Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOC 1 Type 2 — SOC 1 Type 1 vs Type 2: The Essential 2026 Comparison

SOC 1 Type 2 vs Type 1: The Essential 2026 Comparison

A SOC 1 Type 2 report covers a period; a Type 1 report covers a date. That single difference decides what a customer’s auditor can do with the document, how much evidence the service organisation has to keep, and how long the first engagement takes. This guide sets out what each type says, why user auditors ask for Type 2, when a Type 1 is the right first step, and how the period is chosen.

What this guide covers

SOC 1 Type 2 explained
A Type 1 report speaks to a date; a Type 2 report speaks to a period and includes the auditor’s tests.

SOC 1 Type 2 and Type 1: the definitions

Both types are defined in AT-C section 320, the AICPA standard issued as SSAE No. 18, and in ISAE 3402 internationally. Each type is a package of three documents: management’s description of the system, management’s written assertion, and the service auditor’s report. What differs is the question the assertion and the opinion answer.

SOC 1 Type 1 SOC 1 Type 2
Speaks to A specified date A specified period, start to end
Description Fairly presents the system as designed and implemented as of the date Fairly presents the system throughout the period, including relevant changes during it
Design of controls Suitably designed as of the date Suitably designed throughout the period
Operating effectiveness Not addressed Controls operated effectively throughout the period
Auditor’s tests Not included Included: a description of each test and its result, control by control
Evidence the user auditor gets That the controls exist and would work That the controls worked, across the period

A Type 1 report is a photograph. A SOC 1 Type 2 report is a film, and the auditor’s section 4 is the reel: for every control, what was tested, how many items, and whether any deviations were found.

Why user auditors ask for SOC 1 Type 2

A user entity’s auditor has to conclude on transactions across the user entity’s whole financial year. A report that says the controls were designed properly on 31 December gives no evidence that they operated in March. Without a SOC 1 Type 2 report the user auditor is left with three unattractive options: test at the service organisation itself, ask another auditor to, or treat the service as uncontrolled and expand substantive testing. All three cost more, and two of them land on the service organisation as extra visits.

That is why the AICPA’s own guidance for management describes the Type 2 engagement as the one usually performed and the Type 1 as performed very infrequently.

The same logic explains why a customer will chase a SOC 1 Type 2 report even when the contract does not mention it. The request originates with the customer’s auditor, arrives through the customer, and repeats every year. A service organisation that offers a Type 1 to a customer that needs a Type 2 has not answered the question.

When a Type 1 is the right first step

There are two situations in which the AICPA’s guidance describes a Type 1 as appropriate. The first is where user entities can exercise effective controls of their own over the service — the customer authorises, reconciles and reviews everything, so the service organisation’s operating effectiveness matters less to the user auditor. The second is a first report on a system where the service auditor cannot perform the procedures a Type 2 needs in the time available.

The second case is the common one. A service organisation that decides in September that it needs a report by December has no period of operating evidence to examine. A Type 1 as of a date in December, followed by a SOC 1 Type 2 for the period starting the day after, is a defensible sequence — provided the evidence retention, the control-owner attestations and management’s own testing start on day one of the Type 2 period. A period that has already passed cannot be reconstructed, and that is an expensive lesson to learn in fieldwork.

How the SOC 1 Type 2 period is chosen

Neither standard fixes the length of the period. The AICPA’s guidance for management says a report is most useful to user entities and their auditors when it covers a substantial portion of the period covered by the user entities’ financial statements, and gives a report covering at least nine months of the audited period as an example. Twelve-month periods and contiguous six-month reports are the two options the guidance describes, the latter for where customers’ year ends are spread.

The decision is made from data, not habit. A service organisation whose customers mostly close on 31 December wants a period ending close to that date. One whose customers are split between calendar and fiscal year ends may run two reports a year, or one report plus bridge letters. The gap between the period end and a customer’s year end is not covered by the report at all; it is covered by a bridge letter from management, which the auditor has no part in.

