Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Trust and audit

SOC 2 Type 1 vs Type 2

The difference is time. Type 1 shows your controls were well designed on one specific date, like a snapshot. Type 2 follows those same controls over a period, usually three to twelve months, and proves they actually operate day to day. That is why buyers nearly always ask for Type 2 and treat Type 1 as a stepping stone.

Explore SOC 2 readinessGo to the comparison

In short

  • Type 1 assesses control design on a date. Type 2 assesses design and operation across a period.
  • SOC 2 is not a certificate: it is an audit report signed by an independent accounting firm.
  • Type 1 is faster and cheaper, but it is rarely what a customer accepts as the final answer.
  • Sitting on Type 1 for years draws the wrong kind of attention: it reads as a programme that exists on paper only.

Side by side

A snapshot against a film

What to compareSOC 2 Type 1SOC 2 Type 2
What the auditor assessesWhether controls were well designed on a specific date.Whether controls were well designed and operated across a period.
Period coveredA single day, the cut off date.Usually three to twelve months of operation.
Evidence requiredPolicies, configurations and process design.Samples of execution across the whole period, month by month.
Typical timelineShorter, because no observation window is needed.Longer: the observed period plus the audit time.
CostLower, with fewer audit hours.Higher, because the auditor tests samples from the full period.
What the buyer thinksAccepts it as a step, then asks when Type 2 arrives.Closes the conversation in due diligence.
RenewalMakes sense once, as a starting point.Annual, so no gap opens between reports.
Best used forShowing progress and unblocking deals while Type 2 matures.Being the definitive proof that security works in the routine.

Both reports assess the same trust services criteria. Security is mandatory; availability, processing integrity, confidentiality and privacy come in depending on what you promise customers.

The snapshot of one day

SOC 2 Type 1

The auditor looks at your controls on a set date and answers one question: are they designed in a way that would work? It does not test whether they worked last month, because there is no observed period. It comes out faster, costs less and serves a company that needs something concrete now while building the history Type 2 will demand later.

  • Assesses control design on a date
  • Shorter timeline and lower cost
  • Good for unblocking a deal in the short term
  • A starting point, not a destination
The film of the period

SOC 2 Type 2

The auditor follows the same controls over months and tests samples: was that access really reviewed this quarter? was that alert really handled? was that backup really restored in the test? The report shows what worked and also what failed, with the explanation. That detail is what gives the document its weight and what stops your customer's procurement team asking follow up questions.

  • Assesses design and operation across the period
  • Tests real samples of execution, month by month
  • Shows exceptions too, with context
  • What buyer due diligence expects

How they fit together

Type 1 is a step, not an address

Plenty of companies run Type 1 first to have something in hand while the history builds, then follow with Type 2 covering the period that comes after. That sequence is legitimate and it works. The problem starts when Type 1 becomes a permanent address: the buyer notices two or three years have passed with no Type 2 and concludes the controls were never tested in practice. If the plan really is to stay on Type 1, it is better to say so and discuss a different route to proof.

  • Type 1 first, Type 2 for the following period, is a normal sequence
  • An annual Type 2 report avoids a gap between periods
  • Between the end of the period and today, a bridge letter covers the interval

Which case is yours

Where to start

A contract is blocked right now and you have no history

Run Type 1 and schedule Type 2

You show something concrete fast and signal to the customer that Type 2 already has a date.

Your controls have been running for a few months

Go straight to Type 2

If the history exists, skipping Type 1 saves an entire audit.

Your customer is a large or regulated company

Only Type 2 will do

That kind of due diligence asks about the period covered. A report with no period does not pass.

Numbers that matter

1 day

is what Type 1 covers

3 to 12 months

typical period observed in Type 2

Annual

expected Type 2 cadence, with no gap

How DM11 solves it

From the first report to Type 2 without the scramble

We organise the controls, prepare evidence the way the auditor wants it and track the observation period so nothing is missing when testing starts. You reach the audit without a rush and without discovering a hole in the final month.

  • Evidence is collected during the period, not in a panic the night before
  • We pick the criteria with you, so you do not pay for scope nobody asked for
  • A dry run before the audit: you learn where you are weak while there is still time
  • We stay for the annual renewal, so no gap opens between reports
Explore SOC 2 readiness

Common questions

What people ask before deciding

Answers checked against the AICPA trust services criteria and SOC 2 audit practice.

Type 1 assesses whether controls were well designed on a specific date, like a snapshot. Type 2 assesses whether those same controls operated across a period, usually three to twelve months, testing real samples of execution. Type 2 carries more weight because it proves routine, not intention.

More questions? Talk to DM11

Move past Type 1 and hand your customer the report they ask for

A short conversation shows which period makes sense for you and what needs to be ready first.

Talk to a specialistExplore SOC 2 readiness