By Marçal Santos, vCISO and founder of SecureLeap. CISM and CDPSE (ISACA). Previously security roles at Aircall, Citibank and Talkdesk. +20 years in cybersecurity.
Key takeaways
- A SOC 2 Type 1 report tests whether your controls are designed correctly on a single date. It does not test whether they worked over time.
- Audit fees typically run $5,000 to $8,000 for startups under 50 employees and $8,000 to $30,000 for mid-market organizations, before readiness and remediation costs.
- Most organizations go from decision to issued report in 4 to 12 weeks.
- Buying Type 1 and Type 2 as one engagement typically saves 10% to 15% versus commissioning them separately. Almost every company that does a Type 1 does a Type 2 the following year, so ask for the combined quote up front.
- Security is the only mandatory Trust Services Criterion. The other four are scoped in only if your commitments require them. Around 90% of the engagements we scope are Security-only.
- It is an attestation, not a certification. There is no pass or fail, and no certificate.
- If your buyer's own auditor needs to rely on the report, Type 1 will not satisfy them. That requires a Type 2 with a window of at least six months.
What is SOC 2 Type 1?
SOC 2 Type 1 is an attestation report in which a licensed CPA firm evaluates whether a service organization's internal controls are suitably designed and implemented to meet the AICPA Trust Services Criteria as of one specific date. Schellman, a CPA firm that performs these examinations, describes the scope as evaluating the design and implementation of a company's controls at a specific point in time (Chad Goubeaux, CPA, CISSP, CISA, Schellman, updated March 2025).
Audit fees typically fall between $5,000 and $30,000 depending on company size and scope, and most organizations reach an issued report in 4 to 12 weeks. That speed is the entire reason Type 1 exists: it is the fastest credible way to put an auditor's opinion in front of a buyer who is asking for one.
Three things it is not: it is not a certification, it is not a pass-or-fail exam, and it is not something a buyer's own auditor can rely on for their financial statement audit.
The three-word difference: design, not operation
Every practical question about Type 1 resolves to one distinction. A Type 1 opinion covers design. A Type 2 opinion covers design and operating effectiveness.
Put concretely: for Type 1, an auditor confirms that your access review process exists, is documented, is assigned to someone, and would work if followed. For Type 2, the auditor pulls a sample of access reviews from across the observation window and checks that they actually happened, on schedule, with evidence.
That distinction drives everything downstream: cost, timeline, evidence burden, and which buyers will accept the report.
One point worth planning around: a three-month Type 2 window is real and issuable, and it is a common choice for a first report (Schellman).
But the window is not only your decision. If your buyer's own audit team intends to rely on the report for their work, Becky McCarty, a Partner at Linford & Co, sets the threshold plainly: the report "should cover a minimum reporting period of six months" (Linford & Co).
Ask which situation you are in before you pick the window, because changing it later means starting the clock again.
Deciding between the two? We cover the full comparison, including which one to run first and how to sequence them, in SOC 2 Type 1 vs Type 2.
What "attestation, not certification" actually changes
This is the single most common misunderstanding, and getting it wrong costs deals.
SOC 2 is an attestation engagement performed under AICPA attestation standards. That means:
- There is no certificate. If a vendor sends you a "SOC 2 certificate," they are sending you something that does not exist.
- There is no pass or fail. The output is an auditor's opinion, which may be unqualified, qualified, adverse, or a disclaimer. Exceptions can be noted in the report while the opinion remains usable.
- There is no certifying body. Any licensed CPA firm may perform the examination. The AICPA sets the standards but does not issue or approve reports.
- The report is restricted-use. It is shared under NDA with customers, prospects, partners, and regulators, not published on your website.
Only a licensed CPA firm can issue the report. Compliance automation platforms such as Vanta, Drata, and Secureframe collect and organize evidence. They do not perform the examination and cannot issue the opinion, and neither SOC 2 nor ISO 27001 requires one.
Where teams get burned: a sales rep writes "SOC 2 certified" into an RFP response, procurement asks for the certificate, and there is nothing to send. Say "SOC 2 Type 1 attestation report, available under NDA" instead.
The Trust Services Criteria you are actually scoped against
SOC 2 is built on five Trust Services Criteria. Only Security is mandatory. The other four are included only when your customer commitments or system design require them.
Scope discipline is the highest-leverage cost decision in the entire project. Each additional criterion adds controls, evidence, and audit hours.
