
A SOC 2 Type 1 report says your controls were suitably designed on a single date. A Type 2 report adds the auditor's tests of whether those controls operated effectively across a period, commonly several months to a year, which is why customers prefer it. SOC 1 is a different report: it covers controls that affect customers' financial reporting.
All of these reports come from an independent CPA firm. Our SOC 2 readiness services prepare a company for either type: the scope, the gap list, the controls and the evidence. This guide explains the report types, where SOC 1 and SOC 3 fit, and how to choose. For the basics, see what a SOC 2 report is, and for whether a small company needs one at all, read SOC 2 compliance for small business.
What is the difference between SOC 1 and SOC 2?
They examine different subjects. The AICPA describes SOC 1 as an examination of controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting, written for those customers and for the CPAs who audit their financial statements. SOC 2 examines controls relevant to security, availability, processing integrity, confidentiality or privacy, measured against the AICPA's Trust Services Criteria. Customers and business partners ask for it because they need to know how a vendor's system protects their data and keeps their service running.
SOC 3 covers the same ground as SOC 2 with far less detail. The AICPA treats it as a general use report that can be freely distributed, which is why companies post SOC 3 reports publicly and share SOC 2 reports only with customers and prospects, usually under a nondisclosure agreement.
| SOC 1 | SOC 2 | SOC 3 | |
|---|---|---|---|
| What it examines | Controls relevant to customers' financial reporting | Controls relevant to security, availability, processing integrity, confidentiality or privacy | The same subjects as SOC 2, summarized |
| Measured against | Control objectives tied to financial reporting | The AICPA Trust Services Criteria | The AICPA Trust Services Criteria |
| Written for | The customer and its financial statement auditors | Customers, prospects and their security or procurement teams | Anyone |
| How it is shared | With customers and their auditors | Selectively, usually under a nondisclosure agreement | Freely, often on a website |
| Report types | Type 1 or Type 2 | Type 1 or Type 2 | A general use summary without the detailed test results |
| Usually requested by | Customers whose financial statements depend on your service, such as payroll, billing or claims processing | Customers handing you their data, such as buyers of software, hosting or managed services | Prospects doing a first check |
That answers a common search, SOC 1 Type 2 vs SOC 2. The type describes how deep the examination goes; the number describes what it examines. A SOC 1 Type 2 tests controls over financial reporting across a period, and a SOC 2 Type 2 tests security-related controls across a period. Neither substitutes for the other, and a company whose service touches both may be asked for both.
SOC 2 Type 1 vs Type 2: what does each report cover?
The AICPA's own definition draws the line. A SOC 2 engagement reports on whether management's description of the system is fairly presented and whether the controls in it are suitably designed and, in a type 2 engagement, whether those controls operated effectively throughout a specified period. In practice:
| SOC 2 Type 1 | SOC 2 Type 2 | |
|---|---|---|
| Question it answers | Were the controls suitably designed? | Were they suitably designed, and did they work? |
| Time covered | A specific date | A period agreed with the CPA firm, commonly several months to a year |
| Testing | The auditor evaluates the description and the design of controls as of the date | The auditor also tests whether each control operated as described across the period |
| What the report contains | The auditor's opinion, management's assertion and the system description | All of that, plus the auditor's tests of controls and their results, including exceptions |
| Best for | A first report while controls are new | Customers that want evidence the controls work day to day |
| Earliest it can be issued | Once controls are designed and in place | After the observation period ends and fieldwork is complete |
SOC 2 Type 1 vs Type 2: which do you need first?
Start with what the customer asked for. Ask which report type, which criteria and which period its procurement team will accept, and get the answer in writing. Then use these rules of thumb:
- Get a Type 1 first when a deal needs a report soon, your controls are new, and the customer will accept a Type 1 while the Type 2 period runs.
- Go straight to a Type 2 when the customer requires one, your controls already produce records, or a Type 1 would cost time and fees you will spend again a few months later.
- Ask about SOC 1 if the request comes from a customer's finance team or external auditor, because their question is about financial reporting, not data security.
Every SOC 2 report covers the security criteria, the common criteria labeled CC1 to CC9. Availability, confidentiality, processing integrity and privacy are added only when customers need them, and each brings its own criteria and evidence. Our SOC 2 compliance checklist lists the controls and records for each one.
How long does each take?
