Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

SOC 2 Type I vs Type II: What Founders Need to Know

When a prospect asks, "Do you have SOC 2?" the answer needs to be more specific than yes or no. There are two types of SOC 2 reports, and they serve different purposes. Understanding the difference will help you plan your compliance roadmap and set the right expectations with customers.

SOC 2 Type I: A snapshot

A Type I report evaluates whether your security controls are designed appropriately at a single point in time. The auditor comes in, reviews your policies, examines your controls, and issues a report that says, "As of [date], this company has controls in place that are suitably designed to meet the SOC 2 Trust Service Criteria."

Think of it as a photograph. It shows what your security posture looks like right now. It does not prove that your controls have been working consistently over time.

Timeline: 4 to 8 weeks of preparation, 2 to 4 weeks of audit. Total elapsed time from kickoff to report: 2 to 3 months.

Cost: $10,000 to $25,000 for the audit itself, plus $5,000 to $15,000 per year for a compliance automation platform if you use one (recommended).

SOC 2 Type II: A movie

A Type II report evaluates whether your controls are operating effectively over a period of time, typically 6 to 12 months. The auditor reviews evidence that your controls were consistently followed throughout the observation period. Did you actually perform those quarterly access reviews you documented? Did your monitoring actually alert on security events? Did terminated employees actually lose access within 24 hours?

Think of it as a movie. It shows that your security posture is consistent and sustained, not just a one-time setup that you did for the audit and then abandoned.

Timeline: 6 to 12 month observation period after Type I controls are in place, followed by 4 to 6 weeks of audit. Total elapsed time: 9 to 15 months from the start of your compliance journey.

Cost: $15,000 to $40,000 for the audit, plus ongoing costs for maintaining controls and the compliance platform.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

Which one do you need?

Start with Type I if you have never been SOC 2 audited. Type I gets you a report you can share with prospects within 2 to 3 months. It demonstrates that you take security seriously and have built the foundation. Most enterprise prospects will accept a Type I report from a startup, especially if you can show that you are working toward Type II.

Plan for Type II within 12 months of your Type I report. Larger enterprise customers and regulated industries (healthcare, financial services) will eventually require Type II. The transition from Type I to Type II is straightforward if you have been consistently following your controls. The auditor just needs to see evidence over the observation period.

Go directly to Type II if you have been operating with strong security practices for at least 6 months and have the evidence to prove it. Some auditors will allow you to skip Type I and go straight to Type II with a 6-month observation period. This saves you the cost of two separate audits.

Common mistakes

Treating it as a one-time project. SOC 2 is not "set it and forget it." Your Type II audit must be renewed annually. The controls need to be followed every day, not just during audit season. If you implement controls for the audit and then stop following them, your next audit will have findings.

Over-scoping. SOC 2 has five Trust Service Criteria: security, availability, processing integrity, confidentiality, and privacy. You do not need all five. Start with security only, which covers about 80% of what enterprise customers ask about. Add criteria later if specific customers require them.

Choosing the wrong auditor. Not all CPA firms are equal. Find an auditor who has experience with SaaS companies and understands cloud-native infrastructure. A firm that primarily audits manufacturing companies will waste your time asking questions that do not apply to your business.

Skipping the compliance platform. Tools like Vanta, Drata, and Secureframe cost $5K to $15K per year but save you hundreds of hours in evidence collection. They integrate with your cloud providers, identity providers, and HR tools to continuously monitor your controls and collect evidence automatically. Without them, you are manually taking screenshots and writing reports, which is both painful and error-prone.

The ROI

SOC 2 compliance costs $25,000 to $60,000 in the first year (audit plus tooling). A single enterprise deal at $100K+ ACV pays for it multiple times over. More importantly, having SOC 2 removes a blocker from your sales pipeline. Instead of losing deals to "we need to see your SOC 2 report," you hand them the report and move to the next step in the sales cycle.

If you are ready to start your SOC 2 journey, book a call with our security team. We will help you scope the engagement, select an auditor, and get audit-ready in the shortest time possible.

