Planning guide

How long does SOC 2 take

The short answer: about two to four months to a Type 1 report, and about six to twelve months to a first Type 2 report, counted from the day you start rather than the day you sign with an auditor. The long answer is that most of the delay is yours, not the auditor's.

Phase by phase

The fast column below assumes a small, single cloud environment, a compliance owner with real time to spend, and a decision maker who does not disappear for two weeks when a policy needs approving. The typical column is what we see more often.

SOC 2 phase durations, fast case and typical case
PhaseFastTypical
Scoping and auditor selectionDeciding which criteria and systems are in scope, getting three quotes, checking the firm can issue in your timeframe.1 to 2 weeks3 to 6 weeks
Readiness and remediationPolicies written and approved, access reviews started, logging and alerting in place, onboarding and offboarding evidenced.3 to 4 weeks2 to 4 months
Type 1 fieldwork and reportPoint in time testing plus report drafting and partner review. The report almost always takes longer than fieldwork.2 weeks4 to 8 weeks
Type 2 observation windowControls must operate, and be evidenced operating, for the whole window. This clock cannot be shortened by spending money.3 months3 to 12 months
Type 2 fieldwork and reportSampling across the window, follow up requests, exception discussion, drafting and quality review.3 weeks6 to 10 weeks

The five things that actually cause delay

  • Policy approval. Writing a policy takes an afternoon. Getting it formally approved, dated and acknowledged by every employee takes weeks in most companies.
  • Evidence with no history. An auditor cannot test an access review you performed once, yesterday. Controls with a quarterly cadence need to have actually run.
  • Penetration test scheduling. Good testing firms book four to eight weeks out, and the report arrives two weeks after testing ends. Start this early.
  • Auditor capacity. Fieldwork slots in the last quarter of the calendar year are scarce. Ask about issuance dates, not just start dates.
  • Subservice organisations. If you rely on a vendor for controls, you need their report, and their report has its own dates and gaps to bridge.

How to compress the timeline honestly

You can shorten readiness by paying for help, you can shorten fieldwork by having evidence organised before the auditor asks, and you can shorten the observation window to three months. What you cannot do is manufacture history. If a customer needs a report in six weeks, the only truthful answer is a Type 1 now with a Type 2 to follow, and a letter from your auditor confirming the Type 2 window has started. Most enterprise buyers accept that if you tell them early.

Watch the gap period too. Once you have a Type 2, the next report covers the following window, and buyers will notice a gap between the end of one report and the start of the next. Plan the second audit before the first report lands.

For the money side of the same plan, see the SOC 2 cost calculator, decide the report type with Type 1 vs Type 2, and work through the readiness checklist before you book fieldwork.