CCSP Exam QuestionsBrowse all questions from this exam

CCSP Exam - Question 123


Unlike SOC Type 1 reports, which are based on a specific point in time, SOC Type 2 reports are done over a period of time. What is the minimum span of time for a SOC Type 2 report?

Show Answer
Correct Answer: A

SOC Type 2 reports are evaluations of an organization's internal controls over a period of time, and the minimum span of time for such an evaluation is six months. This is in contrast to SOC Type 1 reports, which assess the effectiveness of controls at a specific point in time. Therefore, a SOC Type 2 report must cover at least six consecutive months.

Discussion

6 comments
Sign in to comment
EdwardLeeBurtle
Jan 1, 2023

They need to fix the language on these. SOC 1, SOC 2 Type 1 and Type 2 etc. Use the correct format or it makes studying more difficult.

kepalonOption: A
Mar 24, 2023

6 months

DA95
Dec 10, 2023

C. One year

qpodian
Oct 9, 2024

It is 1 year. Just google it

ra1paulOption: A
Feb 2, 2025

12 months is a long time without any control changes.

MaciekMTOption: A
Feb 19, 2025

Although the AICPA does not mandate a strict minimum for the coverage period of a SOC 2 Type 2 report, the generally accepted industry practice (and what most clients and auditors expect) is a six-month coverage period at a minimum. This is because a Type 2 report is meant to verify the effectiveness of controls over time, rather than just at a single point.