Security · Flashcard

What does a SOC 2 Type 2 report cover that a Type 1 does not?

  • AWhether the controls operated effectively across a stated period of time
  • BWhether the controls were suitably designed to meet the criteria selected
  • CWhether the description of the system fairly presents what was actually built
  • DWhether the service organisation's assertion was signed by its management

Why this is the answer

Both reports cover the system description and the suitability of the controls' design; only a Type 2 adds testing of operating effectiveness over a period, typically three to twelve months, which is why a customer's risk team asks for Type 2. Design suitability appears in both. So does the fairness of the system description. And management's written assertion is a precondition of any attestation engagement, not something Type 2 introduces.

Official docs
Study in Gnoseed →