SOC 2 Type I and Type II

The road to a SOC 2 report

What the year actually looks like, where the time really goes, and the five ways companies turn a four-month project into a fourteen-month one.

Type I or Type II?

Type I says the controls were designed properly on one date. Type II says they actually operated over a window, usually three to twelve months. Enterprise buyers want Type II. Type I is worth doing only when you need something to show a buyer within weeks and you are committed to the Type II immediately after. Doing Type I as an end in itself buys you a document most procurement teams will not accept.

SOC 2 is an attestation, not a certification. A CPA firm examines whether the controls you described were designed properly and, for a Type II, whether they operated over a period of time. Nobody grants you a certificate. You get a report, and your customers read it.

Read this if

  • A customer contract or a security review is gating on it, with a date attached
  • You sell software or a service that holds someone else's data
  • You are between roughly 20 and 500 people and this is your first time
  • You have bought a compliance automation platform and the percentage is not moving
The roadmap

What the program actually looks like.

Durations assume a first attempt with a team that has other work to do. They are the numbers we would give you on a call, not the ones in a sales deck.

Scope the audit

2 to 4 weeks

Decide which systems, which trust services criteria and which entity are in scope. This single decision drives cost, effort and duration more than anything else you will do. Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are each optional and each adds real work.

You come out with: A written scope and boundary, agreed with your executive team, and a defensible reason for every system left out.

Gap assessment

2 to 3 weeks

Compare current practice against the criteria in scope. Split findings three ways: audit-blocking, deal-blocking, and neither. Only the first two earn engineering time before the audit.

You come out with: A ranked remediation plan with owners, effort estimates and a critical path to your target report date.

Remediate and design controls

4 to 12 weeks

Build the controls that are missing and redesign the ones that exist but would not survive fieldwork. Design them around how your team already works, or you will be fighting them every quarter for years.

You come out with: Working controls, a policy set written to be followed, and a named human owner for every control who can explain it out loud.

Operate through the observation window

3 to 12 months

This is the part nobody can compress. For a Type II, the auditor examines evidence across a period. Three months is the shortest window most auditors will accept; six to twelve is what enterprise buyers prefer to see. The window starts when the controls genuinely operate, not when you decide it starts.

You come out with: Continuous evidence: access reviews performed, tickets closed, alerts triaged, onboarding and offboarding records, change approvals.

Auditor fieldwork

3 to 6 weeks

The auditor samples evidence, interviews control owners and tests operating effectiveness. Your job here is logistics and fast, accurate answers. Engineers should be involved only where they are genuinely needed.

You come out with: Requested evidence delivered on time, exceptions understood before they are written down, and management responses drafted for anything that lands.

Report and sustain

2 to 4 weeks, then annual

The report issues. Then the real question: will year two be a repeat of year one, or a routine? That is decided by whether evidence is produced by working normally or by a quarterly scramble.

You come out with: The report, a customer-facing trust package, and an annual calendar that keeps the next one boring.
Where the time goes

The five things that consume the calendar.

None of these are the parts people budget for, and all of them are the parts that slip.

  • The observation window. It is calendar time and no amount of money shortens it.
  • Access reviews across every in-scope system, done properly rather than as a signature on a CSV export.
  • Vendor management, because SOC 2 asks about your subservice organizations and most companies have never listed them.
  • The system description, a narrative document that auditors judge and customers read, and that no platform generates for you.
  • Waiting for an auditor with capacity, which in Q4 can be six weeks on its own.
Cost drivers

What moves the number.

Two organizations of the same size can differ several-fold on price. This is usually why.

  • Number of trust services criteria beyond Security
  • Number of in-scope systems and cloud environments
  • Length of the observation window
  • Whether you have any control ownership internally, or none
  • Headcount, because auditors price partly on the size of the population they sample
Deliverables

What you have to produce.

Every one of these will be asked for. Missing any of them is a finding.

ArtifactWhat it has to contain
Scope and boundary documentWhat is in, what is out, and the reasoning for both
Policy setWritten to match reality, not a downloaded template library
Risk assessmentDocumented, dated, and revisited, because the auditor will ask when you last did it
System descriptionThe narrative at the front of the report describing your service and its controls
Evidence repositoryOrganized so an auditor can walk it without a guide
Vendor inventorySubservice organizations, what they do, and their own reports
Management assertionYour formal statement that the description is fair and controls operated
How it goes wrong

Five failures we see repeatedly.

Each of these turns a manageable program into an expensive one. All five are avoidable at the start and very hard to fix in the middle.

Scoping by accident

Nobody makes a deliberate decision about the boundary, so the whole corporate estate ends up in scope. The control surface roughly doubles, the evidence load doubles with it, and the customer gets no additional assurance for any of it.

Believing the platform is the program

Vanta, Drata and Secureframe collect evidence continuously and that is genuinely useful. None of them can scope an audit, design a control, write the system description or argue with an auditor. The dashboard goes green while the program underneath is not defensible.

Starting the window too early

The observation period begins and the controls are not really operating yet. Three months later the sample comes back with gaps, and the choice is a qualified report or restarting the clock.

Treating the system description as boilerplate

It is the part of the report your customers actually read. A vague or inaccurate one undermines an otherwise clean opinion, and a customer who spots the gap between the description and reality will ask about it.

Choosing the auditor on price alone

The cheapest quote is often a firm that will sample lightly and issue quickly. That feels efficient until an enterprise buyer's security team recognizes the name and discounts the report.

Questions

What people ask us about SOC 2.

How long does it really take, start to finish?
For a first Type II with a three-month window and controls that mostly do not exist yet: six to nine months. With a twelve-month window: twelve to fifteen. A Type I alone can be done in three to four months. Anyone promising a Type II in eight weeks is either selling a Type I or planning to start the window before the controls work.
Do we need a compliance platform?
Not strictly, but by year two you will want one. Automated evidence collection turns the annual repeat from a project into a routine. Buy it for what it does, which is the evidence pipeline, and do not expect it to make the judgment calls.
What does it cost?
The audit fee is usually the smaller number. Readiness work, remediation and the internal time to operate controls typically exceed it several times over. Be suspicious of any proposal that quotes only the audit.
Can we reuse this for ISO 27001?
Substantially, yes. The control sets overlap heavily and the evidence often serves both. Carrying two frameworks should not mean maintaining two control sets, and if you know both are coming, map once at the start rather than twice.

Want this run for you?

We run these programs end to end: scoping, control design, evidence, auditor management, and the operating rhythm that keeps year two boring.