SOC 2 Type I or Type II: which one to do first, and what it actually costs

Type I is a photograph, Type II is a film. The choice changes your timeline by months and what a customer will accept. How to pick, how long each takes, and where the money goes.

The first enterprise customer asks for your SOC 2 report, you do not have one, and the sales cycle stops. That is how almost every SOC 2 project begins, which means the real question is not "which report is better" but "which one unblocks the deal soonest without wasting the work".

The difference in one line

A Type I report says the controls were designed appropriately and were in place on one specific date. A Type II report says the controls operated effectively over a period — usually three to twelve months.

Type I is a photograph. It says the fire extinguisher was on the wall on 30 September. Type II is a film: it says the extinguisher was on the wall every day for six months, was inspected monthly, and here is what happened the day someone took it down.

Buyers know the difference. A Type I satisfies a procurement team that needs to tick a box. A security review at a bank or a large SaaS platform will accept Type I once, with a commitment to Type II next year, and then ask for the Type II.

When Type I is the right call

Type I earns its place when a deal is blocked now and the alternative is waiting six months. You can be audit-ready in roughly two to three months from a standing start, and the report arrives weeks after the observation date rather than after an observation period.

It is also a genuinely useful forcing function. The gap assessment and remediation work for Type I is the same work Type II needs; you are not throwing it away. And going through an audit once removes a lot of uncertainty about what the auditor will ask for.

The cost of doing Type I is the audit fee — meaningful but not enormous — plus the fact that you will pay a second audit fee for the Type II within the year.

When to skip straight to Type II

Skip Type I if no deal is blocked this quarter. The Type II observation window can start as soon as the controls are in place, so the useful comparison is not "three months versus nine months" but "three months to a weaker report versus starting the clock now on the one that will be asked for anyway".

Start with a three-month observation window for the first Type II, then move to twelve months annually. A three-month window gets you a real report faster; the auditor may note the short period, but no buyer has ever rejected a three-month Type II that was followed by an annual one.

Choosing the Trust Services Criteria

Security — the common criteria — is mandatory. The other four are optional and each one adds scope, evidence and cost:

  • Availability: include it if you sell an SLA. Most B2B SaaS should.
  • Confidentiality: include it if you handle customer data under contractual confidentiality terms. Most should.
  • Processing integrity: only if you process transactions where correctness is the product — payments, payroll, billing.
  • Privacy: the heaviest. Only if customers specifically ask, and note that it is not the same as GDPR compliance and does not substitute for it.

Most companies should do Security, Availability and Confidentiality. Adding Privacy to a first audit because it sounds thorough is how a six-month project becomes a year.

Where the money and time actually go

The audit fee is usually the smaller half. The larger half is:

The readiness work. Access reviews, onboarding and offboarding records, vendor risk assessments, a risk assessment, incident response procedures that have been exercised, and a change management process with evidence. Most of this exists informally in an engineering organisation and has to be made visible.

Evidence collection during the observation window. This is the part that surprises people. For every month of the window, you need proof that controls ran: access reviews performed, backups tested, vulnerabilities triaged within the stated timeframe, changes approved. Collecting this by hand at the end does not work, because the evidence has to be dated across the period. Plan automated evidence collection before the window opens, not during it.

Engineering remediation. Usually MFA everywhere, centralised logging with retention, formal offboarding, encryption in transit and at rest, and a documented, tested restore.

If you already have ISO 27001

The overlap is large — one estimate puts it around 80 percent of the underlying controls — but the reports are not interchangeable. ISO 27001 certifies a management system against a standard; SOC 2 is an attestation by a CPA firm about your controls, written for your customers' auditors. European buyers tend to ask for ISO; North American buyers tend to ask for SOC 2.

If you have one and need the other, the gap is mostly in the evidence format and in the SOC 2 requirement that controls be described in your own words and then tested against that description. It is a few months, not a restart. Doing both from scratch simultaneously with a shared control set and a shared evidence pipeline is cheaper than doing them a year apart.

ConsultorIA

Want this done on your cloud?

A ten-day read-only assessment is free, and Skyline lets you see your estate on a map before you write to us.

Related articles