The 90-day SOC 2 Type 1 plan
A week-by-week sequence for a first SOC 2 type 1 examination: scope, policy set, evidence pipeline, risk assessment, fieldwork.
Compliance10 Jul 20268 min readUpdated 3 Sept 2026
On this page
A vendor security questionnaire arrives, and the buyer expects a SOC 2 report as the answer. The market estimate for a first report is usually nine to twelve months. That estimate holds for work done in the wrong order. An organisation whose enterprise deal depends on that questionnaire can reach a type 1 report in 90 days, provided the sequence below is respected.
This briefing is the sequence. It assumes one criteria category, security, and a type 1 report rather than a type 2. It also assumes one production system in scope, not everything the organisation runs.
What a SOC 2 report is, and what it is not
AICPA describes SOC 2 as "a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy" 1. The criteria are the 2017 Trust Services Criteria, republished with revised points of focus in 2022 2.
Those five categories are security, availability, processing integrity, confidentiality and privacy. A first examination almost never covers all five. Security alone is the working scope, and the other categories are added when a contract asks for them.
SOC 2 is not a certification. A certification body audits a management system against a requirements standard, which is what ISO/IEC 27001:2022 provides 3. A SOC 2 examination ends in an attestation report signed by a CPA firm. AICPA describes the audience as users who "need detailed information and assurance about the controls at a service organization" 1.
The practical consequence is that the CPA firm needs evidence rather than intentions. Most of the 90 days goes on producing evidence, not on designing controls.
Type 1 and type 2, in report terms
The two report types differ in what the service auditor examines, not in the criteria applied. A type 1 is fixed to a single as-of date, and covers the description of the system together with the design of the controls at that date. AICPA treats it as a distinct examination, with its own illustrative management representation letter 4. A type 1 therefore says nothing about how those controls behaved before or after the as-of date.
A type 2 report goes further. AICPA's illustrative type 2 report contains management's assertion, the description of the system, the service auditor's report, and tests of controls and results thereof 5. Those tests are the difference: a type 2 examines operating effectiveness across a period, so it cannot be produced faster than the period it covers.
One further document shapes the deliverable. The description of the system is prepared and evaluated against the 2018 SOC 2 description criteria, republished with revised implementation guidance in 2022 6.
Weeks 1-2: auditor, scope, as-of date
Nothing later recovers from a slow start here. The as-of date is the fixed point the rest of the plan is built backwards from.
Weeks 3-4: the policy set
A first examination normally needs twelve to eighteen written policies. Buying a template set is cheaper than writing one, and adapting it honestly is the work that matters. A policy that describes a practice the organisation does not follow converts into a failed control the moment the auditor asks for evidence.
Weeks 5-8: the evidence pipeline
This is where late programmes collapse. Type 1 evidence answers one question: did the control exist on the as-of date? Wire the existing tooling to produce that answer automatically, rather than assembling screenshots by hand in week 11.
The vendor inventory is the item most often skipped and the one auditors reach for first. It is also the artefact that a buyer's third-party risk team asks about immediately after the report lands.
Weeks 9-10: risk assessment and tabletop
Weeks 11-12: fieldwork
The auditor issues an information request list, usually called the PBC list, for items provided by the entity. A prepared organisation answers it in days rather than weeks.
Fieldwork commonly runs ten to fifteen working days for a type 1. The delivery owner carries it, not the executive owner.
What breaks a 90-day plan
- Opening with several criteria categories at once. Each category adds controls and evidence. Start with security; add availability or confidentiality when a contract requires it.
- No executive owner. The criteria expect evidence of management oversight, and an unowned programme produces none.
- Policies written the week before fieldwork. Everything should be approved two weeks before the as-of date, not on it.
- Controls performed once. A quarterly access review with one instance in the past year fails the moment the auditor samples it.
- Treating the report as the finish line. A type 1 opens the door; the type 2 examination that follows tests whether the controls actually operated.
What it costs
Budget four lines rather than one: the CPA firm's examination fee, a compliance automation subscription if one is used, optional external advisory support, and internal time. Internal time is the line most often underestimated, because the delivery owner is effectively unavailable for other work in weeks 11-12. Fees are quoted per engagement and vary by scope, system complexity and the number of criteria categories, so ask two firms to quote against the same written scope.
Where an existing ISO 27001 management system helps
An organisation already certified to ISO/IEC 27001:2022 has most of the underlying material and needs to re-present it, not rebuild it 3.
| Already in the ISMS | What the SOC 2 examination still needs |
|---|---|
| Scope statement and statement of applicability | A description of the system written to the SOC 2 description criteria |
| Risk assessment and treatment plan | The same register, dated inside the examination window |
| Internal audit and management review records | Evidence of management oversight mapped to the criteria |
| Supplier controls and agreements | A vendor inventory with assurance-report dates per service |
| Certificate from the certification body | An attestation report signed by a CPA firm |
The reverse direction is harder. A SOC 2 type 1 report is a point-in-time attestation and does not establish the management system that a certification audit expects to see running.
References
<!-- The rendered Sources block is generated from the verification markers above (ArticleShell). This list carries the publisher, official title and URL behind each of those markers, in the same order the article cites them. -->- AICPA & CIMA. SOC 2® — SOC for Service Organizations: Trust Services Criteria. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/ 1
- AICPA & CIMA. 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus – 2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 2
- AICPA & CIMA. 2018 SOC 2® Description Criteria (With Revised Implementation Guidance – 2022). https://www.aicpa-cima.com/resources/download/get-description-criteria-for-your-organizations-soc-2-r-report 6
- AICPA & CIMA. Illustrative SOC 2® Report with Illustrative System Description. https://www.aicpa-cima.com/resources/download/illustrative-soc-2-r-report-with-description-and-assertion 5
- AICPA & CIMA. Illustrative Management Representation Letter: SOC 2® Type 1, 31 August 2022. https://www.aicpa-cima.com/resources/download/illustrative-management-representation-letter-soc-2-r-type-1 4
- ISO. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements. https://www.iso.org/standard/27001 3
Sources
- 1AICPA & CIMA, SOC 2 topic page · verified 2026-09-03
- 2AICPA & CIMA, 2017 Trust Services Criteria · verified 2026-09-03
- 3iso.org, ISO/IEC 27001:2022 catalogue entry · verified 2026-09-03
- 4AICPA & CIMA, illustrative type 1 representation letter · verified 2026-09-04
- 5AICPA & CIMA, illustrative SOC 2 report · verified 2026-09-03
- 6AICPA & CIMA, 2018 SOC 2 description criteria · verified 2026-09-03
Related
- ISO 27001 first certification
Engagement pattern
- NIS2 for the security officer
Briefing
- NIS2 readiness for an important entity
Engagement pattern