How long the observation window should be

The window is negotiable and most first-timers do not realize it. A Type II can be issued over three months, six months, nine months or twelve, and the choice changes both what the report is worth and how likely it is to come back clean.

A three-month window is the fastest route to a Type II and it is accepted by a fair number of buyers, particularly when you tell them the next report will cover twelve. It also gives the auditor a small population to sample from, which cuts both ways: fewer samples to fail, and less room to demonstrate that a quarterly control actually ran. If your access review is quarterly and your window is three months, you get exactly one instance of it, and if that one instance is late or missing you have an exception with no other evidence to soften it.

Six months is the common landing point for a first Type II. Twelve months is where you want to be steady-state, because it lines the report up with an annual renewal cycle and stops you paying for two audits in fourteen months when a buyer asks for continuous coverage.

The move most teams make, once they think about the calendar rather than the milestone, is a short first window followed by a twelve-month second window that starts the day the first one ends. That produces continuous coverage from the earliest possible date, which is the thing procurement teams actually check.

Bridge letters, and the gap nobody warns you about

A SOC 2 report covers a period that has already ended. If your window closed on 31 March and a prospect is asking in August, the report has a five-month hole in front of it, and their vendor risk team will notice.

The instrument that closes it is a bridge letter, sometimes called a gap letter. You write it, not the auditor. It states the period between the end of the audit window and today, asserts that no material changes have occurred to the system or the control environment, discloses anything that did change, and is signed by management. Most buyers accept a bridge covering up to three months and get uncomfortable beyond that.

Two practical points. Write the template before you need it, because the first time somebody asks it will be inside a deal with a deadline. And do not sign a bridge that is untrue: if you migrated cloud providers or lost half the engineering team during the gap, that belongs in the letter. A signed assertion that turns out to be wrong is a considerably worse problem than a disclosed change.

What the auditor actually does during a Type II

Type I is largely inspection: read the policy, look at the configuration, confirm the control exists as described. Type II adds sampling, and sampling is where teams get caught.

The auditor asks for a population, meaning the complete list of events a control should have covered during the window: every person who joined, every person who left, every production change, every access request, every alert that fired. Then they select a sample from it and test each one. The critical and underappreciated step is completeness. Before testing a sample, a good auditor checks that the population itself is complete, usually by reconciling your list against an independent source such as the identity provider, the payroll system or the repository history.

This is where a well-run program separates from a well-documented one. If you hand over a list of twenty-two terminations and the payroll export shows twenty-five, the three missing names are not a sample failure, they are a population failure, and the auditor now has reason to distrust every population you provide. Reconcile your own lists before you submit them.

Sample sizes scale with control frequency. A daily control might draw twenty-five samples over a twelve-month window, a monthly control two to four, a quarterly control one or two, and an annual control the single instance. Low-frequency controls carry disproportionate risk for that reason: one missed quarterly review is a fifty percent failure rate on a two-sample test.

Exceptions, qualified opinions, and what a clean report means

An exception is an instance where the control did not operate as described. One offboarding that took nine days against a documented one-day commitment is an exception. It does not automatically qualify the report.

The auditor evaluates whether exceptions, individually or together, mean the control failed to meet the applicable criterion. An isolated instance with a plausible cause and no impact usually lands as a noted exception with a management response attached, and the report remains unqualified. A pattern, or a single exception that defeats the purpose of the control, produces a qualified opinion where the auditor states that a specific criterion was not met.

A qualified report is not fatal and it is not the same as failing. Buyers read the exceptions section, read your management response, and make a judgment. What they are looking for is whether you noticed, what you changed, and whether the change is credible. A management response that says the exception was a one-off caused by a manual handoff, and that the handoff is now enforced by the offboarding workflow, reads very differently from one that promises to be more careful.

Write your management responses yourself and write them specifically. This is one of the few parts of the report where your own words appear, and prospects do read them.

