SOC 2 is not a certification. It is an attestation report, issued by a licensed CPA firm under the AICPA's attestation standards, describing the controls a service organisation has in place against the Trust Services Criteria and, in one of the two report types, whether those controls worked over a period.
The difference between the two types is the single most common question we hear from companies approaching their first SOC 2, so here it is in full.
What each report says
Type I reports on the design of controls as of a specific date. The auditor confirms that the controls you describe exist, are suitably designed to meet the criteria, and were implemented on that date. It says nothing about whether they kept working the week after.
Type II reports on design and operating effectiveness over a period, called the observation or review period. The auditor samples evidence across that period: access reviews that were actually performed each quarter, tickets that were actually approved before deployment, alerts that were actually triaged. The period is commonly six or twelve months, and three months is the practical minimum most firms will accept for a first report.
Both reports cover whichever Trust Services Criteria you put in scope. Security (the common criteria) is mandatory. Availability, processing integrity, confidentiality and privacy are optional additions, and each one you add brings more controls to test.
What buyers actually accept
Enterprise security teams and procurement functions want a Type II. A Type I tells them that on one day your controls looked right; it does not tell them the controls are habits. Many vendor-risk programmes will not accept a Type I at all, or will accept it only with a commitment to deliver a Type II within a stated number of months.
That does not make the Type I useless. It has three legitimate jobs.
A first milestone for a young company. If you have just built your control environment, you cannot produce a Type II until the observation period has run. A Type I lets you show a prospect something signed by an auditor now, while the clock runs on the Type II.
A design check before you commit. Going through a Type I forces the control descriptions, the system description and the scoping decisions to be written down and reviewed. Problems found here are cheap to fix. Problems found six months into a Type II observation period cost you the period.
A contractual bridge. Some deals close on a Type I plus a dated commitment. Whether that works depends on the buyer, so ask before assuming.
The case against doing a Type I is cost and time. You pay for an examination whose report most buyers will discount, and the observation period for the Type II does not shorten because you did one. If you can start the observation period today and your buyers will wait, skip straight to the Type II.
The observation period, in practice
The period begins when your controls are in place and operating. Not when you decided to do SOC 2, not when you bought a compliance platform, and not when you started collecting evidence, but when the controls as described are running. If a control is added part way through, the auditor will note the date and may test it only from then, which shows up as a qualification in the report.
During the period, the discipline is evidence. Every control that says "quarterly" needs a quarterly artefact. Every control that says "all changes are approved" needs a population of changes the auditor can sample from and an approval trail on each. The failure mode is not usually a control that does not exist; it is a control that ran but left no record, which to an auditor is the same thing.
At the end of the period, fieldwork takes several weeks. The auditor requests populations, selects samples, reviews evidence and follows up on exceptions. Exceptions are not the end of the world: a Type II report can be unqualified while listing exceptions, as long as management's response is credible and the exceptions do not undermine the criteria. A pattern of exceptions in one area can lead to a qualified opinion on that criterion, which buyers will notice.
Bridge letters
A Type II report is dated. Its usefulness decays as the report period recedes, and a buyer looking at a report whose period ended nine months ago will ask what has happened since. The bridge letter (or gap letter) is a short statement from management, not the auditor, that no material changes to the control environment have occurred between the end of the report period and the date of the letter. Most companies issue them on request, and most buyers accept one covering up to roughly three months. Beyond that, they will want the next report.
This is why most organisations move to a rolling annual Type II with a twelve-month period: the report is always reasonably fresh, and the bridge letter covers the fieldwork gap.
Who can issue the report
Only a CPA firm licensed in the United States can issue a SOC 2 report, because it is an attestation under AICPA standards. Firms outside the US can and do perform the fieldwork, but the report is signed by the CPA firm. When you engage an auditor, ask who signs. The compliance automation platforms that many companies use to collect evidence do not issue reports; they connect you to a firm that does.
Independence rules apply. The firm that issues your report cannot have designed your controls or written your policies for you, which is why readiness consulting and the audit itself are usually separate engagements with separate people.
A sensible sequence
For a company starting from nothing with a buyer waiting: readiness work to design and implement controls, a Type I as soon as the controls are in place if the buyer needs paper now, then a Type II over the following three to six months, then annual twelve-month Type II reports from there.
For a company with a reasonable control environment and patient buyers: start the observation period, skip the Type I, and go straight to a Type II at six months.
For a company that already holds ISO 27001: the controls overlap substantially and a combined engagement, where one audit team produces both the ISO surveillance result and the SOC 2 Type II, is often the most efficient route. Not every firm can do both, so this is a scoping question to raise at the outset.