Five circumstances make a shorter first SOC 1 Type 2 period unavoidable, and the guidance lists them: the auditor is engaged too late for retrospective evidence, the system or its controls have run for less than a substantial portion of the year, controls changed significantly mid-year, it is the first report on the system, or a new law or regulation took effect inside the period. In each case the plan is a short first period expanding to a full one.

What changes for the service organisation between Type 1 and Type 2

The controls do not change. The evidence does. A SOC 1 Type 2 examination tests each control across the period, so for every control the organisation must be able to produce the record of every occurrence — every approved access request, every signed reconciliation, every reviewed job log — for the whole period, and must be able to show the population those records came from is complete. Manual controls must have been applied consistently by people with the competence and the authority to apply them, because that is the operating-effectiveness criterion in both standards.

  • Evidence retention from day one. A control whose records do not exist for a month cannot be tested for that month.
  • Management’s own testing. The assertion in a Type 2 report says the controls operated effectively; management needs a reasonable basis for saying so, and the auditor’s work is not that basis.
  • Change capture. The Type 2 description must include relevant changes to the system during the period — a manual control automated, a subservice organisation replaced, a system migrated. A change nobody captured is an omission in a document management asserts is complete.
  • Deviations. Every deviation, whoever finds it, is recorded, evaluated for cause and classified — acceptable within the expected rate, needing more testing, or showing the control did not operate.

The written assertion changes too. The Type 2 version adds a criterion — that the controls were consistently applied as designed throughout the period — and a statement that the description includes relevant details of changes. The representation letter the auditor asks management to sign at the end confirms the same things.

Reading a SOC 1 Type 2 report as the customer

The period is the first thing to check. A report for the year to 30 June supports a customer with a 31 December year end for half its year and no more. The second is the opinion: unmodified, or qualified on one or more objectives. The third is section 4, where each exception is reported against its control and the auditor states whether the objective was still achieved. The fourth is the list of complementary user entity controls, which the auditor’s report says the objectives depend on — those are the customer’s to perform.

Our SOC 1 report guide walks through the whole document; the SOC 2 Type 1 vs Type 2 comparison covers the same distinction for the security examination.

Moving from Type 1 to SOC 1 Type 2

The transition is a project with a hard start date. Before the period opens: every control’s evidence defined and retention switched on; owners and performers confirmed competent and authorised; management’s testing plan approved; the quarterly attestation cycle scheduled; the change log and the deviation register open; design gaps from the Type 1 examination remediated and the remediation operating. Anything missing on day one shortens the period the organisation can assert to for the controls affected.

The SOC 1 Toolkit carries the Type 1 to Type 2 transition plan, the report type and period selection memo with the customer year-end analysis, both assertions, the management testing plan and the quarterly attestation, alongside the description templates and the control objective library. If the first engagement is a Type 1 and the second must be a Type 2, the SOC 1 Toolkit is built for that sequence.

Further reading in this series: SOC 1 vs SOC 2, SSAE 18 explained, the SOC 1 audit checklist that sets out what must exist on day one of a Type 2 period, and SOC 1 audit cost, where the Type 1 versus Type 2 decision is the first driver.

Frequently asked questions

Is a SOC 1 Type 2 report better than a Type 1?

It answers a bigger question. A Type 1 says the controls were designed properly on a date; a Type 2 says they operated across a period, with the auditor’s tests to show it. For a customer’s financial-statement audit, only the Type 2 provides evidence of operation, which is why it is the one asked for.

How long does a SOC 1 Type 2 period have to be?

Neither AT-C 320 nor ISAE 3402 sets a minimum. The AICPA’s management guidance points to a substantial portion of the customers’ financial year, with nine months as an example, and twelve months is the established norm. Shorter first periods are common and are expanded in the following year.

Can you skip Type 1 and go straight to Type 2?

Yes. An organisation with mature controls and time to plan can go straight to Type 2. A Type 1 is a stepping stone when the period cannot be covered in time, not a prerequisite. The AICPA’s SOC 1 resources describe both engagements.

What is a Type 2 gap, and what fills it?

The interval between the end of the report period and the date a customer needs coverage to. A bridge letter from the service organisation’s management, stating whether the system and controls have changed, fills it; the auditor does not extend the opinion.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.