Last updated: September 2026
Most B2B SaaS companies should start with a SOC 2 Type 1 if a deal is waiting on a report in the next few months, and go straight to a Type 2 observation window if nobody is waiting. A Type 1 report says your controls were designed properly as of a single date. A Type 2 report says they also operated effectively over a period, usually several months, and it is the one enterprise buyers eventually expect to keep on file. The two are not competing options, so the real decision is about timing: what you can hand a prospect this quarter, and how to build the evidence once so it serves both reports.
If you have just told a prospect’s security team that you are “getting SOC 2”, this post is for you. It explains what each report proves, why procurement teams usually end up asking for a Type 2, how to sequence the work so you do not collect evidence twice, and what to tell your sales team about the calendar. We went through both audits ourselves at Skycloak, so we will use our own timeline as a worked example.
What is the difference between SOC 2 Type 1 and Type 2?
SOC 2 is an attestation framework from the American Institute of Certified Public Accountants (AICPA). An independent CPA firm examines your controls against the AICPA’s Trust Services Criteria, whose current version is the 2017 criteria with revised points of focus published in 2022. Security is always in scope, and availability, processing integrity, confidentiality and privacy are optional additions. The Type 1 and Type 2 labels describe what the auditor tests, not which criteria are covered.
| SOC 2 Type 1 | SOC 2 Type 2 | |
|---|---|---|
| Question it answers | Were the controls designed properly? | Did the controls actually work? |
| Time covered | A single date (“as of”) | A period of months (the observation window) |
| What the auditor tests | Design and implementation of controls | Design, plus operating effectiveness through the whole window |
| Evidence needed | Policies, configuration, a sample showing each control exists | Records across the window: tickets, reviews, logs, approvals |
| How buyers treat it | A useful first step that keeps a deal moving | What most enterprise procurement teams want on file |
People often say “SOC 2 certified”, and we do too, but strictly speaking SOC 2 is a report containing an auditor’s opinion rather than a certificate. That matters for one practical reason: a prospect’s security team will ask for the report itself, usually under NDA, and read the auditor’s opinion and any exceptions it lists.
What a Type 1 proves
A Type 1 report is a point-in-time review. The auditor checks that each control you describe exists and is designed to meet the criteria on the report date. It can be produced relatively quickly because nothing has to be observed over time, which is why companies doing this for the first time often start here.
What a Type 2 proves
A Type 2 report covers an observation window, and the auditor samples evidence from across that window to confirm the controls were followed in practice. If your policy says access is reviewed every quarter, the auditor wants to see the reviews that happened during the window, with dates and outcomes. In our experience most audit firms run a first window of a few months and a full year after that, and the AICPA’s criteria do not fix a single length.
Why do enterprise buyers eventually ask for Type 2?
A Type 1 shows that you had the right controls on one day, and a buyer cannot tell from it whether those controls kept working the week after. A Type 2 answers that question with evidence from an auditor, which is why it is the report most procurement teams want before a renewal or a larger contract. In our experience a Type 1 is often accepted to get a first contract signed, with the expectation that a Type 2 will follow.
Buyers also care about how recent the report is. A report describes a past period, so as it ages, customers start asking what has happened since. The common answer is a bridge letter (sometimes called a gap letter), a short statement from management covering the time between the end of the last report period and today. It helps, but it is your word rather than the auditor’s, so it only stretches a report so far. Plan on a new Type 2 every year once you have the first one.
If you are unsure which items a buyer’s security review will focus on, our post on what vendor security questionnaires ask about login covers the identity section in detail, and the vendor risk brief for your CTO covers the wider review.
Should you get a Type 1 first or go straight to Type 2?
It depends on whether a deal is waiting. There is no rule that you must do a Type 1 before a Type 2, so the Type 1 is only worth its cost if having a report sooner changes something.
Start with a Type 1 if:
- A named prospect needs a report within the next quarter and will accept a Type 1 for now.
- You have never been audited and want an auditor’s view of your control design before the observation window starts, so that design gaps are found early rather than showing up as exceptions in your Type 2.
Go straight to a Type 2 window if:
- Nobody is waiting on a report this quarter.
- Your controls are already running and producing records, for example because you have followed a framework informally for a while.
- The buyers you sell to have told you a Type 1 will not satisfy them.
Our own sequence is a concrete example. Skycloak completed its SOC 2 Type 1 audit in December 2024 and its Type 2 audit in April 2025, moving into the Type 2 observation period directly after the Type 1. That gave us a report to share with customers early while the evidence for the Type 2 built up, and it took about four months from the Type 1 report to the Type 2 report. Our post on Skycloak’s SOC 2 audits describes what was in scope.
