Back to Guides
Guide16 September 2026

What is SOC 2 Type 1 and when should you get it?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is SOC 2 Type 1?
  3. How does SOC 2 Type 1 differ from Type 2?
  4. What criteria are covered?
  5. Typical timeline and cost
  6. Validity and expiration
  7. When is SOC 2 Type 1 useful?
  8. Limitations to be aware of
  9. How to prepare for a SOC 2 Type 1 audit
  10. What the deliverable looks like
  11. Frequently asked questions
  12. Bottom line

Key takeaways

What is SOC 2 Type 1?

SOC 2 Type 1 is an independent attestation report from a licensed CPA firm that evaluates whether a service organization’s internal controls are suitably designed to meet the AICPA Trust Services Criteria at a specific point in time. It does not test how those controls performed over a period.

How does SOC 2 Type 1 differ from Type 2?

What criteria are covered?

The Security criterion is mandatory. Organizations can also include Availability, Processing Integrity, Confidentiality, and Privacy based on their services and customer expectations. The audit follows SSAE 18 / AT - C 105 and AT - C 205, the same standards used for Type 2.

Typical timeline and cost

PhaseDuration
Field - work (auditor review)4 - 8 weeks
Total from kickoff to report4 - 12 weeks

Costs range from $28 k to $58 k for a 10 - 50 - person startup in 2026, representing roughly 40 - 60 % of a comparable Type 2 engagement.

Validity and expiration

The report itself does not have a formal expiration date, but most procurement teams treat it as valid for 12 months and expect a refreshed report (or a Type 2) after that period.

When is SOC 2 Type 1 useful?

Limitations to be aware of

Because it only assesses design, a control could be perfectly designed yet fail in practice. A Type 1 report does not guarantee that controls actually worked after the audit date, so relying solely on it for ongoing risk management can be risky.

How to prepare for a SOC 2 Type 1 audit

  1. Document control design - create clear policies, procedures, and system diagrams.
  2. Map controls to Trust Services Criteria - indicate which criteria each control addresses.
  3. Perform internal walkthroughs - verify that documented controls exist and are implemented as described.
  4. Gather evidence artifacts - screenshots, configuration files, and access logs that show the control is in place.
  5. Engage a qualified CPA firm - ensure they have experience with SSAE 18 / AT - C 105 audits.

What the deliverable looks like

The report follows the standard SOC 2 structure: management description, control objectives, and the auditor’s opinion on design suitability. It omits the “operating effectiveness” section and detailed test - of - controls results found in a Type 2 report.

Frequently asked questions

Q: Is SOC 2 Type 1 a certification? A: No. It is an attestation with a CPA opinion on design suitability, not a pass/fail certification.

Q: Can I use a Type 1 report to win contracts? A: Yes, many customers accept a recent Type 1 as proof of control design, especially when they need evidence quickly.

Q: How often should I renew the report? A: Most buyers expect a fresh report every 12 months, or upgrade to Type 2 for longer - term assurance.

Bottom line

SOC 2 Type 1 provides a fast, cost - effective way to demonstrate that your security controls are designed correctly at a specific point in time. It is ideal for meeting immediate compliance demands and preparing for a later Type 2 audit, but it does not prove that those controls actually work in practice.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary