New: Autonomous AI risk intelligence is live — your compliance program in 12 minutes. Get started →

SOC 2 · Common question

How often do you recertify SOC 2?

Short answer

SOC 2 is not a one-time certification — it's an annual attestation. Type 2 reports typically cover a rolling 12-month window and are re-issued each year. Most enterprise buyers require your report be dated within the last 12 months to remain valid for procurement.

SOC 2 isn't a certification with a fixed expiry date — it's an attestation covering a specific time period. That distinction matters for how often you 'recertify.'

Type 1 reports are point-in-time: they attest that controls were designed correctly on a specific date. Enterprise buyers typically accept a Type 1 report for 12 months from the report date, and only for early-stage vendors. After that, they expect Type 2.

Type 2 reports cover a period — usually 6 or 12 months — during which controls must operate effectively. The standard cadence is:

Year 1: Type 1 (unblocks first deals in month 3–4), then a 6-month Type 2 covering months 4–10, issued in month 11.

Year 2+: 12-month Type 2 reports on a rolling basis, each covering the prior 12 months.

Enterprise procurement typically wants your Type 2 report to be dated within the last 12 months. A report older than that starts triggering renewal blockers — buyers assume controls may have drifted.

Practical implication: SOC 2 becomes an annual event. Prep + audit + report issuance is roughly 6–8 weeks each year after the first cycle. Cost drops 20–40% after year one because the initial policy and control setup carries forward.

The mistake that costs the most is letting a Type 2 report expire without a successor scheduled. If a large customer's compliance review lands in the gap, deals stall for weeks. Schedule the next audit engagement 3 months before the current report expires.

Related

Still have questions?

Book a 20-minute walkthrough.

More on SOC 2