HomeBlog › SOC 2 Type 1 vs Type 2: What Is the Difference and Which One Do You Need?

SOC 2 Type 1 vs Type 2: What Is the Difference and Which One Do You Need?

Published 2026-07-23 · 5 min read · BALTUM

"SOC 2 Type 1 or Type 2?" is the first question every company asks when a customer requests SOC 2. Both reports are issued by an independent CPA firm and both rely on the same criteria, yet they answer different questions. This article explains the difference between Type 1 and Type 2, compares timelines and costs, and gives a practical recommendation on where to start.

The short answer

SOC 2 Type 1 answers the question: "Are the company's controls suitably designed as of a specific date?" The auditor verifies that policies exist, controls are implemented and they are capable of meeting the relevant criteria.

SOC 2 Type 2 answers a harder question: "Did those controls operate effectively throughout a period?" The auditor samples evidence across the whole observation period (usually 3, 6 or 12 months) and tests whether procedures were actually followed: were leavers' accounts removed, were backups tested, did changes go through review?

Put simply: Type 1 is a photograph, Type 2 is a video recording.

Side-by-side comparison

AspectSOC 2 Type 1SOC 2 Type 2
Subject of the auditDesign of controlsDesign + operating effectiveness
Time coverageA single date ("as of")A period of 3–12 months
Auditor testingDocument review, interviews, configuration checksThe same, plus evidence sampling across the period
Time to report from scratch2–4 months6–12 months
Typical audit fee (SMB)$8–20k$15–40k
How customers read it"They have started the journey""They have proven the processes work"
FrequencyUsually onceAnnually

What the auditor actually tests

Type 1

As of the report date, the auditor assesses each control on the basis of "does it exist and is it adequate". For a control such as "production access is granted only after approval", it is enough to show the policy, the approval workflow in the ticketing system and the current user list with evidence that every user has an approved request.

Type 2

For the same control, the auditor will request a list of all access grants during the period, say six months, select a random sample and verify for each one that a request existed, an authorised person approved it, and access was granted after approval rather than before. If one of 25 sampled cases lacks an approval, that is an exception and it goes into the report.

This is why Type 2 requires discipline: controls must operate every day and evidence must be collected continuously, not the week before the audit.

When Type 1 is enough

  • A customer requires "any SOC 2" on a short deadline, for example before contract signature in three months.
  • You have only just implemented the controls and have no operating history; Type 2 is physically impossible without an observation period.
  • An early-stage start-up needs to show investors and first customers that security is taken seriously.
  • Major infrastructure changes are imminent, making it impractical to lock in an observation period now.

When you need Type 2

  • Enterprise customers, banks, insurers, healthcare companies. Their vendor risk procedures typically require Type 2 with a period of at least six months.
  • You already hold a Type 1; customers will expect a Type 2 within the following year.
  • SOC 2 is part of your sales strategy rather than a one-off requirement. Type 2 is renewed annually, and an unbroken chain of reports with no gap in coverage is a strong negotiating asset.
  • You process sensitive data at scale and want a genuine test of your own process maturity.

The typical strategy: Type 1, then Type 2

The most common and least risky path looks like this:

  1. Gap analysis and control implementation (1–3 months). Define the scope and TSC criteria, close the gaps.
  2. Type 1 audit. You receive a first report you can already share with customers.
  3. Observation period (usually six months for the first Type 2, then twelve). Controls operate and evidence accumulates.
  4. Type 2 audit. You receive a report covering the full period.
  5. Annual renewal of Type 2 with no gaps in coverage.

You can skip Type 1 and go straight to Type 2. It is cheaper overall, but your first report arrives only after 8–12 months. If deals are waiting, an interim Type 1 pays for itself.

What a bridge letter is and why it matters

A Type 2 report covers a past period. If a customer asks for the report in February and your last period ended in September, there is a gap. For such cases the company issues a bridge letter (also called a gap letter): a management statement that no material changes to controls have occurred since the period ended. It does not replace the report, but it covers the interval until the next audit.

Common mistakes when choosing

  • Promising a customer a Type 2 "in three months". Without an observation period that is impossible, and a reputable auditor will not agree to it.
  • Choosing the shortest period (three months) for the first Type 2 when the customer clearly expects six or twelve.
  • Changing scope or criteria mid-period without agreeing it with the auditor.
  • Not planning the next period immediately after receiving the report, and ending up with a coverage gap.

How BALTUM helps

We run the gap analysis, draft policies and help implement controls so they are Type 2-ready from day one, not merely Type 1-ready. We set up evidence collection so the observation period holds no surprises, and we manage communication with the CPA audit team that issues the report. If you are also considering ISO 27001, look at the SOC 2 + ISO 27001 package; most controls are shared. For budgeting details read how much SOC 2 costs, and for the fundamentals see what SOC 2 is.

Not sure which report type fits your situation? Send us a brief description of your product and your customer's requirement and we will recommend the optimal sequence and timeline. Get a consultation.