Guides

Plain-language explainers for technical founders and security leaders. Cost estimates are planning ranges; your customer, scope, and contracts determine what evidence is useful.

SOC 2: Type I or Type II?

A SOC 2 examination is performed by an independent CPA firm under AICPA attestation standards. Type I reports on the design of controls at a point in time. Type II reports on design and operating effectiveness over a period. Ask the buyer whether they require a specific type, trust services criteria, report age, or observation period before choosing a schedule.

SOC 2 is an attestation report, not a certification. It does not by itself establish that every security risk is addressed or guarantee a particular security outcome.

What drives project cost?

Scope, number of systems and locations, evidence readiness, control complexity, observation period, and provider responsibilities all affect cost. Separate external CPA examination fees, readiness consulting, tooling subscriptions, internal staff time, and penetration testing when comparing proposals.

Questions to ask an auditor

  • Which CPA firm will issue the report, and who signs it?
  • What systems, trust services criteria, and exclusions are in scope?
  • What period will a Type II examination cover?
  • What are the report-delivery milestones and retest or remediation fees?
  • What work is performed by the CPA firm versus a separate readiness adviser?

Official starting points