SAM registration: free, annual, and the thing that expires quietly
Registration costs nothing and lapses on a date nobody diarises. An expired entity cannot be awarded a contract or paid on an existing one.
Type 1 says the controls were designed properly on one day. Type 2 says they worked for months. Enterprise buyers ask for the second and accept the first only as a step towards it.
Both are SOC 2 reports produced by a CPA firm against the same trust services criteria. The difference is what the auditor opines on. A Type 1 addresses whether the controls were suitably designed as at a specified date. A Type 2 addresses whether they were suitably designed and operated effectively throughout a period — commonly between three and twelve months.
That distinction decides which one satisfies a customer. A Type 1 tells a buyer that a system was described and the controls looked right on a Tuesday. A Type 2 tells them the controls actually ran. Enterprise security reviews ask for the second, and accept the first mainly as evidence that the second is coming.
A Type 2 report can contain exceptions — instances where a control did not operate as described — and still carry an unqualified opinion. Buyers who read many reports expect a small number and look at what they were, whether management responded, and whether they cluster in one area. A report with no exceptions at all is either a well-run organisation or a narrow scope, and experienced reviewers check which. Vendors should be ready to discuss their exceptions plainly rather than hoping the section is skipped.
Read the scope before the opinion. A clean report covering only the security criterion for one product tells a buyer nothing about the product they are buying or about availability. Scope is where reports differ most, and it is stated in the description rather than in the opinion letter.
Beyond the opinion, a report includes management’s description of the system, the criteria and related controls, and — for a Type 2 — the auditor’s tests and results. That description is written by the service organisation and is the part a careful customer reads most closely, because it defines what was examined. Subservice organisations appear here too: whether their controls are carved out or included changes what the report covers, and a carve-out means the buyer needs that provider’s own report as well.
Reports are confidential, distributed under agreement, and superseded annually. Ettex Records holds each report with its period, scope and the list of customers it was shared with, Ettex Docs keeps the description of the system with version history between cycles, and the gap-period statement issued between reports is covered in soc 2 bridge letter.
To be clear: this is records, not assurance, and none of it is audit advice. The opinion comes from a CPA firm, scope decisions have commercial consequences, and which report a specific customer will accept is a question worth asking them directly before commissioning either.
Type 1 opines on control design as at a date; Type 2 opines on design and operating effectiveness throughout a period.
Type 2. Type 1 is generally accepted only as an interim step while a Type 2 period runs.
No. It is an attestation report containing an auditor’s opinion, a system description and, for Type 2, test results and any exceptions.
Not necessarily. Reports can carry an unqualified opinion with exceptions; reviewers look at what they were and how management responded.
Registration costs nothing and lapses on a date nobody diarises. An expired entity cannot be awarded a contract or paid on an existing one.
Setting an option strike price too low is not a company problem — the tax consequences land on the employees who accepted the grant.
A rent roll is a snapshot of income, and every reader of it is checking the same things — term expiries, arrears and whether the numbers tie to the leases.