Home / Services / SOC 2 Type I Preparation
SOC 2 · Type I

SOC 2 Type I readiness, so your first examination isn't a gamble.

Control design documentation, a precise system description, and a dry-run readiness assessment, built so your independent CPA firm's Type I examination comes back clean the first time.

Type I ReadyDesign-effectiveness focus
CPA-firm ready evidence
UK · US · EU consultants
Who it's for

Who this is for

Companies selling into the United States market where a customer or prospect has asked for a SOC 2 report, and who need something credible in hand reasonably quickly. Type I is frequently the right first step because it assesses control design at a point in time rather than operation over a period, which means you are not waiting months before you have anything to show. If your customer has specifically asked for Type II, read our Type II page instead, because a Type I will not satisfy that request.

What's included

Scope, in plain terms.

S1-01 Scope

Trust Services Criteria Mapping

Controls mapped to the criteria relevant to your business: typically Security, and Availability and/or Confidentiality where applicable.

S1-02 Scope

System Description

A precise, auditor-ready system description covering your infrastructure, software, people, procedures and data, the document your CPA firm's report is built around.

S1-03 Scope

Control Design Review

An assessment of whether your policies and control narratives hold up as evidence of design effectiveness at a single point in time, which is Type I's specific focus.

S1-04 Deliverable

Readiness Assessment

A dry-run assessment identifying any control that wouldn't hold up under CPA firm scrutiny, before you pay for the real examination.

S1-05 Deliverable

Evidence Package

Every artefact your CPA firm will request, organised and indexed so the actual examination moves fast.

S1-06 Fit

CPA Firm Introduction

We help you select and brief an independent, licensed CPA firm to perform the examination itself.

What SOC 2 is and where it came from

SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants. Unlike ISO 27001, it is not a certification and there is no certificate. What you receive is a report written and signed by an independent CPA firm expressing an opinion on your controls. That difference in form matters when customers ask for evidence, because you are handing over a detailed report rather than a one page certificate.

SOC 2 reports are built around the Trust Services Criteria. Security, sometimes called the common criteria, is mandatory in every SOC 2 report. Availability, Confidentiality, Processing Integrity and Privacy are optional and included only where relevant to the service you provide. Each additional criterion adds scope, cost and audit effort, so choosing them carelessly is an expensive habit.

Because the report is an opinion from a licensed CPA firm, independence rules apply strictly. The firm that helped design and implement your controls cannot be the firm that examines them. This is the same principle that keeps us out of the examination itself, and it is worth understanding early so the engagement is structured correctly from the start.

Type I compared with Type II

A Type I report assesses whether your controls are suitably designed as at a specified date. The auditor examines the design of each control and your system description, and forms an opinion on whether the controls, if operating as described, would meet the criteria. It is a snapshot.

A Type II report assesses whether those controls operated effectively across a period, commonly three, six or twelve months. The auditor samples evidence from across the window and reports exceptions where controls did not operate as described. It is substantially more demanding and substantially more valuable to the customer reading it.

The usual path is Type I first, then Type II covering a period beginning shortly after. That gives you something to show quickly while the observation window for Type II accumulates. Some companies with mature controls skip straight to Type II, and if your customer has explicitly asked for Type II there is limited value in producing a Type I first.

The system description, and why it matters more than people expect

The system description is the section of a SOC 2 report where you describe your service, your infrastructure, your people, your procedures and your data. It is written by you rather than the auditor, and the auditor opines on whether it is fairly presented. It is also the part most companies underestimate.

A weak system description creates problems in both directions. Describe your environment vaguely and the report becomes hard for a customer to rely on, which defeats the purpose of producing it. Describe controls you do not actually operate and you have created an inaccuracy the auditor is obliged to address. We review your description against what your environment genuinely does, and flag anything that claims more than the evidence supports.

Engagement process

How the work actually happens.

01

Scoping

We confirm which Trust Services Criteria apply to your business and agree the boundary of your system description.

02

Gap assessment

Current controls are assessed against the criteria, with gaps prioritised by how likely they are to surface an exception.

