Independent publication. General information only: not an auditor, certification body, law firm or standards body.
Baseline ReadySecurity & Compliance Intelligence Check your readiness

Framework guide

SOC 2 Type 1 vs Type 2: what each covers and costs

Updated Last verified

In short: a Type 1 report reviews the design of your controls at a single point in time. A Type 2 report reviews how they operate over a period, which auditors describe as typically 3 to 12 months. Type 2 takes longer and, in published ranges, costs more.

Side by side

Type 1Type 2
What is testedDesign of controlsDesign and operation of controls
Time coveredA single point in timeA period, typically 3–12 months per auditors
Published audit fee (The Pun Group)$5,000–$20,000 (base fee)$20,000–$50,000 (base fee)
Published audit fee (Drata, small to midsize companies)$7,500–$15,000$12,000–$20,000

Fees are third-party estimates in US dollars, as published by the firms named; they exclude readiness work, tooling and internal time unless stated. See the Cost & Readiness Index for all published figures.

How to decide

  • Ask who needs the report. The customers or prospects requesting it are the ones who decide which type they will accept. Ask them before you plan.
  • Plan the observation period. A Type 2 can only report on a period that has already happened, so the earliest date you can have one depends on when that period starts.
  • Count the evidence. A Type 2 needs evidence that controls ran throughout the period, which is why collecting it as work happens matters. See What SOC 2 readiness involves.

AICPA's own formal definitions of the two report types are in its SOC 2 guide, which is a paid publication; the descriptions above follow how CPA firms explain them. Only a CPA firm can tell you which report suits your situation.