Sentrix

Analysis · Compliance

SOC 2 Type 1 or Type 2: which one your customers ask for

Type 1 describes controls at a date, Type 2 proves they operated over a period. What customers actually ask for, how the observation period works, how to plan.

By Sentrix · Published 2026-09-20

A software company receives the security questionnaire of an important customer. The question fits on one line: "Do you have a SOC 2 report?" Behind that line hide two very different reports that carry the same name, and the choice between them commits several months of work and determines what the customer will actually be able to conclude.

What the sources say

The AICPA, which defines the SOC framework, describes SOC as a suite of attestation services that certified public accountants provide on the controls of a service organization. A SOC 2 report covers the controls relevant to security, availability, processing integrity, confidentiality or privacy: the five categories of the Trust Services Criteria. Its stated purpose is to give report users the information they need to assess and address the risks associated with outsourcing a service. The AICPA also publishes the 2018 description criteria (guidance revised in 2022), which frame the description of the system that the organization writes itself and that the auditor examines. The same AICPA page warns against promises of a "fast and easy" SOC 2, which it considers a threat to the quality of the engagements.

The Type 1 versus Type 2 distinction is stated plainly in Microsoft's compliance documentation, which describes its own SOC 2 program: Type 1 examinations "don't look back over a period of performance", whereas Type 2 examinations cover a rolling twelve-month period and evaluate whether the controls were designed appropriately, in operation on a given date and operating effectively over the whole period. The report is issued a few months after the end of the period. Between two reports, Microsoft issues bridge letters that it itself calls self-attestations, not examination reports. The Amazon Web Services SOC FAQ confirms the same mechanics: SOC 2 reports over twelve-month periods and a continued operations letter updated every month.

Why it matters

A Type 1 is a photograph: on a precise date, the controls described exist and are designed to meet the criteria. A Type 2 is a film: the auditor tests that each control operated during the period, from dated evidence, and reports the exceptions. A customer reading a Type 1 learns that you have an access review policy. A customer reading a Type 2 learns how many reviews took place, whether they were done on time, and what management answered to the gaps.

That is why procurement teams almost always ask for the Type 2, and why they look at four things first: the auditor's opinion, the list of exceptions and management's responses, the period end date, and the presence of a bridge letter if that date is several months old. A Type 1 serves as a milestone when a contract is pressing; it does not replace the Type 2 that follows.

The observation period is the point teams underestimate. It does not start when the policy is signed, but when each control actually produces its evidence: logs, tickets, approvals, reviews. A control put in place in the middle of the period cannot be tested over the whole period. And a period that leaves a gap before the next one forces you to explain yourself to every customer.

What we think at Sentrix

A successful SOC 2 is planned backwards, from the date the customer wants to read the report. In order:

  1. Fix the scope first: the systems covered and the categories retained. Security is the base; availability, confidentiality, processing integrity and privacy are added when your contracts promise them.
  2. Choose the Type according to the customer's calendar, not according to ease: Type 1 only if a contract requires it now, with the date of the Type 2 already announced; otherwise, aim directly for the Type 2 with a first period agreed with the auditor.
  3. Date the start of the period to the day each control produces evidence, and keep an evidence register per control from that day. That is the role of the compliance module of our platform: every control has an owner, a frequency and an expected piece of evidence.
  4. Reuse what exists: an ISO 27001 management system already covers a large share of the common security criteria; the SOC 2 framework page on our site describes the mapping.
  5. Prepare the exceptions rather than hide them: an exception with a credible management response reads better than a report with no gap and no explanation.
  6. Plan consecutive periods before the end of the first, so that the bridge letter never covers more than a few months.

The next step

If a customer asks for your SOC 2 report this year, count backwards: desired reading date, issue month, period end, period start, and today's date. The gap between the last two is your margin to get the controls running. If the margin is negative, a dated Type 1 and a written Type 2 plan are the honest answer to give the customer. Talk to us about your calendar and we will tell you what is realistic.

Sources

Frequently asked questions

Is a SOC 2 Type 1 report enough to reassure a customer?
Rarely in the long run. A Type 1 confirms that controls are designed and in place at a given date, without looking back. Most procurement teams want proof that the controls operated over a period, which means a Type 2. The Type 1 remains useful as a milestone when a contract is pressing, provided you announce the date of the Type 2 that will follow.
How long is the observation period of a Type 2?
The standard does not fix a single duration; the period is agreed with the auditor. The large cloud providers we cite publish reports covering twelve months and chain the periods without interruption. A shorter first period is possible to obtain a first report sooner, then you extend it. What matters is that every control produces dated evidence from the first day to the last.
What happens between two SOC 2 reports?
The report carries an end date. Between that date and the next report, the organization issues a bridge letter stating that the controls have not changed. It is a self-attestation by management, not an auditor's opinion. Customers accept it for a few months, not indefinitely, which is why consecutive periods with no gap are worth planning.

Let's talk about your compliance program.

Last updated: 2026-09-20