SOC 2 Type II Report
Definition
An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover a period of time (typically six to twelve months), offering stronger assurance than a point-in-time SOC 2 Type I report.
- Report type
- Independent audit report
- Typical review period
- Six to twelve months
- Contrast
- Stronger than a point-in-time Type I report
- Criteria covered
- Security plus selected Trust Service Criteria
Common questions
Why do vendor risk teams generally prefer a Type II report over a Type I?+
A Type I report only confirms that controls were designed appropriately on a given date. A Type II report tests whether those controls were actually followed and effective across an extended period, which gives a reviewer more confidence that the control environment holds up in practice, not just on paper.
How often does an organisation need a new SOC 2 Type II report?+
Because each report covers a fixed observation window in the past, organisations typically commission a new audit annually so that vendor risk reviewers are always working from a report that reflects a recent operating period rather than a stale one.
Does a SOC 2 Type II report get published publicly?+
No. It is a restricted-use report shared directly with customers and prospects, usually under a non-disclosure agreement, because it can contain sensitive detail about the organisation's internal control environment.
Related terms
- Audit Rights Clause
- A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
- CAIQ (Consensus Assessments Initiative Questionnaire)
- A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
- Fourth-Party Risk
- The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
- Inherent Risk
- The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
- SIG (Standardised Information Gathering)
- A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...