SOC 2 is voluntary, so the cadence is set by whoever reads the report. Customer contracts and vendor-management policies typically require a “current” report, and current is near-universally interpreted as covering the past twelve months. That interpretation, multiplied across your customer base, is the requirement. Some regulated buyers go further and write the annual expectation into their vendor terms outright.
The clean pattern is consecutive windows: the day one observation period ends, the next begins, and each year’s audit tests the year behind it. Let a gap open between periods and it turns into a permanent hole in the audit history — visible in the period dates forever, and a reliable diligence question later.
Annual audits should not mean annual effort spikes. Access reviews, change management, vendor assessments, and evidence collection are what fill the next window — the posture usually called continuous compliance. Companies that keep it running through a managed program meet each renewal with the evidence already in hand; companies that let the platform decay between audits re-buy readiness every year at full price. Run continuously, the annual audit becomes a sampling exercise over a year that already went well.
You can, and some companies do under budget pressure — but the period gap stays visible permanently, some contracts read it as a breach, and rebuilding the program usually costs more than maintaining it would have.
Noticeably, when the program ran all year: same auditor, settled scope, evidence on tap. Renewals only stay dramatic for teams that rediscover their controls a month before fieldwork.