Glossary

What is SOC 2 Type I?

Key takeaway

A SOC 2 Type I report evaluates whether an organization's controls are properly designed at a specific point in time. Learn how it differs from Type II.

What is SOC 2 Type I?

A SOC 2 Type I report is an independent auditor's assessment of whether an organization's controls are suitably designed to meet one or more Trust Services Criteria at a specific point in time. Unlike a Type II report, which tests controls over a period, a Type I report provides a snapshot of control design on a single date.

How does a SOC 2 Type I audit work?

During a Type I engagement, the service auditor examines the organization's system description and the controls management has put in place. The auditor evaluates whether those controls, if operating as described, would reasonably achieve the relevant Trust Services Criteria objectives.

The process typically involves:

  1. System description review — the auditor reviews a written description of the organization's system, including infrastructure, software, people, procedures, and data
  2. Control identification — the auditor identifies the controls relevant to the selected Trust Services Criteria
  3. Design assessment — the auditor evaluates whether each control is suitably designed to meet its objective
  4. Report issuance — the auditor produces a report with an opinion on the design of controls as of the specified date

What is the difference between SOC 2 Type I and Type II?

The key differences between Type I and Type II reports:

  • Type I assesses control design at a point in time. It answers: "Are the controls properly designed?"
  • Type II assesses control design and operating effectiveness over a period (typically 3-12 months). It answers: "Are the controls working as intended over time?"

Type I reports are faster and less expensive to obtain, but they carry less weight with enterprise buyers. Many organizations use a Type I report as a stepping stone while building toward a Type II.

When should you pursue a SOC 2 Type I report?

A Type I report makes sense in several scenarios:

  • First-time SOC 2 — organizations new to SOC 2 often start with Type I to validate their control design before committing to an observation period
  • Urgent customer requests — when a prospect or customer needs a SOC 2 report quickly and cannot wait for a full Type II observation period
  • Significant system changes — after a major infrastructure migration or reorganization, a Type I can confirm the redesigned controls are appropriate

What is the timeline and cost of a SOC 2 Type I?

A Type I audit typically takes 2-4 weeks once the organization is audit-ready. The total timeline including preparation can range from 6-12 weeks. Costs vary based on scope and auditor, but Type I engagements generally cost 30-50% less than Type II engagements.

What are the limitations of SOC 2 Type I?

Because a Type I report only evaluates design at a single point in time, it does not demonstrate that controls actually operated effectively. An organization could have well-designed controls that are not consistently followed. This is why sophisticated buyers and security teams prefer Type II reports for ongoing vendor assessment.

How do you move from SOC 2 Type I to Type II?

Most organizations treat Type I as a milestone, not a destination. After obtaining a Type I report, the next step is to enter an observation period (typically 3-6 months for the first Type II) during which the auditor can test operating effectiveness. This transition requires maintaining consistent control execution and evidence collection throughout the observation window.

How does episki help with SOC 2 Type I?

A Type 1 report describes design at a point in time, and episki gets you there by drafting rather than templating — agents write the policies and control descriptions from your own context, and a human approves. Because controls are evaluated from day one, the same program continues into a Type 2 observation period without restructuring. Learn more about Type 1 vs Type 2.

Dealing with this in your own program? episki's agents handle the drafting, mapping, and evidence work.

Start free trial

See how episki handles this

Start a free trial and explore controls, evidence, and automation firsthand.