Type 1 or Type 2: what changes in your prep
Both report types need the same controls. What changes is when your evidence has to start existing, and that difference is the whole argument.
The preparation for a Type 1 and a Type 2 is identical up to the day the controls go live. After that they diverge completely: a Type 1 tests design at a single date, so your evidence is a set of screenshots and documents current on that date, while a Type 2 tests operation across a window of three to twelve months, so your evidence is a run of records produced continuously from day one of that window. The controls are the same. The evidence discipline is not.
Same Policies, controls and scope work for both
1 day Evidence period for a Type 1
3 to 12 months Evidence period for a Type 2
For the report-buyer's view, including what a customer does with each and how the fees compare, GetSOC2 covers the comparison. This page is the preparer's side.
What changes in your preparation?
| Preparation activity | Type 1 | Type 2 |
|---|---|---|
| Scope and system description | Identical. Written once, reused | Identical |
| Policy set | Approved and acknowledged before the date | Approved and acknowledged before day one of the window |
| Control implementation | Configured and demonstrable on the date | Configured before the window and running throughout it |
| Access reviews | Not sampled. Show the process exists | At least one review inside the window, sampled |
| Change management | Branch protection settings inspected | Settings inspected plus a sample of merged changes across the window |
| Onboarding and offboarding | Checklist exists, one example helps | Every joiner and leaver in the window is in the population |
| Log retention | Configuration screenshot on the date | Must cover the whole window, and cannot be applied retroactively |
| Training | program exists and is assigned | Completion records for everyone, inside the window |
| Incident response | Plan exists | Plan exists and an exercise or a real incident is evidenced |
| Restore test | Not usually required | Tested and recorded inside the window |
| Vendor reviews | Register exists and is rated | Reviews performed at your stated cadence, dated |
Read the right column as a list of things that have a date attached. That is the entire difference. Every Type 2 row is a cycle that must fall inside the window, and none of them can be produced retrospectively without lying.
How much longer does a Type 2 take?
| Phase | Type 1 | Type 2, 3 month window |
|---|---|---|
| Scope, gap analysis, remediation | 8 to 16 weeks | 8 to 16 weeks |
| Observation window | None | 13 weeks |
| Fieldwork | 2 to 4 weeks | 3 to 6 weeks |
| Report issuance | 2 to 4 weeks | 2 to 4 weeks |
| Total from a standing start | 3 to 6 months | 6 to 9 months |
Those ranges assume the preparation actually gets somebody's attention. The timeline page works the same numbers backwards from a date a customer has given you, which is usually the more useful direction.
Which one should we go for?
- Read what the customer wrote. If the contract or the security review says "SOC 2 Type 2", a Type 1 will not close the deal, and you need the conversation about an interim rather than a substitute.
- Count the weeks to the date. If a report has to exist in under four months and you are starting now, a Type 2 is arithmetically impossible and nobody can sell you one.
- Ask whether this is your only report ever. If you will need a Type 2 eventually, and almost everyone does, a Type 1 costs you a separate engagement and a separate fee for a report with a short shelf life.
- Check whether your controls have been running. If access reviews, training and change approvals have genuinely been operating for three months already, you may be able to start the Type 2 window in the past rather than today.
- If you are still torn, go straight to Type 2 with a three month window and use a signed engagement letter plus a stated window start date to keep the customer moving in the meantime.
The honest case against a Type 1
A Type 1 is a real report and it does unblock some deals, particularly with mid-market buyers who mainly need to know an auditor has looked at you. It also costs a full audit fee, produces a document that says nothing about whether your controls worked, and is often followed within six months by the Type 2 you were always going to need. Buy one when a specific deal turns on it, and not because it feels like a safer first step.
When can the observation window start?
The window starts when your controls are actually in place, not when you decide it starts. If you turn on MFA enforcement on 14 March, a window that opens on 1 March has a month in it where a tested control did not exist. Some firms will let you backdate a window start where you can evidence the controls were operating; most will not, and none should when they were not.
Every remediation item with a lead time sits between you and the window opening. Log retention, training rollout, background checks and the penetration test all take weeks, and the remediation plan page covers which ones to start first. The readiness scorecard gives you a lead time per finding and an earliest defensible window start date.
What do we tell the customer in the meantime?
Give them the truth plus a date. A signed engagement letter with the audit firm, your window start and end dates, and the report's expected issuance date is enough for most security reviewers to conditionally approve, particularly if you can also show a recent penetration test. Once you have a report, the gap between its period end and the customer's question is covered by a bridge letter, which GetSOC2 explains. Before the first report there is nothing to bridge, so the engagement letter and a clear window date are the whole of what you have.
What that reviewer will ask for alongside the report is a longer list than most Canadian companies expect, and it is worth reading what US buyers actually ask for before you promise a date.
Get the right report prepared for your buyer
Preparing for a Type 1 and preparing for a Type 2 are different pieces of work. Send your scope and compare firms that will tell you which one your deal actually needs.
Get matchedCommon questions
Can we do a Type 1 and then a Type 2 with the same auditor?
Yes, and most firms will discount the second engagement because the scope work, system description and control walkthroughs carry over. Ask for the combined price up front rather than treating them as two decisions, because the Type 1 quoted alone is rarely the price you end up paying in total.
Can the Type 2 window start before the Type 1 report is issued?
Yes. The window is about your controls operating, not about the previous report existing. Companies commonly start the Type 2 window on the day after the Type 1 as-of date, which means the second report follows the first by roughly the window length plus fieldwork.
What is the shortest useful Type 2 window?
Three months. Shorter windows are occasionally issued and enterprise buyers regularly push back on them, because a quarterly control gets sampled once. Six months is the length that stops the conversation, and twelve is what you settle into from the second report onward.
Does a Type 1 count as evidence for the Type 2?
Not as such. The Type 2 tests operation over its own window, and the Type 1 opinion covers design at a point before that window. What carries over is all the preparation: the system description, the control matrix, the policy set and the auditor's familiarity with your environment.
We have been running these controls for months already. Does that count?
It can. If you can evidence access reviews, change approvals, training and monitoring operating over a past period, some firms will agree a window start in the past. Bring the evidence to that conversation before you bring the request, because a firm that agrees and then finds gaps will move the window forward anyway.