On this page

Most companies with a SOC 2 Type 2 report get a new one every year, each covering a 12-month period that starts the day after the last one ended. Annual is what customers expect, not something the AICPA sets. A Type 1 is usually done once, and a first Type 2 often covers 3 to 6 months before the company moves to 12.

SOC 2 is a voluntary attestation, so the interval comes from your customers. Vanta’s help center says there is no mandatory timeframe to renew and that most companies complete an audit on an annual (12 months) or semi-annual (6 months) basis. This guide covers frequency: how often reports are issued, how long each period runs, and what happens in the months between reports. For how to run the renewal itself, use our SOC 2 audit renewal playbook.

The usual SOC 2 cycle

StepReportWhat it coversHow often
First report, when a buyer needs something fastType 1Control design at one dateUsually once
First Type 2Type 2Commonly 3 to 6 monthsOnce
Every year afterType 212 months, starting the day after the last period endedAnnually

Johanson Group describes this pattern: a Type 1 is normally done once, though a company may repeat it after significant changes, then a first Type 2 of 3 to 6 months, then 12-month periods. Not every company starts with a Type 1. Scrut notes that a team whose controls already operate can go straight to a Type 2, and that a Type 1 will not satisfy a buyer who requires a Type 2. Our Type 1 vs Type 2 comparison covers how to choose.

Why annual is a convention, not an AICPA rule

A SOC 2 report describes a past period. It does not expire. Schellman puts the rule of thumb at 12 months, says it is up to your customers, and says the AICPA does not specify a validity period. Schellman also reports that the AICPA permits use of its SOC logo for 12 months after the report date. That guideline sits behind a registration wall on the AICPA’s site, so we are relying on Schellman’s description of it.

Sources disagree on where the 12 months start. Secureframe says a report’s opinion is typically accepted for twelve months after the issue date. Bridge letter guidance from Larson & Company measures the gap from the end of the report period. A buyer can use either, so ask which one applies to you.

Contracts override convention. MJD has seen agreements that require annual 12-month reports or a minimum period length for a first-time audit, and HiComply says enterprise agreements often include an annual Type 2 clause. HiComply’s own guidance is that a report older than 12 months is increasingly flagged by procurement teams. That is one vendor’s view, not a measured buyer behavior.

How long each Type 2 period should be

Three, six, and twelve months are the common lengths, and your CPA firm has to agree to the dates. MJD, a CPA firm writing on the Cloud Security Alliance site, says there are no requirements for the length of the period and that you usually see three to twelve months. Our observation period guide covers how control frequency fits each window, and our timeline guide covers how long testing and the report take after the period closes.

You may see forum posts claiming the AICPA sets a six-month minimum. We could not source that. The six-month language Linford & Company quotes from AICPA guidance is in the SOC 1 guide, and it says a Type 2 period would need to overlap, typically by at least six months, the customer’s audit period. That is about how useful a SOC 1 report is to a customer’s auditor, not a minimum for SOC 2.

Short periods have a cost over time. Schellman gives an example: if a company’s annual recovery test falls outside a 6-month period, Availability criterion A1.3 could be hard to meet. Schellman says most organizations choose a 12-month period once past the ramp-up from Type 1 to Type 2. MJD flags a commercial risk. A company that issues a 3-month report every year may leave customers wondering what happened in the other nine months.

What two years look like on the calendar

The schedule below is an illustration, not a quote from any firm. A company has a Type 1 as of month 0 and opens its first Type 2 period the same day. That period runs 6 months, from month 0 to month 6. Its report arrives 1 to 3 months after the period closes, so at month 7 to 9. The second period runs 12 months, from month 6 to month 18, starting the day the first one ended. Its report arrives at month 19 to 21. The 1 to 3 month lag follows the ranges in our timeline guide: about 2 to 8 weeks of testing plus about 3 to 5 weeks for the report.

Type 1: as-of date to report
Type 2: first period
Report for first period
Type 2: second period
Report for second period
Newest report ended 12+ months ago
Even back-to-back periods leave 1 to 3 months when the newest report ended a year or more agoIllustrative schedule, months from the Type 1 as-of date. Each report row runs from the earliest to the latest likely issue date, 1 to 3 months after the period closes.

The last row is easy to miss. At month 18 the newest report in hand is the first one, and its period ended 12 months earlier. That stays true until the second report is issued at month 19 to 21. A buyer who counts report age from the period end sees a report 12 to 15 months old for up to 3 months, even though the company never missed a period. A buyer who counts from the issue date has less to complain about, and only if the second report takes longer to issue than the first.

Two things shrink that window. One is a shorter lag between period end and report, which you can ask your CPA firm to commit to in writing. The other is a bridge letter: a statement from your management about changes since the report period ended. The CPA firm provides no assurance on it. Linford & Company says bridge letters typically cover no more than three months and suggests revisiting the report period with the auditor rather than issuing a letter for longer. Our bridge letter guide covers what to put in one.

If the next period starts late

If the second period starts months after the first ended, the months in between are never tested, and no later report will cover them. A bridge letter can describe them, but it is management’s statement, so a buyer that wants independent coverage for those months cannot get it from the letter. Johanson Group advises that once the audit process starts, you should always be under an audit period, because gaps between reporting periods mean explaining to clients what happened.

When customers ask for more or less than annual

Customer requests are often ambiguous. Ask what the buyer needs before you commission work.

What the customer saysWhat it can meanWhat to ask
”Annual SOC 2 Type 2”A report issued in the last 12 months, a period that ended in the last 12 months, or a 12-month periodWhich date they count from, and whether a bridge letter is accepted
”Semi-annual” or “every six months”Two back-to-back 6-month periods, or a 12-month report issued every six monthsWhether they need 12 months of coverage in each report
”An updated report after a major change”A new Type 1 or Type 2, or a bridge letter that names the changeWhich they accept. The CPA firm judges what the change affects
”A report for our fiscal year”A period that overlaps their year, with a bridge letter for the restTheir year-end date

The first row follows from the sources above. The second reflects our reading of the term: Vanta and HiComply both describe 6-month cycles, and neither says which structure it means. IS Partners says a significant change in the control environment can warrant a Type 1 or a full Type 2. Larson & Company’s fiscal-year example is a report ending October 31 and a customer year-end of December 31, with a bridge letter covering the two months between.

For less than annual, we found no rule that forbids a longer gap and no source that measures how buyers treat one. Plan to explain any gap to the buyers who ask. Linford & Company describes SOC examinations as meant to recur at least annually, to give customers continuous coverage.

Before you fix your dates

  1. Read the contract or security questionnaire for a stated period length, maximum report age, or bridge letter rule.
  2. Ask the buyer whether report age counts from the issue date or the period end.
  3. Ask your CPA firm how long it usually takes from period end to issued report, and book the next period’s fieldwork before the current one closes.
  4. Start each new period the day after the last one ended.

To work backward from a customer deadline, use the SOC 2 timeline calculator. If you are choosing a firm for a recurring engagement, compare SOC 2 auditors and ask each one about report lag and next-period scheduling.