SOC 2 Type II blocks enterprise deals, so it gets bought under time pressure, usually as an audit plus a compliance platform. That combination covers perhaps a third of the actual work. The rest is engineering - and because Type II tests whether controls operated over a period rather than existed on a date, the work has to be done before the clock starts, not during the audit.
01Type I and Type II are different products
Type I attests that controls were designed appropriately at a point in time. Type II attests that they operated effectively across an observation window, typically three to twelve months. Enterprise buyers almost always want Type II, and the observation window is why the timeline cannot be compressed past a point.
The sequencing that works is readiness first, then a deliberate window start once controls genuinely operate. Starting the window while controls are still being implemented produces exceptions in the report, and a Type II with exceptions is materially harder to sell than one without.
| Phase | Duration | What happens |
|---|---|---|
| Gap assessment | 2-4 weeks | Scope, trust criteria, what is missing |
| Remediation | 2-4 months | Engineering work - the largest phase |
| Window start | - | Controls must operate from here |
| Observation window | 3-12 months | Evidence accumulates continuously |
| Fieldwork and report | 4-8 weeks | Auditor tests samples from the window |
02The engineering work behind the controls
Access review requires knowing who has access to what, which requires identity and permissions to be centralised rather than scattered across systems with local accounts. Change management requires every production change to be traceable to a reviewed, approved change - which means no direct pushes and no manual production edits.
Logging and monitoring require retained, tamper-resistant logs covering access to customer data. Vulnerability management requires a working inventory of dependencies and a demonstrable patching cadence. Each of these is a real project, and together they are why remediation dominates the timeline.
- Centralised identity with SSO, so access reviews are possible at all
- Enforced code review and CI-gated deploys - no direct production access
- Immutable audit logging with defined retention
- Dependency inventory with an evidenced patching cadence
- Onboarding and offboarding that provably revoke access promptly
03Automate evidence or spend the window collecting it
Type II auditors sample from across the observation window. If evidence is gathered manually at the end, someone spends weeks reconstructing months of access reviews, change approvals and monitoring alerts - and any gap becomes an exception because the control demonstrably did not operate.
Compliance platforms earn their cost here by collecting evidence continuously from the systems that produce it. What they do not do is implement the controls; they observe controls that already exist. Buying the platform before doing the engineering produces a dashboard showing precisely which controls you do not have.
04Scope narrowly and deliberately
Every system in scope must have controls evidenced across the window, so scope drives cost more than anything else. Security is the mandatory trust services criterion; availability, confidentiality, processing integrity and privacy are optional and each adds work.
Add only the criteria your customers actually ask for. Buyers frequently include availability by default and discover it commits them to evidencing uptime monitoring and capacity management for the whole window. Similarly, systems that do not touch customer data can often be excluded with a defensible boundary - and defining that boundary early is one of the highest-leverage decisions in the programme.
Topics
Marcus Hale
Security Lead · SyncTrix
Writes about the engineering decisions behind production systems - architecture, delivery and the trade-offs that only show up at scale.
Building something like this?
SyncTrix engineers AI, SaaS, platform and cloud systems for enterprises and high-growth teams. Tell us what you're shipping and we'll scope it with you.