Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

SOC 2 Type I vs Type II

A SOC 2 Type I report attests that your security controls are designed correctly at a single point in time. A SOC 2 Type II report attests that those same controls operated effectively over a period, usually three to twelve months. Type II is harder to earn and is what most enterprise buyers ultimately require.

In practice

Type I is a snapshot. It answers "are the right controls in place today?" and is faster to obtain, which makes it useful for unblocking a deal that is stalling on the security review.

Type II is a track record. The auditor samples evidence across the observation window to confirm controls ran consistently, not just on audit day. The common path is to earn Type I first, then run a Type II observation period immediately after.

// how traztech helps

traztech delivers SOC 2 Type I and Type II delivery for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

The distinction becomes practical the moment somebody asks for a date. A Type I can be issued as soon as controls are designed and in place, so it is achievable in the near term. A Type II attests that those controls operated across a period, so the period has to elapse before the report can exist.

The mistake we see is treating Type I as a lesser version of the same document. It is better understood as the first half of the same programme: if every control is designed to produce evidence, the observation window becomes a waiting period rather than a second project.

SOC 2 Type I vs Type II: common questions

Will a buyer accept a Type I?

Frequently yes, as an interim step, particularly if you can state when the Type II window closes. Some enterprise procurement teams will only accept a Type II, which is worth establishing before you scope the work.

How long should the Type II observation window be?

Three months is common for a first report and twelve months for a mature cycle. Shorter windows are cheaper and faster but some buyers discount them, so the window length is a commercial decision as much as a technical one.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.