●Enterprise Cybersecurity & Compliance●Cloud & Infrastructure Security●Offensive Security Testing●Governance & Risk Management
●Enterprise Cybersecurity & Compliance●Cloud & Infrastructure Security●Offensive Security Testing●Governance & Risk Management
SOC 2 • Trust Services Criteria

Build trust with SOC 2 Type 1 assurance.

Understand what SOC 2 really means, why Type 1 matters, how it differs from Type 2 and ISO/IEC 27001, and how to prepare your organization for an independent CPA examination.

SOC 2TYPE 1
Point-in-timeType 1 perspective
5 categoriesTrust Services Criteria
IndependentCPA / service auditor
Evidence-ledControls & system
01 / Start with the basics

What is SOC 2?

SOC 2 is an attestation examination and reporting framework for controls at a service organization relevant to security, availability, processing integrity, confidentiality or privacy. It is designed to give specified report users information they can use to assess and address risks arising from their relationship with the service organization.

01

Control assurance

The organization defines its system and relevant controls. An independent service auditor examines the defined subject matter against applicable criteria.

02

Trust Services Criteria

SOC 2 uses the AICPA Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy.

03

Customer-facing evidence

The report helps knowledgeable users understand the service organization’s system, controls, commitments and related risks.

Important: SOC 2 is not an ISO-style certification. It is an attestation engagement that results in a SOC 2 report issued by an independent service auditor / CPA firm.
02 / THE TYPE 1 ANSWER

What is SOC 2 Type 1?

A SOC 2 Type 1 examination provides a point-in-time view of a service organization’s defined system and relevant controls. The independent service auditor examines whether the system is appropriately described and whether the relevant controls are suitably designed as of the specified date.

TYPE
1
POINT-IN-TIME
AS OF A SPECIFIED DATE

Does the right system and control design exist today?

Type 1 is about the state of the control environment at a defined point in time. It examines the system description and the suitability of relevant control design; it is not the Type 2 conclusion about whether controls operated effectively throughout a period.

01Define the system
→
02Design controls
→
03Independent examination
01
WHAT IS ASSESSED

System description

The service organization’s system is described as of the specified date, including the relevant system components, boundaries and controls within scope.

02
WHAT IS ASSESSED

Control design

The service auditor evaluates whether the relevant controls are suitably designed to provide reasonable assurance against the applicable Trust Services Criteria.

03
WHO PERFORMS IT

Independent CPA / service auditor

The independent service auditor performs examination procedures, obtains sufficient appropriate evidence and issues the SOC 2 report.

04
MANAGEMENT ROLE

Management owns the assertion

Management prepares the system description and written assertion and remains responsible for the underlying system and controls.

✓ TYPE 1 PROVIDESA point-in-time examination of the system description and suitability of relevant control design.
VS
× TYPE 1 DOES NOT PROVIDEA Type 2 conclusion that controls operated effectively throughout a specified period.
Think of Type 1 as the starting assurance milestone.It establishes that the defined system and relevant controls have been independently examined at a specific point in time. Organizations that need evidence of sustained operating effectiveness typically progress to Type 2.
03 / Background

Why did SOC reporting become important?

Modern organizations increasingly depend on service organizations for technology, platforms, processing and other outsourced functions. That creates a need for customers and business partners to understand the controls protecting the systems and information they depend on.

01 / OUTSOURCING

Services move outside the enterprise

Customers rely on external service organizations for technology, processing, support and infrastructure.

02 / RISK

Dependency creates assurance needs

Customers need information about how the service organization manages relevant system and control risks.

03 / SOC SUITE

AICPA structured SOC reporting

The AICPA’s SOC suite provides distinct examination/reporting services, including SOC 1, SOC 2 and SOC 3.

04 / TRUST

Independent evidence matters

A SOC 2 report gives specified users an independent examination of relevant controls within the defined scope.

SOC 1

Focused on controls relevant to user entities’ internal control over financial reporting.

SOC 2

Focused on controls relevant to Security, Availability, Processing Integrity, Confidentiality or Privacy.

