | A written system description and a ranked gap list with owners |
| 2 | Policies drafted and approved. Long-lead items started: log retention, training, background checks, penetration test booked | Policy set approved and acknowledged. Long-lead work in flight |
| 3 | Technical remediation: access control, change management, monitoring, vendor register | Controls exist in the systems, not only on paper |
| 4 | Readiness assessment, evidence structure set up, auditor engaged | Collection routine running and fieldwork dates booked |
| 5 to 7 | Observation window. Controls operate, evidence accumulates, at least one cycle of every periodic control completes | A complete evidence set covering every day of the period |
| 8 | Fieldwork. Auditor requests populations, samples them, asks follow-up questions | Requests answered within days rather than weeks |
| 9 | Draft report, management response to any exceptions, final report issued | A report you can send to a customer |
Month four is the one that gets skipped and the one that decides whether month eight is calm. Setting up evidence collection before the window opens is what separates a nine month plan that holds from a nine month plan that becomes twelve.
The observation window is the constraint
A Type 2 report is an opinion about whether controls operated over a stated period. The period is real elapsed time. You cannot pay to shorten it, run it in parallel with remediation, or start it retroactively on a date when your controls were not actually running.
Three months is the common minimum for a first report. Six or twelve months is what mature enterprise buyers prefer and what most companies move to in year two, so that consecutive reports leave no gap between periods.
| Window | Time to first report | How buyers read it |
|---|---|---|
| Type 1, no window | 2 to 4 months | Accepted as an interim step, usually with a Type 2 date expected |
| 3 months | 6 to 9 months | Fine for a first report. Some large buyers ask when the next one covers longer |
| 6 months | 9 to 12 months | Comfortable for most enterprise procurement |
| 12 months | 15 to 18 months | The steady state, and where you end up eventually |
Two dates people get wrong
The window starts when your controls are genuinely operating and evidence is being captured, not when you decide it starts. And the report arrives weeks after the window closes, not on the closing date, because fieldwork and report writing follow. If a customer needs a report in hand by a date, work backwards from that date by at least six weeks before you even begin counting the window.
When a deal needs it sooner than that
This is the most common situation on this page: a contract is waiting and someone has been told SOC 2 takes a few weeks. It does not, and no amount of budget changes the arithmetic. What you can do instead:
Ask what the buyer actually needs. Procurement often asks for SOC 2 by default when the underlying requirement is a completed security questionnaire, evidence of a penetration test, or specific contractual commitments. Some of those you can meet this month.
Offer a Type 1 with a committed Type 2 date. A Type 1 tests design at a point in time and can follow readiness almost immediately. Many buyers accept it for a first year when the Type 2 date is written into the contract. It costs $15,000 to $30,000 CAD on top of the Type 2 you will still do, which is the price of the deal closing now.
Give them the plan, honestly. A dated remediation plan with named owners, plus a completed questionnaire, plus a recent penetration test, closes more deals than people expect. Claiming a report you do not have closes none of them, and it ends badly at the point they ask for the document.
What actually causes delay
Almost none of it is the auditor. In order of how much time they cost:
- Evidence missing from the first weeks of the window, which either moves the window or produces an exception.
- A periodic control with no complete cycle inside the period, most often a quarterly access review started too late.
- Scope that changes mid-programme, usually when a system assumed to be out turns out to hold customer data.
- Audit firm availability. Good Canadian firms book a quarter or more ahead, so engaging after the window closes adds weeks of waiting.
- Penetration test findings arriving late, leaving no time to evidence the fixes inside the period.
- Slow responses during fieldwork. A request list answered over three weeks instead of three days stretches the whole engagement.
- No named owner, which is the root cause of most of the above.
Year two and after
The second report is easier and the timeline changes shape. Preparation largely disappears because the controls are running. The window extends, usually to twelve months, and it should start the day after the previous period ended so that your reports are continuous. Buyers do notice a gap between periods, and explaining one is more work than avoiding it.
Plan for the annual cycle: window running continuously, fieldwork in the same months each year, penetration test scheduled to land well inside the period, and the periodic controls on a calendar that nobody has to think about. That is the point at which SOC 2 becomes an operating cost rather than a project, and it is also when evidence collection discipline pays for itself.
Have a date you need to hit
Tell us the date and where you are today, and we will tell you whether it is achievable and what the honest alternative is if it is not.
Get matchedCommon questions
How long does SOC 2 take from start to finish?
Six to nine months for a first Type 2 with a three month window: two to four months of preparation, three months of observation, then four to eight weeks of fieldwork and reporting. A Type 1 takes two to four months. A company with an existing security program can take two or three months off the preparation stage but not off the window.
Can we get a SOC 2 report in 30 days?
No, and any vendor implying otherwise is describing something else. The fastest genuine path is a Type 1, which still needs your controls designed and implemented before an auditor can test them, so two to four months from a standing start. A Type 2 requires the observation period to have already happened.
How long should our first observation window be?
Three months, unless a customer has specified otherwise. It gets you a report soonest and gives you a real cycle of the program before committing to a longer period. Move to twelve months for the second report, starting the day after the first period ends so there is no gap between them.
When should we engage the audit firm?
During preparation, before the window opens, and certainly before it closes. Canadian firms are frequently booked a quarter ahead. Engaging early also means you can confirm your window dates and control list with them, so the first surprise does not arrive during fieldwork.
Does using a compliance platform make the timeline shorter?
It shortens preparation, sometimes by several weeks, because you start with a mapped control framework and automated evidence collection. It does not shorten the observation window, the fieldwork or the report writing, so the effect on a first Type 2 is real but smaller than the marketing suggests.