The 2023 Interagency Guidance on Third-Party Relationships, issued by the federal banking agencies, advises banking organizations to consider whether contract provisions “describe the types and frequency of audit reports the banking organization is entitled to receive from the third party.” It names System and Organization Controls reports, the family that includes SOC 2, as one example.
That shifts the practical question from obtaining a report to choosing between its two versions. A Type I report examines control design as of a single date. A Type II report evaluates both the setup and ongoing performance of internal controls over a specified timeframe.
In This Article:
|
Inside a SOC 2 Report: Primary Areas Covered
The American Institute of Certified Public Accountants (AICPA) publishes the trust services criteria a SOC 2 examination tests against. The engagement is defined as “a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.” In practice, a report need not cover all of these categories, only those the service organization and its auditor agreed to examine.
When a provider says “we have a SOC 2 report,” they’re making a claim that doesn’t specify which categories the auditor examined. That report’s scope section names those categories, and its opinion section states the date or period the examination covers. Those two sections are why screening for a SOC 2 certified provider means reading the report.
What a SOC 2 Type I Report Examines
In a Type I engagement, the service auditor evaluates and reports on whether the company’s system description is presented fairly and whether its controls are suitably designed as of a specific date. The report lists the controls in scope but includes no auditor test steps or results because a Type I engagement does not assess operating effectiveness.
That limit is why customers push past a Type I report. A Type I report tells a reviewer that access provisioning, change approval, and log review are defined, assigned to named owners, and capable of meeting the criteria. It does not tell the reviewer whether anyone performed those three tasks last quarter.
What a SOC 2 Type II Report Examines
A Type II engagement covers the same design question and adds operating effectiveness throughout a specified period. The report also includes the auditor’s tests of controls and their results, which show which controls were tested and whether the tests found exceptions.
The AICPA publishes no minimum length, so the service organization and its auditor fix the period when they scope the engagement. Three to twelve months is a common range.
A shorter period produces a report sooner. A longer period covers more of the year and allows for controls that run on a cycle, because a control needs at least one completed cycle within the period to be tested. A six-week window cannot evidence a quarterly user access review.
Understanding Client and Partner Demand for Type II Reports
The 2023 interagency guidance directs banking organizations to contract provisions describing how often they receive audit reports and the types of reports. Customers ask for a SOC 2 report in the security questionnaire that comes with a new contract, and again when that contract renews.
Because a Type II report covers a historical period, coverage lapses between the end of that period and the issuance of the next report. Customers often close that gap by requesting a bridge letter. The letter comes from the service organization’s own management rather than from the auditor, because an auditor cannot give an opinion on a period it did not test.
The AICPA doesn’t publish guidance on bridge letters, so treat one as a customer expectation rather than a compliance requirement.
Which Report Fits Your Situation
A Type I report is not a prerequisite for a Type II report. Type I reports fit when a specific deal is gated, no evidence history exists, or the control set is new enough that a period test would return exceptions for gaps the organization already knows about.
A Type II report is appropriate when a customer requests it, and the controls are already in place. Under those conditions, proceeding with a Type II report without a Type I report is often the less expensive option.
How To Prepare for Each Report
Preparation for a Type I report is documentation work, meaning written policies, a system description that matches what is actually deployed, and a named owner for each control.
Preparation for a Type II report is that same work plus evidence that accumulates while the window is open. Access review records, change tickets, tested restores, and onboarding and offboarding records must all include dates within the period to support continuous compliance monitoring.
NIST Special Publication 800-34 Revision 1 treats recovery testing as a scheduled exercise, at least annually and more often for high-impact systems. This means a period shorter than that cadence will not contain a restore test for the auditor to examine.
How Advantage Tech Guides SOC 2 Readiness

Advantage Tech is SOC 2-compliant and organizationally certified, with a team of CISSP-certified professionals, so the examination you are preparing for is one we have already been through. Our cybersecurity risk assessment can evaluate your IT environment, and our certification audit support turns the gaps that evaluation finds into a compliance roadmap.
Contact Advantage Tech today with the customer requirement you were handed, and our team will walk you through which report that requirement actually calls for.