SOC 3

Uses the Trust Services Criteria for a general-use report with different reporting requirements from SOC 2.

04 / Why organizations pursue it

Why is SOC 2 Type 1 needed?

SOC 2 Type 1 is not a universal legal requirement. Organizations typically pursue it because customers, enterprise procurement teams, partners or contracts want credible evidence that the defined system and relevant controls have been designed and implemented against applicable Trust Services Criteria.

↗
01 • SALES

Win enterprise customers

Strengthen security due-diligence conversations with an independent SOC 2 report that prospective customers can review as part of their vendor assessment.

✓
02 • TRUST

Build customer confidence

Demonstrate that relevant controls have been examined by an independent service auditor rather than relying only on internal claims or questionnaires.

◎
03 • VISIBILITY

Make controls visible

Clearly define the system boundary, control responsibilities, commitments, risks and evidence that support the examination scope.

◆
04 • GOVERNANCE

Strengthen control discipline

Bring policies, procedures, ownership and management oversight into a more structured control environment that can be maintained.

▣
05 • DUE DILIGENCE

Reduce questionnaire friction

Where accepted by the customer, a SOC 2 report can provide a reusable source of assurance information and reduce repeated security evidence requests.

↻
06 • NEXT STEP

Create a Type 2 foundation

Use the Type 1 milestone to establish scope, controls and evidence practices that can support a future examination of operating effectiveness over a period.

Think of Type 1 as a credibility milestone.It gives specified report users a point-in-time view of the defined system and relevant control design and implementation—not a guarantee that controls operated effectively throughout a period.
05 / Compare the reports

How is Type 1 different from Type 2?

The core distinction is the time dimension and the assurance question. Type 1 is point-in-time; Type 2 adds operating effectiveness throughout a specified period and includes the service auditor’s tests and results.

DimensionSOC 2 Type 1SOC 2 Type 2
Primary questionWere the system and relevant controls appropriately described and suitably designed/implemented as of a point in time?Were the system and relevant controls suitably designed and did the controls operate effectively throughout a specified period?
Time frameAs of a specified date.For a specified period of time.
Operating effectivenessNot the Type 2 period-of-time conclusion.Yes. Operating effectiveness is examined throughout the defined period.
Testing detailFocuses on description and suitability of design/implementation at the point in time.Includes a detailed description of service auditor tests of controls and the results.
Best fitOrganizations establishing or demonstrating a control environment at a specific date.Organizations that need evidence that controls operated effectively over time.
Commercial signalUseful milestone for enterprise readiness and customer assurance.Stronger evidence of sustained control operation where customers require it.
06 / Who needs it?

Who is SOC 2 Type 1 for?

SOC 2 is designed around service organizations and the systems they use to deliver services. It is especially relevant when customers depend on your technology, data processing or operational controls.

SaaS & cloud platforms

Demonstrate how the systems supporting your hosted service are governed and protected.

Managed service providers

Provide customers with independent assurance around relevant operational and security controls.

FinTech & payment technology

Strengthen customer trust around systems that handle sensitive or business-critical information.

HealthTech & data platforms

Support assurance conversations where privacy, confidentiality and system controls matter.

B2B technology vendors

Respond more confidently to procurement and security-review requirements from enterprise buyers.

Data & processing services

Explain the system, commitments and controls behind outsourced processing services.

Not every organization needs SOC 2. The right assurance model depends on customer expectations, contractual requirements, service model, risk profile and the type of information or systems involved.
07 / Business impact

How will SOC 2 Type 1 help my business?

SOC 2 should not be treated as a document-generation exercise. The real value is connecting business commitments, system boundaries, risks, controls, ownership and evidence into a defensible assurance story.

$

Shorter trust conversations

Give customer security teams a structured independent report rather than answering every question from scratch.

↗

Stronger enterprise positioning

Use independent assurance as a commercial trust signal when enterprise buyers evaluate vendors.

⚙

Clearer internal ownership

Define who owns controls, what evidence is expected and how responsibilities connect across teams.

◈

Better evidence discipline

Move from scattered screenshots and emails toward controlled, traceable evidence mapped to specific controls.

!

