Compliance framework
What is SOC 2 Type I?
A SOC 2 Type I report evaluates whether a service organization's security controls are designed appropriately at a specific point in time. Unlike a Type II, it does not assess whether those controls operated effectively over time.
Type I reports are often a starting point for vendors early in their compliance journey. They establish that controls exist and are designed correctly, but they carry less assurance than a Type II because operating effectiveness is untested. Procurement teams accepting a Type I should note the report date and plan to request a Type II within twelve months.
Which vendors hold SOC 2 Type I?
Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.
Common questions about SOC 2 Type I
Which vendors hold SOC 2 Type I certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current SOC 2 Type I certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does SOC 2 Type I certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's SOC 2 Type I report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.