Where a Type 1 stops at design, a Type 2 examination follows every control through an observation period — commonly three months for a first report, twelve at renewal — and checks that it ran each time it was supposed to. The auditor pulls full populations (every access request, code change, and new hire in the window), samples them, and records results control by control in the testing section, including any exceptions found along the way.
A Type 1 shows controls exist; a Type 2 shows someone operated them, month after month, with an independent firm checking the artifacts. That is the assurance a security reviewer wants before routing your report to their risk committee, and it is why enterprise questionnaires and RFPs so often specify “Type 2” by name. The framework itself — criteria, scoping, audit mechanics — is covered on our SOC 2 page.
The calendar is the real constraint. Evidence must exist for the entire window, so a lapse in quarterly access reviews cannot be repaired after the fact — the period restarts or the miss lands in the report. Teams that treat the window as a live operating commitment, not a date on the auditor’s calendar, renew without drama; teams that rediscover it each summer do not.