In practice, this decision is less open than it looks. Roughly 90% of the SOC 2 engagements SecureLeap scopes are Security-only, and the pattern is consistent: these are companies under 50 employees doing SOC 2 for the first time, with no contractual commitment that requires anything beyond Security. Availability or Confidentiality get added later, when a specific customer contract actually asks for them.
The failure mode runs in one direction only. Teams scope in extra criteria early because it feels more thorough, then pay for controls, evidence, and audit hours that no buyer ever asked to see. Start with Security, and expand when a contract forces the question.
Cost, timeline, and who on your team it consumes
Audit fees
Auditor fees scale primarily with headcount, then with the number of criteria in scope.
Where these numbers come from. The under-50 range reflects what SecureLeap sees directly: auditor invoices and CPA firm quotes reviewed on behalf of clients between 2024 and 2026. Roughly 90% of the engagements we scope are Security-only, because for most of these companies it is their first SOC 2 and there is no contractual reason to scope wider. The mid-market range is a broader market figure and sits outside the profile we typically work with, so treat it as a directional benchmark rather than an observed one.
What these numbers exclude. The CPA firm's fee only. Readiness work, remediation, tooling, and internal staff time are all separate. Actual quotes vary with criteria in scope, system complexity, the number of subservice organizations, and the firm you select. These are budgeting benchmarks, not a SecureLeap price list and not a quote.
The bundle discount nobody mentions
If this is your first SOC 2, you do not have to buy the two reports separately.
Most CPA firms will price a Type 1 and a follow-on Type 2 as a single engagement, and in our experience that typically comes in 10% to 15% cheaper than commissioning them one at a time. The logic is straightforward from the auditor's side: the scoping, the walkthroughs, and the system description are largely shared work, so doing them once across a combined engagement removes duplicated effort.
This is worth asking about specifically, because it is rarely offered unprompted. Nearly every company that completes a Type 1 goes on to complete a Type 2 in the following year, so you are almost certainly buying both eventually. Negotiating them together is simply pricing the path you are already on.
Ask your shortlisted firms for both a standalone Type 1 quote and a combined Type 1 plus Type 2 quote, and compare the total.
Timeline
A typical project runs 4 to 12 weeks from decision to issued report:
- Readiness and gap assessment (1 to 2 weeks). Map current state against the criteria in scope.
- Remediation (2 to 6 weeks). Close the gaps. This is the step that actually varies, and it is where the whole timeline is won or lost.
- Evidence collection (1 to 2 weeks, overlapping remediation). Assemble artifacts as of your chosen assessment date.
- Audit fieldwork (1 to 4 weeks). Walkthroughs, sampling, auditor questions.
- Report issuance (1 to 3 weeks after fieldwork). Draft review, management assertion signed, final report.
A-LIGN, which reports having completed more than 17,500 SOC assessments, describes two viable preparation paths: a full readiness assessment that simulates the audit, recommended for companies without formal procedures, or a lighter high-level gap assessment for organizations whose controls are already mature (A-LIGN). Choosing the lighter path when you are not actually ready is the most common way a 6-week project becomes a 16-week one.
Who it consumes internally
- Executive sponsor (CISO, CTO, or COO): scope decisions, signs the management assertion.
- Technical leads (DevOps, security, IT): control implementation, evidence gathering, auditor walkthroughs.
- Operations and HR: policy documentation, background checks, onboarding and offboarding records.
Plan around your business cycle. Starting a readiness project during a fundraise, a major launch, or peak sales season is the most reliable way to blow the timeline.
Preparing for the audit: five steps
- Define scope. Decide which criteria apply, which systems and environments are in scope, and which subservice organizations you will carve out or include. Everything downstream inherits this decision.
- Document policies and procedures. Information security, access control, change management, incident response, risk assessment, vendor management, and HR security. They must reflect what you actually do, because the auditor will test the two against each other.
- Run a readiness assessment. Map your current controls to the criteria and produce a gap list with owners and dates.
- Remediate the gaps. Implement missing controls and let them run long enough to produce artifacts. Remediation is the step that determines your real timeline.
- Collect evidence as of your assessment date. Screenshots, configuration exports, tickets, signed policies, training records, access review records. Everything is anchored to that single date.
Choosing your auditor. Verify the firm is a licensed CPA firm, ask how many SOC 2 examinations they perform annually, confirm they work with companies at your stage, and get clarity on the fee structure and what triggers change orders. Ask for the combined Type 1 plus Type 2 quote at this stage, not after the Type 1 is done. If you would rather not run the selection and auditor management yourself, that is what our SOC 2 consulting engagements cover.
Who should run a Type 1, and who should skip it
Run a Type 1 if:
- You have a specific deal that needs an auditor's opinion sooner than a Type 2 window allows.
