HomeBlogCompliance

SOC 2 Type 1 vs Type 2 (and SOC 1 vs SOC 2) Explained

Pixel-art illustration of a robot on a pirate ship's deck holding up a glowing blue shield against red bug-shaped threats above stormy waves

A SOC 2 Type 1 report says your controls were suitably designed on a single date. A Type 2 report adds the auditor's tests of whether those controls operated effectively across a period, commonly several months to a year, which is why customers prefer it. SOC 1 is a different report: it covers controls that affect customers' financial reporting.

All of these reports come from an independent CPA firm. Our SOC 2 readiness services prepare a company for either type: the scope, the gap list, the controls and the evidence. This guide explains the report types, where SOC 1 and SOC 3 fit, and how to choose. For the basics, see what a SOC 2 report is, and for whether a small company needs one at all, read SOC 2 compliance for small business.

What is the difference between SOC 1 and SOC 2?

They examine different subjects. The AICPA describes SOC 1 as an examination of controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting, written for those customers and for the CPAs who audit their financial statements. SOC 2 examines controls relevant to security, availability, processing integrity, confidentiality or privacy, measured against the AICPA's Trust Services Criteria. Customers and business partners ask for it because they need to know how a vendor's system protects their data and keeps their service running.

SOC 3 covers the same ground as SOC 2 with far less detail. The AICPA treats it as a general use report that can be freely distributed, which is why companies post SOC 3 reports publicly and share SOC 2 reports only with customers and prospects, usually under a nondisclosure agreement.

SOC 1SOC 2SOC 3
What it examinesControls relevant to customers' financial reportingControls relevant to security, availability, processing integrity, confidentiality or privacyThe same subjects as SOC 2, summarized
Measured againstControl objectives tied to financial reportingThe AICPA Trust Services CriteriaThe AICPA Trust Services Criteria
Written forThe customer and its financial statement auditorsCustomers, prospects and their security or procurement teamsAnyone
How it is sharedWith customers and their auditorsSelectively, usually under a nondisclosure agreementFreely, often on a website
Report typesType 1 or Type 2Type 1 or Type 2A general use summary without the detailed test results
Usually requested byCustomers whose financial statements depend on your service, such as payroll, billing or claims processingCustomers handing you their data, such as buyers of software, hosting or managed servicesProspects doing a first check

That answers a common search, SOC 1 Type 2 vs SOC 2. The type describes how deep the examination goes; the number describes what it examines. A SOC 1 Type 2 tests controls over financial reporting across a period, and a SOC 2 Type 2 tests security-related controls across a period. Neither substitutes for the other, and a company whose service touches both may be asked for both.

SOC 2 Type 1 vs Type 2: what does each report cover?

The AICPA's own definition draws the line. A SOC 2 engagement reports on whether management's description of the system is fairly presented and whether the controls in it are suitably designed and, in a type 2 engagement, whether those controls operated effectively throughout a specified period. In practice:

SOC 2 Type 1SOC 2 Type 2
Question it answersWere the controls suitably designed?Were they suitably designed, and did they work?
Time coveredA specific dateA period agreed with the CPA firm, commonly several months to a year
TestingThe auditor evaluates the description and the design of controls as of the dateThe auditor also tests whether each control operated as described across the period
What the report containsThe auditor's opinion, management's assertion and the system descriptionAll of that, plus the auditor's tests of controls and their results, including exceptions
Best forA first report while controls are newCustomers that want evidence the controls work day to day
Earliest it can be issuedOnce controls are designed and in placeAfter the observation period ends and fieldwork is complete

SOC 2 Type 1 vs Type 2: which do you need first?

Start with what the customer asked for. Ask which report type, which criteria and which period its procurement team will accept, and get the answer in writing. Then use these rules of thumb:

  • Get a Type 1 first when a deal needs a report soon, your controls are new, and the customer will accept a Type 1 while the Type 2 period runs.
  • Go straight to a Type 2 when the customer requires one, your controls already produce records, or a Type 1 would cost time and fees you will spend again a few months later.
  • Ask about SOC 1 if the request comes from a customer's finance team or external auditor, because their question is about financial reporting, not data security.

