← All postsHow-to

SOC 2 Type 1 vs Type 2: which one a customer will accept

Type 1 says the controls were designed properly on one day. Type 2 says they worked for months. Enterprise buyers ask for the second and accept the first only as a step towards it.

How-toS

Both are SOC 2 reports produced by a CPA firm against the same trust services criteria. The difference is what the auditor opines on. A Type 1 addresses whether the controls were suitably designed as at a specified date. A Type 2 addresses whether they were suitably designed and operated effectively throughout a period — commonly between three and twelve months.

That distinction decides which one satisfies a customer. A Type 1 tells a buyer that a system was described and the controls looked right on a Tuesday. A Type 2 tells them the controls actually ran. Enterprise security reviews ask for the second, and accept the first mainly as evidence that the second is coming.

SOC 2 Type 1 vs Type 2: where each one fits

  • Type 1 — first report for a young company, to unblock a deal while the observation period for a Type 2 runs. It is a milestone, not a destination.
  • Type 2 — the report enterprise buyers expect, renewed annually so that coverage is continuous.
  • A first Type 2 with a shorter period is common and accepted; subsequent ones normally cover twelve months.
  • Going straight to Type 2 is entirely possible and often the better use of money if no deal is waiting on a Type 1.
  • Neither is a certification. There is no pass mark and no certificate — there is an auditor’s opinion and a description of any exceptions.

Exceptions are not failures

A Type 2 report can contain exceptions — instances where a control did not operate as described — and still carry an unqualified opinion. Buyers who read many reports expect a small number and look at what they were, whether management responded, and whether they cluster in one area. A report with no exceptions at all is either a well-run organisation or a narrow scope, and experienced reviewers check which. Vendors should be ready to discuss their exceptions plainly rather than hoping the section is skipped.

Read the scope before the opinion. A clean report covering only the security criterion for one product tells a buyer nothing about the product they are buying or about availability. Scope is where reports differ most, and it is stated in the description rather than in the opinion letter.

What the report actually contains

Beyond the opinion, a report includes management’s description of the system, the criteria and related controls, and — for a Type 2 — the auditor’s tests and results. That description is written by the service organisation and is the part a careful customer reads most closely, because it defines what was examined. Subservice organisations appear here too: whether their controls are carved out or included changes what the report covers, and a carve-out means the buyer needs that provider’s own report as well.

Keeping the report and its distribution

Reports are confidential, distributed under agreement, and superseded annually. Ettex Records holds each report with its period, scope and the list of customers it was shared with, Ettex Docs keeps the description of the system with version history between cycles, and the gap-period statement issued between reports is covered in soc 2 bridge letter.

To be clear: this is records, not assurance, and none of it is audit advice. The opinion comes from a CPA firm, scope decisions have commercial consequences, and which report a specific customer will accept is a question worth asking them directly before commissioning either.

Frequently asked

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 opines on control design as at a date; Type 2 opines on design and operating effectiveness throughout a period.

Which do enterprise customers want?

Type 2. Type 1 is generally accepted only as an interim step while a Type 2 period runs.

Is SOC 2 a certification?

No. It is an attestation report containing an auditor’s opinion, a system description and, for Type 2, test results and any exceptions.

Do exceptions mean the report is bad?

Not necessarily. Reports can carry an unqualified opinion with exceptions; reviewers look at what they were and how management responded.

DK
Written by Daria K.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.