The system description is what gets people in trouble

Section three of the report is your description of the system, written by you and tested by the auditor for fair presentation. It names your infrastructure, your subservice organizations, your control activities, and the boundaries of scope.

Two structures inside it matter to your customers. Complementary user entity controls are the things your report says your customers must do for the controls to be effective, such as managing their own users and configuring single sign-on correctly. Buyers read these closely, because each one is work assigned to them. Keep the list short and honest rather than using it to push responsibility outward, since a long list reads as an attempt to shift risk.

Subservice organizations are your own critical vendors, and you choose between the carve-out method, where their controls are excluded and their report is referenced, and the inclusive method, where their controls appear in yours. Carve-out is standard for cloud providers and much simpler. Whichever you pick, you are then expected to have obtained and reviewed their reports, which is a control your auditor will test.

Description drift is the most common cause of a rough second audit. The document was accurate when it was written, the architecture moved, and nobody updated it. Review it whenever a material change ships, not once a year in a panic.

Cost drivers people do not see coming

The audit fee is the visible number. Around it sit several others.

Scope is the biggest multiplier. Each additional trust services category adds control activities, evidence and audit hours, with availability and confidentiality relatively cheap to add and privacy consistently the most expensive because it reaches into data handling practices across the business. Multiple products or legal entities in one report add hours. A window that includes an infrastructure migration adds hours, since the auditor has to test controls in both configurations.

Then there is the readiness work. Going into fieldwork with mapped controls, a complete evidence register and reconciled populations reduces auditor time materially, and auditors price partly on expected effort. We have taken $11,000 off a client's audit quote by walking the auditor through a documented readiness position before the engagement letter was signed, which is not a trick, just the auditor pricing a known quantity instead of an unknown one. Our own SOC 2 in 75 Days track starts from $3,000 for the gap analysis for the same reason: knowing the distance is what makes the rest predictable.

Budget for the retest and remediation loop as well. Penetration test findings, if you are running one to satisfy the vulnerability management criteria, need fixing and verifying inside the window.

Choosing and changing auditors

Ask three questions that most buyers skip. When was the firm's last AICPA peer review and what was the result. How many SOC 2 reports do they issue a year, and how many for companies of your size and architecture. Who is on the engagement team, and is the person doing the testing the person you met in the sales call.

Ask also about their evidence platform integration, because an auditor who works natively with the compliance tooling you already run will pull evidence directly instead of asking for it by email, which shortens fieldwork by weeks.

Changing auditors mid-program is allowed and normal. The cost is that the new firm re-performs a fair amount of scoping and description review, and there is no continuity of judgment on prior exceptions. If you change, do it between windows rather than partway through one, and keep your evidence in your own system rather than in the previous auditor's portal so the handover is a permissions change rather than a reconstruction project. Keeping that register under your control is one of the reasons our Workspace is free to use.

When Type II is not the right purchase

Three situations where we tell people to hold.

One customer is asking and they have not said Type II. Enterprise security questionnaires often accept a Type I, a completed standardized questionnaire, or a recent penetration test with a remediation memo. Ask the buyer's security team directly what will unblock the contract, in writing, before you commit to a twelve-month program. The answer is sometimes considerably cheaper than the assumption.

Your controls are three weeks old. Starting an observation window before the cadence has actually run once is how you buy an audit with exceptions in it. Run the access review, the vendor review and the change process for a full cycle first, find out what breaks, then start the clock. A report with several exceptions costs the same as a clean one and is worth less in a sales conversation.

Your buyers are European or your contracts point at ISO. If the demand is coming from outside North America, an ISO 27001 certificate covering 93 Annex A controls plus clauses 4 to 10 may be the artifact that actually gets accepted, and running both at once as a first move is more program than most teams of that size can absorb. Sequencing them a year apart, with evidence collected once and mapped to both, is the cheaper path.

If you are not sure which of those describes you, send us the buyer's exact wording. Half the time the requirement in the contract is narrower than the one in the email, and we would rather tell you that than sell you a window you did not need.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.