# SOC 2 Type 2 | Secureframe

> Understand SOC 2 Type II audits, how Type II differs from Type I, the audit timeline, what auditors evaluate, and why Type II reports are preferred by enterprise customers.

canonical: https://secureframe.com/glossary/soc-2-type-ii

A SOC 2 Type 2 report examines how well a service organization's system and controls perform over a period of time.

## What is SOC 2 Type 2?

There are two types of SOC 2 reports: Type 1 and Type 2 (sometimes written as “Type I" and "Type II”). 

A Type 1 report is a point-in-time report that assesses how your security controls are designed. 

[A SOC 2 Type 2 report](https://secureframe.com/blog/soc-2-type-ii) examines how well a service organization's system and controls perform over a period of time (typically 3-12 months). 

Both report types require an external audit by an AICPA-accredited CPA firm. Organizations that need a SOC 2 report as quickly as possible may opt for a Type 1 report, which takes less time to complete. However, SOC 2 Type 2 reports hold more weight with customers and will be necessary for most companies to achieve.