How do you avoid collecting the evidence twice?
Treat the Type 1 as the start of the Type 2, not as a separate project. The controls, owners and tools you set up for the Type 1 should be the same ones that run during the observation window, so that every quarterly review and every access change from that point on is already Type 2 evidence.
A few habits make this work:
- Decide the control set once. Write each control with an owner, a frequency and the record it produces. If a control produces no record, the auditor cannot test it over time.
- Automate the records you can. Evidence that comes from systems, such as sign-in logs, access changes and deployment approvals, is easier to produce for a whole window than evidence someone has to remember to write down.
- Start the window when the controls are actually running. If your quarterly access review has never happened, run the first one before the window opens rather than hoping to fit it in.
- Fix design findings before the window. A gap found in the Type 1 is cheap to fix. The same gap during the Type 2 becomes an exception in the report your customers read.
Where identity controls fit
Much of what a SOC 2 auditor tests comes back to who can access what. The logical access controls in the Trust Services Criteria, the CC6 series, cover how users are registered and authorised, how access follows roles, and how it is removed when people leave. In practice that means single sign-on for internal tools, enforced multi-factor authentication, role-based access, a regular access review, and prompt offboarding. If your product offers SSO to customers, the same work also answers a large part of their security questionnaire.
This is also where vendors show up in your audit. If you rely on a provider for identity, hosting or email, your auditor will want to see how you assess them, which usually means collecting their SOC 2 reports and reviewing the user controls those reports expect you to operate. You can see how we share our own report on the Skycloak trust page, and what it covers on our security page.
What should you tell the deal desk about the calendar?
Give sales a range, not a date, and tie each milestone to something they can tell the prospect. Every audit firm schedules differently, so the numbers below are the shape of a typical first-time timeline rather than a promise, and your auditor’s own estimate should replace them as soon as you have it.
- Readiness (a few weeks to a few months). Choose an audit firm, write the controls, close obvious gaps and start producing records. The length depends mostly on how much is already in place.
- Type 1 audit (a matter of weeks after readiness). The auditor tests design as of a date and issues the report. This is the first thing sales can actually share.
- Type 2 observation window (several months). The controls run and the evidence accumulates. Sales can share the Type 1 and, if your audit firm is willing to provide one, a letter confirming the Type 2 engagement is under way.
- Type 2 report (some weeks after the window closes). The auditor tests the window and issues the report, which then renews every year.
The most useful thing to tell a prospect is exactly which of these stages you are in, what they can have today, and when the next report is expected. In our experience security teams are comfortable with an honest timeline, and deals stall far more often when a promised report date slips.
Frequently asked questions
Is a SOC 2 Type 2 better than a Type 1?
It proves more, because it covers months of operation rather than a single date, and most enterprise buyers expect it eventually. A Type 1 still has a place as a faster first report that keeps a deal moving while the Type 2 observation window runs.
Can you skip SOC 2 Type 1 and go straight to Type 2?
Yes. There is no requirement to complete a Type 1 first. Skipping it makes sense when no prospect needs a report soon and your controls are already producing evidence. A Type 1 is mainly useful when you need something to share sooner.
How long is a SOC 2 Type 2 observation period?
There is no single required length. In our experience a first Type 2 usually covers a few months, and later reports usually cover a full year so that there is no gap between one report and the next.
How long does a SOC 2 report stay valid?
A SOC 2 report does not have a formal expiry date, but customers judge it by how recent the covered period is. Most expect a new report each year, and a bridge letter from management can cover the months between the end of the last period and today.
Does ISO 27001 replace SOC 2?
Sometimes. In our experience many buyers, particularly in Europe, accept ISO 27001 certification as an alternative, while many North American buyers ask for SOC 2 specifically. Check what your largest prospects request before choosing, because the two frameworks overlap enough that doing both later is manageable.
Sources
- AICPA, “2017 Trust Services Criteria (with revised points of focus, 2022)” (not reachable from our research environment), https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
- AICPA, “SOC 2: SOC for Service Organizations: Trust Services Criteria” (not reachable from our research environment), https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
- Skycloak, “Skycloak Is SOC 2 Type 2 Certified: What We Audited and Why It Matters” (Type 1 in December 2024, Type 2 in April 2025), https://skycloak.io/blog/skycloak-is-now-soc-2-type-1-certified/