Earlier risk visibility

Identify gaps in access, change management, incident response, vendor oversight and other relevant control areas.

→

Path to sustained assurance

Build a control environment that can mature from Type 1 readiness toward Type 2 operating-effectiveness assurance where required.

08 / Trust Services Criteria

The 5 SOC 2 Trust Services Criteria

The AICPA Trust Services Criteria are organized into five categories. Security is the common category; Availability, Processing Integrity, Confidentiality and Privacy add category-specific criteria when included in scope.

COMMON + CORE

Security

Protect information and systems against unauthorized access, unauthorized disclosure and damage that could affect objectives.

SERVICE RELIABILITY

Availability

Controls supporting information and systems being available for operation and use to meet objectives.

PROCESS QUALITY

Processing Integrity

Processing is complete, valid, accurate, timely and authorized to meet the entity’s objectives.

SENSITIVE INFORMATION

Confidentiality

Information designated as confidential is protected to meet the organization’s objectives.

PERSONAL INFORMATION

Privacy

Personal information is collected, used, retained, disclosed and disposed of according to applicable commitments and criteria.

Scope matters: A SOC 2 examination does not automatically include every category. The applicable criteria are selected based on the organization’s services, commitments, system and engagement scope.
09 / Define the system

What exactly is examined?

The SOC 2 system is more than an application or server. The guide defines a system in terms of the infrastructure, software, procedures and data operated by people to achieve business objectives.

InfrastructureNetworks, facilities, platforms and technical foundations.
SoftwareApplications, code, configurations and supporting software.
PeopleRoles, responsibilities, competence and authorized actions.
ProceduresPolicies, processes, workflows and control activities.
DataInformation processed or maintained to provide the service.

A strong Type 1 engagement starts with a defensible system boundary: what is in scope, what is outside scope, how the system interacts with customers and which vendors or subservice organizations support the service.

10 / The deliverable

What is inside a SOC 2 Type 1 report?

The attached AICPA guide identifies three key components for a SOC 2 report. Type 1 focuses on the system and control design/implementation at the point in time.

01 / SYSTEM DESCRIPTION

Description of the system

The service organization’s system is described as of a point in time in accordance with the applicable description criteria.

02 / MANAGEMENT ASSERTION

Management’s assertion

Management asserts that the system description meets the criteria and that the stated controls were suitably designed as of the specified date.

03 / SERVICE AUDITOR OPINION

Independent opinion

The service auditor reports an opinion based on the examination and sufficient appropriate evidence obtained for the engagement.

Type 2 adds more: the Type 2 report also addresses operating effectiveness over a specified period and includes the service auditor’s tests of controls and the results of those tests.
11 / Compare the frameworks

How is SOC 2 different from ISO/IEC 27001?

They overlap in information-security control themes, but they are different assurance models. Choosing between them—or using both—should depend on your business, customer requirements and assurance strategy.

SOC 2 Type 1

AICPA Trust Services Criteria + attestation
Primary lensControls relevant to the selected Trust Services Criteria within a defined service-organization system.
AssuranceIndependent CPA / service auditor examination and report.
Time perspectiveType 1 is as of a point in time; Type 2 adds operating effectiveness over a period.
OutputSOC 2 report for specified users with sufficient knowledge of the service and system.
Commercial fitOften valuable for SaaS, technology and service providers facing customer assurance requests.

ISO/IEC 27001

Information Security Management System
Primary lensOrganization-wide management system for establishing, implementing, maintaining and continually improving information-security risk management.
AssuranceAn organization may choose independent certification through a certification body; certification is distinct from SOC 2 attestation.
Time perspectiveManagement-system requirements emphasize ongoing operation, evaluation and continual improvement.
OutputISO/IEC 27001 certificate when the organization completes a certification process successfully.
Commercial fitUseful where customers, regulators or stakeholders expect a globally recognized ISMS certification.
Think complementary, not interchangeable: SOC 2 can provide customer-focused attestation around a defined service system, while ISO/IEC 27001 provides a formal ISMS framework and optional certification route.
12 / Understand the ecosystem

What are AICPA, CPA and CPA attestation?