03

Review & validate

We review your policies and control narratives against the Trust Services Criteria, and check the tooling (access management, logging, change management) your controls depend on is actually enforcing them.

04

Readiness review

A full dry-run against Type I expectations, so nothing about your control design surprises the CPA firm.

05

Remediation round and re-review

You get one round to address the control design gaps we identified. We re-review those items and issue the final readiness report.

06

Handover to CPA firm

We brief your chosen independent CPA firm and support you through the examination, but they perform and sign the actual Type I report.

Included as standard

One remediation cycle is built into every engagement

After the readiness assessment, you get one round to address the control design gaps we identified. We then re-review those specific items and issue the final readiness report, so your CPA firm begins its examination against your corrected control design rather than the state we first assessed.

What goes wrong

Common mistakes we are asked to fix.

Adding Trust Services Criteria you do not need

Processing Integrity in particular is often included reflexively by companies that do not process transactions. Each criterion added expands scope permanently, since dropping one later looks like a step backwards to customers.

Treating the system description as marketing copy

It is an audited document. Anything it claims must be evidenced, and overstatement creates exceptions rather than impressions.

Choosing a CPA firm late

Firms book up, and their availability often sets your real timeline. Identify and engage yours early rather than after preparation is complete.

Assuming Type I satisfies a Type II request

If a customer contract specifies Type II, a Type I report does not meet it. Clarify exactly what has been asked for before choosing a path.

Timelines

Timing and what to expect

Most first time clients reach Type I readiness in six to ten weeks, depending on how much control tooling already exists. The CPA firm's examination itself typically takes a further two to four weeks from fieldwork to issued report. If you are moving toward Type II afterwards, the observation window begins after Type I and runs for the period you and your customers agree, so factor that into any commitment you make to a prospect.

One thing worth being clear about

We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.

Offer

Your first year of service is free

Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →

Common questions

Frequently asked questions

What's the difference between Type I and Type II?

Type I assesses whether your controls are designed appropriately at a single point in time. Type II assesses whether those same controls operated effectively over a period, typically 3 to 12 months. Most companies start with Type I and move to Type II once controls have been running long enough to evidence.

Do you perform the SOC 2 examination yourselves?

No. AICPA independence rules require the CPA firm issuing your SOC 2 report to be independent of anyone who designed or implemented your controls. We prepare you; an independent, licensed CPA firm performs the examination. Full detail in our independence statement.

How long does Type I readiness typically take?

Most first-time clients are examination-ready in 6 to 10 weeks, depending on how mature your existing controls and tooling are.

Can you help us pick the right Trust Services Criteria?

Yes. This is one of the first things we scope. Adding criteria you don't need (like Processing Integrity when you don't process financial transactions) adds cost and audit burden for no customer benefit.

Will this satisfy customer security questionnaires immediately?

The Type I report itself, once issued by your CPA firm, is what satisfies most questionnaires. Our job is making sure that report comes back clean.

Is SOC 2 a certification?

No. It is an attestation report issued by a licensed CPA firm expressing an opinion on your controls. There is no certificate and no certifying body, which is why you share the report itself rather than a badge.

Which Trust Services Criteria do we actually need?

Security is mandatory. Add Availability if you commit to uptime obligations, Confidentiality if you handle customer data under confidentiality terms, Processing Integrity if you process transactions where accuracy is central, and Privacy if you handle personal information in ways that warrant it. We scope this with you before anything else.

Can a UK or EU company get a SOC 2 report?

Yes. SOC 2 is a US originated framework but is used internationally and is commonly requested of non US suppliers selling into the US market. The examining firm must be a licensed CPA firm.

Do we need both ISO 27001 and SOC 2?

Only if your customers ask for both, which does happen when you sell across regions. The underlying control work overlaps substantially, so running them together is considerably more efficient than sequentially.

Who can see our SOC 2 report?

SOC 2 reports are restricted use documents, normally shared with customers and prospects under NDA rather than published. That is one practical difference from an ISO 27001 certificate, which can be displayed openly.

Is remediation included, or is that charged separately?

One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.

Related services

Often scoped alongside this.

Ready to scope this?

Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.

Book a discovery call