Compliance

Is your SOC 2 report Type I or Type II, and how can customers obtain it?

How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.

Expert answer

State which report you hold and the difference reviewers care about: Type I evaluates control design at a point in time, while Type II tests operating effectiveness over an observation period, typically 6 to 12 months, and is what most enterprise reviewers require. Name the trust services criteria in scope, the audit period, and the distribution channel — usually a trust center or NDA-gated request.

Answer every security questionnaire in minutes

Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demo