Operating-effectiveness controls, continuous evidence collection and a mid-window health check, so your independent CPA firm's Type II examination reflects consistent control operation, not a lucky snapshot.
Companies whose customers have specifically asked for a Type II report, and companies who already hold a Type I and are moving to the next stage. Type II is what most enterprise procurement teams mean when they ask for SOC 2, because it evidences that controls actually operated rather than merely existed on a given day. If you are starting from nothing and need something to show within weeks rather than months, look at Type I first.
Controls built and monitored to actually operate consistently over your full observation window, not just look good on paper for one day.
We help configure continuous evidence collection (access reviews, change logs, vendor reviews) so evidence gathering isn't a frantic scramble before the exam.
A process for catching and documenting control exceptions as they happen. Auditors expect some exceptions; undocumented ones are the real problem.
A checkpoint partway through your observation window to catch drift before it becomes an exception in the final report.
Guidance on bridge letters for the gap between your examination period end and report delivery, so customer contract renewals aren't blocked.
We help you select and brief an independent, licensed CPA firm to perform the Type II examination itself.
Type I asks whether a control is designed properly. Type II asks whether it worked, every time it was supposed to, across the whole observation window. That sounds like a small difference and it is not. A control that is beautifully designed but performed late in two months out of six will produce an exception in your report.
The practical consequence is that Type II preparation is less about documentation and more about operational discipline. Quarterly access reviews need to actually happen in the quarter. Change approvals need to exist before the deployment rather than being backfilled. Offboarding needs to complete within the window your own policy specifies. Auditors sample across the period, and gaps show up.
This is why we treat evidence collection as an engineering problem rather than a paperwork problem. If your access review depends on someone remembering to run it, it will eventually be late. If it is scheduled, ticketed and produces an artefact automatically, it will not.
Type II reports cover a period, and you choose it. Three months is the shortest window most CPA firms will examine and is common for a first Type II. Six months is a frequent middle ground. Twelve months is what mature companies settle into, because it produces continuous coverage year on year with no gaps between reports.
The trade off is straightforward. A shorter window gets you a report sooner but demonstrates less, and some enterprise customers will ask why the period is short. A longer window is more convincing but delays the report. If a specific customer deal depends on the report, start from their requirement and work backwards.
Once you are in an annual cycle, the important thing is avoiding gaps between consecutive report periods. A gap in coverage is exactly the kind of thing a diligent procurement reviewer notices, and bridge letters only stretch so far.
An exception is where the auditor found that a control did not operate as described. Most Type II reports contain some, and a report with none is less common than people assume. What matters is the nature of the exception, whether you identified it yourself, and what you did about it.
An exception you detected through your own monitoring, documented, investigated and corrected reads very differently from one the auditor discovered that you had no idea about. The first demonstrates that your control environment works, including its ability to catch its own failures. The second suggests nobody was watching.
This is the reasoning behind the mid window health check. Finding a drifting control in month three of a six month window gives you time to correct it and evidence the correction. Finding it when the auditor does gives you an exception and no story to accompany it.
We agree your Trust Services Criteria and set an observation window: typically 3, 6 or 12 months depending on customer requirements.
Controls are implemented with the operating cadence built in from day one: who reviews access, how often, and where the evidence lands.
A final dry-run against the full observation window before your CPA firm's fieldwork begins.
You get one round to correct the gaps we identified. We re-review those items and issue the final readiness report before fieldwork begins.
We brief your chosen independent CPA firm and support evidence walkthroughs, but they perform and sign the Type II report.
After the pre-examination readiness review, you get one round to correct the control gaps we identified. We then re-review those specific items and issue the final readiness report before your CPA firm's fieldwork begins. This is separate from the mid-window health check, which is also included.
The observation period only counts once controls are genuinely running. Starting early to save time reliably produces exceptions across the opening months.
Anything that depends on a person remembering will eventually be missed, and a Type II window is long enough to guarantee it.
Consecutive Type II reports should cover continuous periods. Gaps prompt awkward questions from procurement teams that bridge letters only partially answer.
Self identified and corrected exceptions strengthen a report. Undocumented ones found by the auditor do the opposite.
Plan for four to eight weeks of preparation before the observation window opens, then the window itself, which is commonly three, six or twelve months. The CPA firm's fieldwork and report issuance typically adds four to six weeks after the window closes. A first Type II with a three month window therefore realistically takes five to seven months from engagement to issued report. If a customer deadline is driving this, tell us the date early, because window length is the main lever available and it needs deciding at the start.
We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.
Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →
Most first-time Type II reports use a 3 or 6-month window, moving to 12 months in subsequent years once controls are proven stable. Enterprise customers increasingly expect 12-month windows.
This is exactly what the mid-period health check is designed to catch. A documented, remediated exception is normal and expected; an undocumented one is what damages a report.
No. The same AICPA independence rule that applies to Type I applies here. We prepare and operationalise your controls; an independent CPA firm performs and signs the examination. See our independence statement.
The control set is often similar, but Type II tests whether those controls actually operated consistently over time, which means evidence cadence and exception handling matter far more than at Type I.
Yes. Many clients pursue both frameworks together, and a lot of the underlying control work (access management, risk assessment, vendor review) overlaps. Ask us about a combined programme.
Three months is the common starting point when a report is needed reasonably quickly, moving to twelve months in subsequent cycles. Some enterprise customers explicitly expect six or twelve months, so confirm the requirement before committing.
A bridge letter, sometimes called a gap letter, covers the interval between the end of your report period and the current date, confirming no material changes have occurred. It is commonly requested during procurement when your latest report period ended some months ago. It is not a substitute for a current report.
Rarely, in our experience, provided they are minor, documented and remediated. Reviewers are generally more concerned by unexplained exceptions or by a company that appears surprised by its own findings.
Yes, and most companies do. Changes need to be documented, and the auditor will consider how the control operated across the whole period including before and after the change. What causes difficulty is undocumented change.
The criteria do not name penetration testing explicitly, but CC7.1 expects mechanisms to detect vulnerabilities, and most auditors and customers treat an annual test as the expected evidence. In practice, plan for one.
One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.
Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.
Book a discovery call