SOC 2 Type 1 vs Type 2: which one your customer is asking for
A SOC 2 Type 1 report says your controls were suitably designed on one date. A Type 2 report says they were designed and also operated effectively across a period, and it includes the CPA firm’s tests and results. When an enterprise customer asks for “your SOC 2”, they almost always mean a current Type 2.
What is the difference between Type 1 and Type 2?
A Type 1 report covers the design of your controls at a single point in time. A Type 2 report covers a period of months and adds the CPA firm’s tests of whether those controls actually operated throughout it. Both are examinations performed under standards the AICPA sets for SOC engagements, and both describe the same system. The difference is the question they answer.
| Report | Type 1 | Type 2 |
|---|---|---|
| Question answered | Are the controls designed to meet the criteria? | Did they also operate effectively across the period? |
| Time covered | A single “as of” date | A period agreed with the CPA firm |
| Tests of operation | No | Yes, with results and any exceptions listed |
| What a buyer does with it | Treats it as a promise | Treats it as evidence |
Why do customers ask for a Type 2?
A procurement or vendor-risk team is trying to find out whether your controls work in practice: whether access reviews happened, whether changes were approved, whether leavers lost access on time. Only a Type 2 answers that, because only a Type 2 samples what actually happened over months.
Which one is your customer asking for? Almost always a current Type 2. Some buyers accept a Type 1 as a first step, usually with a committed date for the Type 2, but a Type 1 says nothing about whether the controls ran. The exceptions section matters more than most sellers expect. A clean Type 2 with a narrow scope can be worth less to a buyer than a candid one that covers the system they are actually buying.
When is a Type 1 worth getting?
A Type 1 earns its place when a deal needs something on paper now and the Type 2 period cannot have finished yet. It proves the scope is settled and the design has been examined, and it gives the buyer a date.
If no deal is waiting, many organizations skip it and start the Type 2 period directly, because the Type 1 is effort spent on a report most buyers will ask you to replace. Decide by asking the customer, in writing, what they will accept and by when. The sequence and lead times are in the SOC 2 readiness timeline.
What is a bridge letter, and when will a buyer accept one?
A bridge letter, sometimes called a gap letter, is a statement from your own management covering the months between the end of your last report period and today. It is a market convention rather than a report: it carries no assurance from the CPA firm, and experienced buyers read it that way. Buyers accept one for a short gap while the next report is being prepared. They stop accepting it when the gap is long or the letter mentions changes to the system that the last report never covered.
The practical fix is to plan report periods so they run back to back, and to keep the letter factual: what changed, what did not, and when the next report is due.
Who can issue a SOC 2, and how do you check the firm?
Only a licensed CPA firm can issue a SOC 2 report. A compliance platform, a consultancy or a readiness review cannot issue one, and that includes us. As of September 2026, the AICPA states that it will take action with respect to its members found to be unlicensed, not enrolled in peer review, or not following professional standards, and its Journal of Accountancy warned in February 2026 that promises of “fast and easy” reports threaten SOC credibility. Before you sign, confirm that the firm is licensed, ask about its peer review, and be wary of any offer that bundles the report with the software that generates the evidence.
Our part is the work before an audit: settling scope, closing control gaps, and making sure the evidence for a Type 2 period will exist when the CPA firm asks for it. That work is SOC 2 and ISO 27001 readiness. If you are still choosing between frameworks, start with SOC 2 vs ISO 27001; if the request came from a large customer, security for SaaS selling to enterprise covers the rest of what they will ask.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report covers the design of your controls at a single point in time. A Type 2 report covers a period of months and adds the CPA firm’s tests of whether those controls actually operated throughout it.
Which one is our customer asking for?
Almost always a current Type 2. Some buyers accept a Type 1 as a first step, usually with a committed date for the Type 2, but a Type 1 says nothing about whether the controls ran.
What is a SOC 2 bridge letter?
A bridge letter, sometimes called a gap letter, is a statement from your own management covering the months between the end of your last report period and today. It is a market convention rather than a report: it carries no assurance from the CPA firm, and experienced buyers read it that way.
Who can issue a SOC 2 report?
Only a licensed CPA firm can issue a SOC 2 report. A compliance platform, a consultancy or a readiness review cannot issue one, and that includes us.
How do you plan the first SOC 2 report?
Send us the customer’s request and a short description of the system in scope. The reply says which report fits the deadline and what has to be true before the period starts. More of our writing is indexed at writing.