- You have recently implemented your control set and want independent validation of the design before committing to a 6 to 12 month observation window.
- You need a forcing function to get policies, access reviews, and onboarding controls actually operating.
Skip straight to Type 2 if:
- Your buyers have explicitly asked for Type 2, and the sales cycle can absorb the wait.
- Your buyer's own auditor needs to rely on the report. Type 1 will not work for this at any price (Linford & Co).
- You are selling into healthcare or financial services, where Type 2 is close to table stakes.
- Your controls have already been operating for six months or more and you have the evidence to prove it. In that case Type 1 costs you money and time for a report you have outgrown.
Or buy both at once. For most first-time companies this is the option worth pricing before either of the above. You get the Type 1 quickly for the deal in front of you, the Type 2 follows on a defined window, and the combined engagement typically costs 10% to 15% less than buying them in sequence.
Schellman is direct that many customers, prospects, partners, and user auditors prefer or require a Type 2 because it provides stronger assurance, and that some stakeholders will insist on one (Schellman). Treat Type 1 as a bridge, not a destination.
"The question I get asked is 'which one do we need,' and it is almost always the wrong question. The right one is 'who is asking, and what will they accept.' If it is a procurement team checking a box, Type 1 closes the deal this quarter. If it is their auditor, they need at least six months of evidence behind the report, so plan for Type 2 from the start and buy the two together."
Marçal Santos, CISM, CDPSE, founder of SecureLeap
After the report: what to do with it
Use it in sales properly. Share under NDA, lead with scope and assessment date, and be straightforward that it is a Type 1 with Type 2 to follow on a stated timeline. Buyers respond well to a dated commitment and badly to ambiguity.
Start the Type 2 clock immediately. The controls validated in your Type 1 must now demonstrably operate. Pick your observation window, and remember the six-month threshold if user auditor reliance is in play.
Set up continuous evidence collection now. The failure mode is a team that passes Type 1, relaxes for four months, and then has no evidence for the first third of their Type 2 window. Automate access reviews, log retention, change approvals, and vulnerability scanning before the window opens, not during it.
Map to other frameworks while it is fresh. The control work overlaps substantially with ISO 27001, and running them together is far cheaper than sequentially. See ISO 27001 for US startups.
Frequently Asked Questions
What is SOC 2 Type 1?
An attestation report in which a licensed CPA firm evaluates whether your internal controls are suitably designed and implemented to meet the AICPA Trust Services Criteria as of one specific date. It assesses design, not whether the controls operated over time.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 covers control design at a single date. Type 2 covers design and operating effectiveness across an observation window, typically three to twelve months. Type 1 is faster and cheaper; Type 2 is what most enterprise buyers and all user auditors want.
How much does a SOC 2 Type 1 audit cost?
Auditor fees typically range from $5,000 to $8,000 for startups under 50 employees scoped to Security only, and $8,000 to $30,000 for mid-market organizations with additional criteria. These exclude readiness, remediation, tooling, and internal time.
How long does the SOC 2 Type 1 process take?
Usually 4 to 12 weeks from decision to issued report. Fieldwork is only 1 to 4 weeks of that; remediation is the variable step.
Is SOC 2 Type 1 mandatory?
No. SOC 2 is voluntary and is not a legal requirement in any jurisdiction. It is frequently required contractually by enterprise procurement teams.
Can we skip Type 1 and go straight to Type 2?
Yes, and you should if your controls have already been operating for six months or more, if your buyers have specified Type 2, or if their auditor needs to rely on the report. Type 1 is most useful when you need a credible auditor opinion faster than a Type 2 window allows.
Is SOC 2 Type 1 a certification?
No. It is an attestation engagement. There is no certificate, no pass or fail, and no certifying body. Only a licensed CPA firm can issue the report.
Can you buy SOC 2 Type 1 and Type 2 together?
Yes, and for a first-time SOC 2 it is usually the cheaper path. Most CPA firms will price a Type 1 and a follow-on Type 2 as a single engagement, typically 10% to 15% below the cost of commissioning them separately, because scoping, walkthroughs, and the system description are shared work. Ask for both a standalone Type 1 quote and a combined quote before you sign.
Getting your SOC 2 Type 1 done
Most Type 1 projects fail on scope and remediation sequencing, not on the audit itself. Our SOC 2 consulting service covers the engagement end to end: scoping, gap analysis, policy and control design, evidence collection, and management of the external auditor.
Estimate your audit cost with our SOC 2 calculator or book a 30-minute call.