Both reports start with readiness: scoping, a gap assessment and remediation. How long that takes depends on where you start; a company that already runs managed identity, devices and backups mostly needs policies, evidence and a few fixes. After readiness the calendars split:
- Type 1. Once the controls are designed and in place, the CPA firm examines them as of a date agreed with you, then writes the report.
- Type 2. The controls must run through the whole observation period before the auditor's fieldwork on that period can finish. The period is set with the CPA firm before it starts, commonly several months to a year, and the report follows the fieldwork.
Plan the calendar backward from the date your customer needs the report. Most companies renew a Type 2 every year, with each new period starting as the last one ends, so their coverage has no gap.
What does each cost?
A Type 2 costs more than a Type 1, mainly because the auditor tests samples of every control across the period instead of reviewing design on one date, and because your team spends that period producing evidence. We publish no prices, but every SOC 2 budget has the same four lines:
- Readiness work: scoping, the gap assessment and evidence planning.
- Technical remediation: MFA, device management, logging, backups and recovery testing, whatever the gap list finds.
- Compliance software, if you want a platform to track evidence. It observes controls; it does not configure them.
- The CPA firm's examination, priced on the report type, the criteria and systems in scope, and the length of the period.
Scope is the biggest lever on all four. Our SOC 2 audit cost guide breaks the lines down further.
How do you read a vendor's SOC 2 report?
Check the report type, the period covered, the criteria and systems in scope, and the auditor's opinion. In a Type 2, read the test results, because exceptions show where a control did not operate as described. Our vendor risk management guide covers what else to ask suppliers.
How does NetSys help with SOC 2?
We run readiness as an operating change, not a document exercise. Every control gets a named owner, a procedure and an artifact the auditor can test, and because we already run identity, devices, email and backups for managed clients, most security evidence comes from systems we operate anyway. We do not perform the examination. The AICPA notes that a CPA firm that designs or implements an attest client's systems can face threats to its independence, so the firm that builds your controls should not be the firm that audits them. Our agreements run month to month.
Frequently asked questions
Is SOC 2 Type 2 better than Type 1?
It is stronger evidence, not a different standard. Both reports use the same Trust Services Criteria. A Type 2 adds tests showing the controls operated across a period, so it answers the question customers care about most: whether the controls work day to day. A Type 1 is still useful as a first report while a Type 2 period runs.
Can you skip SOC 2 Type 1 and go straight to Type 2?
Yes, if the customer can wait. You engage the CPA firm for whichever examination you need. Going straight to Type 2 makes sense when your controls already produce records, because the observation period can start as soon as the scope is agreed. A Type 1 first makes sense when a deal needs a report sooner.
Do we need a SOC 1 or a SOC 2?
Ask what the requester is worried about. If a customer's auditors need comfort about your effect on its financial statements, as with payroll, billing or claims processing, that is SOC 1. If a customer needs to know how you protect its data and keep its service running, that is SOC 2. Some service companies need both.
Is a SOC 3 report enough for customers?
Rarely for procurement. A SOC 3 is a general use summary that leaves out the detail a security team reviews, such as the auditor's test results. It works as a public signal on a website. A customer doing vendor due diligence will usually ask for the SOC 2 itself, under a nondisclosure agreement.
How long is a SOC 2 report valid?
A SOC 2 report has no expiration date. It describes a date or a period, and customers judge how current that is, which is why most companies renew every year and start each new period when the last one ends.
Sources and further reading
- AICPA & CIMA: SOC suite of services, checked October 2026.
- AICPA & CIMA: SOC 1, SOC for Service Organizations: ICFR, checked October 2026.
- AICPA Guide: SOC 2 Reporting on an Examination of Controls at a Service Organization, checked October 2026.
- AICPA & CIMA: SOC 3, general use report, checked October 2026.
- AICPA: 2017 Trust Services Criteria, with revised points of focus (2022): the criteria and the definition of a SOC 2 engagement, checked October 2026.
- AICPA: Illustrative SOC 2 report: what a Type 2 report contains, checked October 2026.
Related reading
Cost GuidesSOC 2 Audit Cost: Readiness, Audit and Ongoing Work
Read Article
CybersecuritySOC 2 Compliance for Small Business: Do You Need It?
Read Article
ComplianceSOC 2 Compliance Checklist: Requirements by Trust Services Criteria
Read ArticleAlso on this topic: NIST vs ISO 27001 vs CIS Controls: Key Differences
Discuss soc 2 readiness services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
