Skip to content

SOC 2 Type II Report

Definition

An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover a period of time (typically six to twelve months), offering stronger assurance than a point-in-time SOC 2 Type I report.

Report type
Independent audit report
Typical review period
Six to twelve months
Contrast
Stronger than a point-in-time Type I report
Criteria covered
Security plus selected Trust Service Criteria

Common questions

Why do vendor risk teams generally prefer a Type II report over a Type I?+

A Type I report only confirms that controls were designed appropriately on a given date. A Type II report tests whether those controls were actually followed and effective across an extended period, which gives a reviewer more confidence that the control environment holds up in practice, not just on paper.

How often does an organisation need a new SOC 2 Type II report?+

Because each report covers a fixed observation window in the past, organisations typically commission a new audit annually so that vendor risk reviewers are always working from a report that reflects a recent operating period rather than a stale one.

Does a SOC 2 Type II report get published publicly?+

No. It is a restricted-use report shared directly with customers and prospects, usually under a non-disclosure agreement, because it can contain sensitive detail about the organisation's internal control environment.

Related terms

Audit Rights Clause
A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
CAIQ (Consensus Assessments Initiative Questionnaire)
A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
Fourth-Party Risk
The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
Inherent Risk
The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
SIG (Standardised Information Gathering)
A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.