nerdexam
(ISC)2

CCSP · Question #487

Unlike SOC Type 1 reports, which are based on a specific point in time, SOC Type 2 reports are done over a period of time. What is the minimum span of time for a SOC Type 2 report?

The correct answer is A. Six months. According to AICPA standards, a SOC 2 Type 2 report must cover a minimum audit period of six months to be considered valid. This extended period is necessary to evaluate not just whether controls exist (as SOC Type 1 does), but whether they operate effectively over time. One…

Submitted by joshua94· Apr 18, 2026Legal, Risk and Compliance

Question

Unlike SOC Type 1 reports, which are based on a specific point in time, SOC Type 2 reports are done over a period of time. What is the minimum span of time for a SOC Type 2 report?

Options

  • ASix months
  • BOne month
  • COne year
  • DOne week

How the community answered

(26 responses)
  • A
    92% (24)
  • B
    4% (1)
  • C
    4% (1)

Explanation

According to AICPA standards, a SOC 2 Type 2 report must cover a minimum audit period of six months to be considered valid. This extended period is necessary to evaluate not just whether controls exist (as SOC Type 1 does), but whether they operate effectively over time. One month (B) and one week (D) are too short to demonstrate sustained operational effectiveness. One year (C) is a common audit period in practice but is not the minimum - six months is the floor established by the standard.

Topics

#SOC reports#Auditing standards#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice