Security, Availability, Processing Integrity, Confidentiality & Privacy Assurance
If you have any questions or need assistance, please don't hesitate to contact us.
Evaluates whether relevant controls are suitably designed and implemented as of a specified date. Evidence supports the point-in-time assessment.
Type I is often used when stakeholders need an initial report before a longer Type II reporting period.
Evaluates whether relevant controls are suitably designed and operated effectively throughout a defined review period.
Type II requires period-based evidence such as logs, tickets, reviews, approvals, and monitoring records, providing deeper assurance over sustained operation.


New or recently formalized controls may support a Type I starting point.
Mature controls with consistent evidence may support direct progression to Type II.
Need point-in-time assurance? Type I may fit.
Need sustained assurance? Plan for a Type II review period.
Confirm customer, procurement, contractual, and industry expectations before selecting Type I or Type II.
SOC 2 timing depends on report type, scope, criteria, control maturity, evidence readiness, and auditor coordination.
Timing varies by scope and readiness. Type I focuses on a specified date, so preparation centers on documented control design, implementation, and evidence available at that date.
Type II includes a defined review period. Readiness requires consistent evidence, control operation, exception management, and sustained ownership throughout that period.

Ready to learn more about Trust Services Criteria?
