Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A SOC 2 Type I report attests that your security controls are designed correctly at a single point in time. A SOC 2 Type II report attests that those same controls operated effectively over a period, usually three to twelve months. Type II is harder to earn and is what most enterprise buyers ultimately require.
Type I is a snapshot. It answers "are the right controls in place today?" and is faster to obtain, which makes it useful for unblocking a deal that is stalling on the security review.
Type II is a track record. The auditor samples evidence across the observation window to confirm controls ran consistently, not just on audit day. The common path is to earn Type I first, then run a Type II observation period immediately after.
traztech delivers SOC 2 Type I and Type II delivery for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
The distinction becomes practical the moment somebody asks for a date. A Type I can be issued as soon as controls are designed and in place, so it is achievable in the near term. A Type II attests that those controls operated across a period, so the period has to elapse before the report can exist.
The mistake we see is treating Type I as a lesser version of the same document. It is better understood as the first half of the same programme: if every control is designed to produce evidence, the observation window becomes a waiting period rather than a second project.
Frequently yes, as an interim step, particularly if you can state when the Type II window closes. Some enterprise procurement teams will only accept a Type II, which is worth establishing before you scope the work.
Three months is common for a first report and twelve months for a mature cycle. Shorter windows are cheaper and faster but some buyers discount them, so the window length is a commercial decision as much as a technical one.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.