A Type 1 report answers a point-in-time question — were the controls designed properly on this date? A Type 2 answers a harder one: did they operate, without interruption, across the whole observation period? Every access review, change ticket, onboarding checklist, and backup job inside the window is fair game for testing. First reports often run a shorter window to reach the market sooner; renewals typically settle into an annual rhythm, each new period picking up where the last one ended.
The period is a calendar fact, not a negotiation. Evidence is generated in real time by the systems and rituals of the business, which means a twelve-month report requires twelve months of artifacts — no diligence sprint can manufacture last quarter’s access reviews. Teams facing a deal deadline sometimes ask their auditor to squeeze the window; the only lever that genuinely moves the date is starting the period earlier. That is why SOC 2 before Series A is usually the cheaper play: the window runs while the company builds, and the report is waiting when diligence starts.
In everyday usage, the audit window is this same span — observation period is the formal report term — though some teams use that phrase for the fieldwork weeks afterward, when the auditor shows up to test what the period produced. And the period only applies to SOC 2 Type 2; a Type 1 has no period at all, just an as-of date. What fills the window, day after day, is evidence collection — which is why programs that automate it treat the period as routine rather than an endurance event.