ClearPenTest

AICPA · SOC 2 Type I

Does SOC 2 Type I require a penetration test?

A SOC 2 Type I reports on whether controls are suitably designed at a single point in time. It is a snapshot, and it is the fastest route to having a report to hand a customer.

Common evidenceTrust Services Criteria CC4.1

The short answer

A Type I does not require a penetration test, and because it tests design rather than operating effectiveness over time, a single recent test is usually enough evidence. The test needs to predate the report date, which is the part teams get wrong.

Who it applies to

Companies that need a report in weeks rather than months, usually because a deal is waiting on one.

In detail

A Type I asks one question: as of this date, were the controls designed well enough to meet the criteria. There is no observation window, so there is no need to show that a control ran repeatedly over six months. That makes it achievable quickly, and it is why it is the common first report for a startup under deal pressure.

The testing implication is straightforward. A recent penetration test dated before the report date is a clean design-evidence artifact. A test dated after it is not evidence for that report, which is a scheduling mistake that costs real time when the report is already in draft.

A Type I is a waypoint, not a destination. Most enterprise buyers who accept one will ask when the Type II is coming, so it is worth planning the observation window before the Type I is even issued.

What to have in scope

  • The system as described in the report, tested before the report date
  • Findings remediated or formally accepted with a documented rationale
  • Evidence packaged so it transfers into the Type II window without a second engagement

Questions people ask

What is the difference between SOC 2 Type I and Type II?

Type I reports on whether controls are suitably designed at a single point in time. Type II reports on whether they operated effectively across an observation window, typically three to twelve months. Type II is the one most enterprise buyers eventually require.

How fast can a startup get a SOC 2 Type I?

Weeks rather than months once policies, access controls and monitoring are actually in place. The gating item is usually evidence collection, not the audit fieldwork itself.

Does a Type I penetration test count toward the Type II?

It can, if the test date falls inside the Type II observation window. If the Type I test predates the window, expect to test again inside it.

This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.