The difference
- Type 1 checks that your controls are designed properly at a single point in time.
- Type 2 checks that those controls actually worked over a period of months.
What customers ask for
Most enterprise customers and security questionnaires ask for a Type 2, because it shows the controls work in practice. Some will accept a Type 1 for now if a Type 2 is underway. The fastest way to decide is to ask the customers who are requesting the report.
When a Type 1 makes sense
- A deal depends on showing something soon.
- You want an independent check of your controls before the longer audit.
- Your customers have confirmed a Type 1 is enough for now.
When to go straight to Type 2
- Your customers specifically require it.
- You have time before the report is needed.
- You would rather pay for one audit than two.
How the timelines compare
Preparation is the same for both and typically takes 3 to 6 months. A Type 1 can be audited once preparation is done. A Type 2 adds an audit period, commonly 3 months for a first report, before the audit takes place. See the full SOC 2 timeline.
After the first report
SOC 2 is not a one-time project. Customers expect a current report, so most companies move to a Type 2 that covers twelve months and repeat it each year. The controls have to keep running in between.
We help you decide, then manage the preparation and the audit either way. See SOC 2 readiness and audit management.
