Sooner or later an enterprise deal stalls on a security questionnaire, and the line holding it up asks for a SOC 2 Type 2. Most explanations of what that means are written by companies selling you one, which is a bad place to start.
The short version: Type 2 is about a stretch of time. Type 1 is about a day. Everything else follows from that. I published a longer treatment of this over on DevToolLab, including the full report-reading procedure, so this is the condensed pass.
The distinction the whole thing rests on
A SOC 2 Type 2 is an examination by a licensed CPA firm asking two questions at once: were the controls designed properly, and did they actually run that way across a stated window of time. The dates are printed on the report and every conclusion inside is bounded by them.
A Type 1 asks only the first question, as of one calendar date.
Why that gap matters is easiest to see with a broken control. Suppose employee offboarding works fine in January, quietly breaks in April, and gets repaired in July. A Type 1 stamped August looks at a healthy control and says so, correctly. A Type 2 spanning January through August pulls samples from the whole run and surfaces the April failures. Buyers ask for Type 2 because it is the only one of the two that can find something.
| Type 1 | Type 2 | |
|---|---|---|
| Question asked | Are controls designed well | Designed well and operating |
| Window | One date | A start date and an end date |
| Evidence | Snapshot | Samples drawn across the window |
| Finds | Design gaps | Design gaps and runtime failures |
Nobody is SOC 2 certified
There is no such thing as a SOC 2 certificate, and the language matters more than it sounds. What a CPA firm issues is an opinion, and opinions come in four flavors: unqualified, qualified, adverse, or disclaimed. The Journal of Accountancy, which is the AICPA's own publication, made the point sharply in February 2026 when it described vendors promising "compliance" and noted in the same breath that this is "a term never used in SOC 2 examinations."
SOC reports date to 2011 and are performed under the AICPA's Statements on Standards for Attestation Engagements. Current reporting requirements for service auditor reports come from SSAE-21.
One more thing that catches people out: a SOC 2 is a restricted-use document, released to specified parties who understand the system being described. That is why companies put a SOC 3 or a trust page on their marketing site and keep the SOC 2 itself behind an NDA.
The five criteria, and why most reports only use one
The control criteria come from the AICPA's 2017 Trust Services Criteria with Revised Points of Focus, 2022. Five categories exist:
- Security is the common criteria and appears in every SOC 2 examination
- Availability applies once you sell an uptime promise
- Processing integrity applies when you transform or transact on customer data
- Confidentiality applies to information contractually marked confidential
- Privacy applies to personal information, and gets confused with confidentiality constantly
The other four are elected, not mandatory. Every category you add drags in more controls, more evidence gathering, and more audit hours, which is why a first report is usually security and nothing else.
How long does the window have to be?
The honest answer is that no rule fixes it. The report declares the period it covers, and the length gets decided by management together with the service auditor. It is not written down in the Trust Services Criteria.
That is worth saying plainly because an enormous amount of published guidance states a mandatory three, six, or twelve month window as though quoting the standard. It is not in there. What is real is the commercial pressure: a longer window means more samples across more time, which buys more confidence, and procurement teams generally want unbroken coverage year over year. First-time reports often run short to unblock a deal, then settle into a rolling annual cycle.
Two adjacent things you will meet. The gap between a report period ending and today is normal and gets covered by a bridge letter, which is management asserting nothing has changed, not an auditor opinion. And a report whose period closed a year and a half ago is describing a system that may not exist anymore.
What the AICPA said about fast reports in 2026
This is the part that changed, and the part the full article digs into properly.
Across 2026 the AICPA published an unusual run of material questioning SOC 2 report quality: FAQs on software tools used in SOC 2 examinations dated March 31, ethics guidance covering business arrangements with SOC tool providers dated April 13, and peer reviewer guidance on SOC 2 risks dated May 14. Its SOC landing page also carries a notice that it is looking into allegations about a compliance vendor's business practices.
Sean Linton, CPA/CITP, an audit partner at EisnerAmper LLP who chairs the AICPA Assurance Services Executive Committee's SOC 2 Working Group, told the Journal of Accountancy that SOC "professionals are seeing indications that 'fast and easy' may come at the expense of quality and objectivity." The same reporting notes that tool vendors now number in the dozens, market compliance in weeks or hours, and through heavy SEO spending dominate search results for SOC 2 services.
The structural issue is that most of these vendors are not CPA firms and cannot attest to anything, so some have assembled referral networks of accounting firms, with marketing that gestures at thousands of reports a year. Terry O'Brien, CPA/CITP, a director at Schellman and a Working Group member, described the result bluntly: "You just know it's a template. You can compare any five of their reports, and they're all exactly the same, with a different client logo on it."
Jeff Cook, CPA, of Fortreum Associates LLC pointed out the practical cost, that a report rejected by a business partner is "not worth the paper it's on." Jeff Krull, CPA/CITP, of Baker Tilly US framed the collective risk: "Even if there are 100 good SOC 2 reports, the one bad one that people get their hands on, they're posting it on LinkedIn, they're posting on social media."
Worth being fair here: the same CPAs credit these tools for replacing screenshot-and-spreadsheet evidence collection with direct system integrations, which genuinely is better. The complaint is narrow and specific. Marketing built on speed and audit rigor pull against each other.
Seven checks before you trust a report someone hands you
- Verify the auditor is a licensed CPA firm. Nobody else can issue the opinion. Look them up.
- Read the opinion paragraph. Unqualified, qualified, adverse, or disclaimed. A qualified opinion is not automatically disqualifying, but it is a conversation.
- Measure the gap. Note the end date, count forward to today, and request a bridge letter past roughly three months.
- Read the exceptions. Zero findings across a full year should raise an eyebrow, not lower one. Findings are evidence somebody actually tested.
- Read the scope and system description. Confirm the product you are buying is inside it. Scope drift is the quietest way a clean report covers nothing you care about.
- Check which criteria are included. Security only is normal. If availability or privacy was promised, confirm it is really in there.
- Check subservice organizations and CUECs. Note which subprocessors are carved out, and read the complementary user entity controls, because those are obligations landing on you.
If you are on the other side of this and building toward a report, two things worth having open while you work: the AWS IAM Policy Generator for the least-privilege policies that get sampled under the logical access criteria, and the Security Headers Checker for the transport protections you will be evidencing repeatedly across the window.
So which one do you need
Selling into enterprise and blocked in procurement, you need a Type 2, and a Type 1 buys you one pass before renewal. Pre-revenue with a single urgent contract, a Type 1 unblocks you and is only defensible if the Type 2 window opens immediately behind it. Evaluating somebody else's report, run the seven checks and spend your attention on scope and exceptions rather than the opinion line. Choosing an audit firm or a platform, treat an unusually fixed short timeline as a question rather than a feature, which is precisely what the AICPA's own working group flagged in 2026.
SOC 2 Type 2 means an independent CPA firm looked at your controls over a declared period and formed an opinion about whether they worked. Not a badge, not a pass mark, and not a twelve month window anybody mandated.
References
- What Is SOC 2 Type 2? Scope and Period - the full version on DevToolLab, with the complete report-reading procedure
- Best SOC 2 Compliance Automation Platforms: Vanta vs Drata vs Secureframe vs Sprinto
- Journal of Accountancy: Promises of 'fast and easy' threaten SOC credibility (February 1, 2026)
- AICPA: System and Organization Controls, SOC Suite of Services
- AICPA: FAQs on the effect of the use of software tools on SOC 2 examinations (March 31, 2026)
- AICPA: 2017 Trust Services Criteria with Revised Points of Focus, 2022

Top comments (0)