Track: SOC 2 basics · Lesson 2 of 10
SOC 2 Type I vs Type II: which report do you need first?
Short answer
A Type I report looks at whether your controls are suitably designed at one point in time. A Type II report also tests whether they operated effectively over a period. Many customers expect Type II; a Type I can be a first step while that period runs.
By the SOC 2 Vendor Compare ledger desk · Published 2025-02-11 · Reviewed 2026-09-29 · Editorial assessment
What does a Type I report cover?
A Type I report gives the auditor's opinion on the description of your system and the design of your controls as of a specific date. It answers the question: if these controls run as described, would they meet the criteria? It does not say whether the controls actually ran over time, because no period of operation is tested.
What does a Type II report cover?
A Type II report covers the same description and design, and adds tests of operating effectiveness over a review period that you agree with the auditor. The auditor samples evidence from across that period: access reviews that happened, tickets that were approved, backups that ran. Exceptions, where a control did not work as described, are listed in the report.
Which one do customers ask for?
Security teams at larger customers usually ask for Type II, because it shows controls working over time. A Type I is still useful when a deal needs something now, or when a company wants to confirm its design before the review period starts. Ask your largest prospects which they accept before you plan the timeline.
How does the choice affect your software decision?
For a Type I, the heavy lifting is setup: policies, control mapping and the first round of evidence. For a Type II, the platform has to keep collecting evidence and flag failed controls for the whole review period, so integrations and continuous monitoring matter more. The integrations criterion and each vendor's published integration count are worth checking. If you want someone to run the process with you, compare the expert models in Dedicated expert, partner network or support desk: SOC 2 service models compared.
What about SOC 1 and SOC 3?
SOC 1 reports cover controls relevant to a customer's financial reporting, and they suit services such as payroll or billing. SOC 3 is a general-use summary of a SOC 2 examination that can be shared publicly, with less detail. Several vendors in our lineup list SOC 1 among their frameworks, including Scytale and Thoropass.
Can you go from Type I to Type II?
Yes, and many companies do. The Type I confirms the design; the review period for the Type II can start once controls run as designed. Evidence collected in the platform during that period becomes the auditor's sample. Keep the scope the same between the two reports where you can, so the Type II builds on the Type I work rather than reopening it.