Every SOC 2 engagement produces one of two report types, and Type 1 is the point-in-time version: the auditor examines the system description and the design of each control as of a stated date — say, March 31 — then opines on whether those controls, as built, would satisfy the Trust Services Criteria. Nothing in it claims the controls have actually run. That gap between design and operation is the entire difference between the report types, unpacked under design vs. operating effectiveness.
Type 1 earns its keep as a milestone. A company that stood up its program eight weeks ago has no operating history to audit, but it can still hand a prospect a signed report showing the controls exist and an auditor has inspected their design. Startups under deal pressure sequence it deliberately: close the readiness gaps, take the Type 1, open the observation window, then deliver the Type 2 to the same buyer months later. The economics and timing of that path are laid out on our SOC 2 framework page.
Sophisticated reviewers read a Type 1 as a statement of intent rather than proof of execution, and many security teams accept one only alongside a committed Type 2 date. Present it that way — the first checkpoint on a dated schedule, not the finish line — and it keeps procurement conversations moving instead of stalling them.