Nothing in the standard stamps an expiry on the PDF. The report speaks only to its own coverage — a Type 1 to a single date, a Type 2 to its observation period — and everything after the period end is, strictly speaking, unaudited. That is exactly how security reviewers read it.
So validity gets decided in vendor reviews, not by the AICPA. Reviewers check the period end date first; a report that ended more than roughly twelve months ago starts drawing questions, conditions, or an outright rejection, and plenty of procurement processes encode the twelve-month rule mechanically. Material changes since the period — an acquisition, a new product, an incident — age a report faster than the calendar does. How reviewers pull reports apart is covered in SOC 2 in due diligence.
Annual audits leave a structural gap: the next window has to close and the next report has to be written, so there is always a stretch where your freshest report is aging. The standard patch is a bridge letter — a short, management-signed statement that controls have kept operating since the period end. What it can and cannot promise, with a worked example, is on the bridge letter guide.
The period end date, not the issue date. A window that closed over a year ago — or one that predates major changes to your product, team, or infrastructure — gets discounted however recent the PDF is.
Yes — contiguous windows are the convention. A gap between periods becomes a permanent hole in your audit history that reviewers ask about, and a bridge letter covers issuance lag, not skipped months.