These terms are often confused when organizations first encounter SOC 2. Here is the practical distinction.

What is AICPA?

AICPA stands for the American Institute of Certified Public Accountants. The attached guide is an AICPA publication developed to assist practitioners with SOC 2 examination and reporting guidance.

  • AICPA’s Assurance Services Executive Committee established the Trust Services Criteria used for SOC engagements.
  • AICPA professional standards and guidance provide the professional foundation for attestation work.
  • AICPA itself is not the CPA firm that examines your organization.

What is a CPA?

CPA means Certified Public Accountant. A CPA is a licensed accounting professional; licensing requirements vary by jurisdiction.

  • For SOC 2, the practitioner performing the attestation examination is a CPA / service auditor.
  • The AICPA guide uses “service auditor” for the practitioner in a SOC 2 examination.
  • The independent CPA firm is responsible for the examination opinion—not the readiness consultant.

What is CPA attestation?

Attestation is an assurance engagement in which a responsible party makes an assertion against suitable criteria and a practitioner examines the subject matter and provides an opinion.

01Management prepares system description & assertion
02CPA / service auditor performs examination
03Independent report & opinion

Who does what?

The cleanest SOC 2 operating model separates preparation from independent assurance.

  • Your organization: defines the system, owns controls and management assertions.
  • CyberAtrix: can support scope, gap assessment, control design, documentation, evidence readiness, remediation and examination preparation.
  • Independent CPA / service auditor: performs the attestation examination and issues the SOC 2 report.
13 / CyberAtrix support

What CyberAtrix helps you build

We focus on practical readiness: making the system understandable, controls defensible and evidence organized before the independent examination.

01 / SCOPE

System & boundary definition

Map services, applications, infrastructure, people, processes, data, locations and dependencies.

02 / RISK

Risk & control assessment

Identify risks and connect commitments, control objectives, owners and treatment priorities.

03 / GOVERNANCE

Policies & procedures

Develop or refine the documented practices needed to support the in-scope control environment.

04 / TSC

Criteria mapping

Map relevant controls to applicable Trust Services Criteria and make coverage visible.

05 / EVIDENCE

Evidence architecture

Organize records, tickets, logs, approvals, configurations, reviews and other supporting evidence.

06 / READINESS

Control readiness testing

Identify gaps, test readiness, track remediation and prepare stakeholders for auditor interaction.

07 / SECURITY

Technical assurance

Where relevant, VAPT and technical assessments can support risk treatment and control evidence.

08 / HANDOFF

CPA examination coordination

Help management prepare for the independent service auditor’s requests, evidence review and examination process.

14 / Implementation roadmap

From “we have security” to “we can prove it.”

A SOC 2 Type 1 program works best when scope, controls, evidence and management ownership are developed together.

01

Scope

Define system, services and boundaries.

02

Assess

Review risks, commitments and current controls.

03

Design

Build or refine suitable controls.

04

Implement

Put policies, processes and safeguards into practice.

05

Evidence

Organize support for each relevant control.

06

Readiness

Close gaps and prepare management.

07

Examination

Independent CPA performs the Type 1 engagement.

Timeline: There is no responsible one-size-fits-all duration. Scope, organization size, system complexity, control maturity and evidence readiness determine the effort required.
15 / Report validity & assurance

How long is a SOC 2 Type 1 report valid?

A SOC 2 Type 1 report is an attestation report about the design and implementation of controls as of a specified date. It is not a certificate with a universal AICPA-prescribed expiry period.

Important distinction

Type 1 is point-in-time

The Type 1 opinion is tied to the specific “as of” date stated in the report. It does not provide assurance that controls continued operating effectively after that date.

No fixed expiry

No universal 3-month validity

The AICPA does not prescribe a three-month validity period for a SOC 2 Type 1 report. Customer and vendor-risk policies may impose their own freshness requirements.

Market practice

Freshness matters commercially

In practice, older reports can face more questions from enterprise buyers. A Type 1 is often treated as an early assurance milestone, with many organizations progressing to Type 2 for stronger ongoing assurance.