Every SOC 2 report covers the security criteria, the common criteria labeled CC1 to CC9. Availability, confidentiality, processing integrity and privacy are added only when customers need them, and each brings its own criteria and evidence. Our SOC 2 compliance checklist lists the controls and records for each one.

How long does each take?

Both reports start with readiness: scoping, a gap assessment and remediation. How long that takes depends on where you start; a company that already runs managed identity, devices and backups mostly needs policies, evidence and a few fixes. After readiness the calendars split:

  1. Type 1. Once the controls are designed and in place, the CPA firm examines them as of a date agreed with you, then writes the report.
  2. Type 2. The controls must run through the whole observation period before the auditor's fieldwork on that period can finish. The period is set with the CPA firm before it starts, commonly several months to a year, and the report follows the fieldwork.

Plan the calendar backward from the date your customer needs the report. Most companies renew a Type 2 every year, with each new period starting as the last one ends, so their coverage has no gap.

What does each cost?

A Type 2 costs more than a Type 1, mainly because the auditor tests samples of every control across the period instead of reviewing design on one date, and because your team spends that period producing evidence. We publish no prices, but every SOC 2 budget has the same four lines:

  • Readiness work: scoping, the gap assessment and evidence planning.
  • Technical remediation: MFA, device management, logging, backups and recovery testing, whatever the gap list finds.
  • Compliance software, if you want a platform to track evidence. It observes controls; it does not configure them.
  • The CPA firm's examination, priced on the report type, the criteria and systems in scope, and the length of the period.

Scope is the biggest lever on all four. Our SOC 2 audit cost guide breaks the lines down further.

How do you read a vendor's SOC 2 report?

Check the report type, the period covered, the criteria and systems in scope, and the auditor's opinion. In a Type 2, read the test results, because exceptions show where a control did not operate as described. Our vendor risk management guide covers what else to ask suppliers.

How does NetSys help with SOC 2?

We run readiness as an operating change, not a document exercise. Every control gets a named owner, a procedure and an artifact the auditor can test, and because we already run identity, devices, email and backups for managed clients, most security evidence comes from systems we operate anyway. We do not perform the examination. The AICPA notes that a CPA firm that designs or implements an attest client's systems can face threats to its independence, so the firm that builds your controls should not be the firm that audits them. Our agreements run month to month.

Frequently asked questions

Is SOC 2 Type 2 better than Type 1?

It is stronger evidence, not a different standard. Both reports use the same Trust Services Criteria. A Type 2 adds tests showing the controls operated across a period, so it answers the question customers care about most: whether the controls work day to day. A Type 1 is still useful as a first report while a Type 2 period runs.

Can you skip SOC 2 Type 1 and go straight to Type 2?

Yes, if the customer can wait. You engage the CPA firm for whichever examination you need. Going straight to Type 2 makes sense when your controls already produce records, because the observation period can start as soon as the scope is agreed. A Type 1 first makes sense when a deal needs a report sooner.

Do we need a SOC 1 or a SOC 2?

Ask what the requester is worried about. If a customer's auditors need comfort about your effect on its financial statements, as with payroll, billing or claims processing, that is SOC 1. If a customer needs to know how you protect its data and keep its service running, that is SOC 2. Some service companies need both.

Is a SOC 3 report enough for customers?

Rarely for procurement. A SOC 3 is a general use summary that leaves out the detail a security team reviews, such as the auditor's test results. It works as a public signal on a website. A customer doing vendor due diligence will usually ask for the SOC 2 itself, under a nondisclosure agreement.

How long is a SOC 2 report valid?

A SOC 2 report has no expiration date. It describes a date or a period, and customers judge how current that is, which is why most companies renew every year and start each new period when the last one ends.

Sources and further reading

SOC 2 Readiness Services

Discuss soc 2 readiness services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore SOC 2 Readiness Services 845-203-3914