What about “3 months”?A three-month period is commonly used as a starting observation window for a SOC 2 Type 2 engagement—not as the validity period of a Type 1 report. Type 2 evaluates operating effectiveness over a defined period; Type 1 does not have an observation window.
16 / Why CyberAtrix

Why CyberAtrix for SOC 2 Type 1?

We focus on making the journey practical: define the right scope, build usable controls, organize evidence and get your organization ready for an independent CPA examination.

Performance

Performance-first execution

We prioritize the controls and evidence that matter to your actual service, customer commitments and examination scope—reducing unnecessary compliance work.

Delivery

Delivery discipline

Clear milestones, accountable owners, evidence tracking and practical remediation keep the engagement moving from gap assessment to CPA-readiness.

Costing

Competitive, value-focused costing

We design the engagement around your scope and maturity instead of forcing an oversized consulting package—helping you achieve strong market value from your compliance investment.

Security

Security + GRC expertise

Our approach connects cybersecurity, governance, risk, policies, technical controls and evidence so SOC 2 becomes a working security program—not a paperwork exercise.

Evidence

Evidence that tells the story

We help map controls to practical evidence and identify gaps before the independent examination, reducing avoidable audit friction.

Growth

Built for the next stage

Your Type 1 foundation can be structured with the future in mind, making the transition toward Type 2 and broader customer assurance more manageable.

Drop your enquiry with confidence.

Tell us your scope, company size and customer requirements. We will help you identify a practical SOC 2 Type 1 path with competitive market pricing.

Best-value approach • Transparent scope
17 / FAQ

Frequently asked questions

Is SOC 2 Type 1 a certification?

No. SOC 2 Type 1 is an attestation examination and report. An independent service auditor / CPA performs the examination and issues the report. It should not be described as an ISO-style certification.

Does AICPA perform my SOC 2 examination?

No. AICPA develops the professional framework and Trust Services Criteria. Your independent service auditor / CPA firm performs the examination.

Does SOC 2 Type 1 test whether controls operated effectively?

Type 1 addresses the design and implementation of relevant controls as of a specified date. Testing operating effectiveness throughout a specified period is part of Type 2.

Do I need all five Trust Services Criteria?

No. Security is the common category. Availability, Processing Integrity, Confidentiality and Privacy are included when relevant to the service, commitments and examination scope.

Can SOC 2 Type 1 replace ISO/IEC 27001?

No. They serve different assurance purposes. SOC 2 provides an attestation report around a defined system and applicable Trust Services Criteria; ISO/IEC 27001 defines requirements for an information security management system and can be independently certified.

Who is the intended audience for a SOC 2 report?

SOC 2 reports are intended for specified parties with sufficient knowledge of the service organization, its services, its system and the relevant risks. Users can include user entities, business partners, certain practitioners and regulators.

What does management have to do?

Management is responsible for the system description and written assertion and must provide relevant information and access for the examination.

Can CyberAtrix issue the SOC 2 report?

CyberAtrix can support readiness and implementation. The independent service auditor / CPA firm performs the attestation examination and issues the SOC 2 report.

Is a SOC 2 Type 1 report valid for only 3 months?

No. Three months is commonly used as an initial Type 2 observation period, not as a Type 1 validity period. A Type 1 report is tied to its specified as-of date, and the AICPA does not prescribe a universal expiry period. Customer acceptance and freshness expectations can vary.

How long is a Type 1 report valid?

Type 1 is an as-of-date examination, so its conclusion is tied to the specified date rather than a universal fixed certificate-validity period. Customers may set their own recency or assurance expectations.

Is VAPT mandatory for every SOC 2 Type 1?

Not universally. Technical testing should be driven by the system, risks, commitments and relevant controls. VAPT can be valuable supporting evidence, but it does not replace the broader SOC 2 control examination.

18 / Start the conversation

Ready to make your SOC 2 Type 1 journey audit-ready at the right market value?

Tell CyberAtrix about your service, scope, customer requirements and current security maturity. We will help you choose the right path from gap assessment to control readiness and independent CPA examination—with performance-focused delivery and competitive, value-driven costing.