---
title: SOC 2 Type 2 Quick Start Guide - Core Tier Offering
description: SOC 2 Type 2 Quick Start Guide
---

[Skip to content](https://knowledge.sensiba.com/quick-start-guide-soc2-type2#main-content)

English

Show submenu for translations

- Sensiba

Open main navigation

Close main navigation

- Sensiba
- English
  
  Show submenu for translations
- [Go to sensiba.com](https://sensiba.com/)

[Go to sensiba.com](https://sensiba.com/)

 Hi There! How can we help you?

- There are no suggestions because the search field is empty.

1. [Sensiba Knowledge Base](https://knowledge.sensiba.com/?hsLang=en)
2. [Platform](https://knowledge.sensiba.com/platform?hsLang=en)

# SOC 2 Type 2 Quick Start Guide - Core Tier Offering

## Transition into Type 2 with Confidence

This guide will help you navigate the SOC 2 Type 2 audit process and ensure you're fully prepared for success.

#### **Understanding Type 2: What's Different?**

#### **Type 1 vs Type 2: The Key Difference**

**Type 1:** Evaluates whether controls are suitably designed at a specific point in time.

**Type 2:** Evaluates whether controls operated effectively throughout a defined period (typically 3-12 months).

**Already Completed Type 1?**

If you have already completed a Type 1 audit, much of the heavy lifting has been done through configuring the necessary systems, publishing policies, and personnel onboarding. The focus for Type 2 is maintaining and demonstrating ongoing operational effectiveness.

**New to SOC 2?** If you have not completed a Type 1 previously, please refer back to the guidance in the [SOC 2 Type 1 Quick Start Guide](https://knowledge.sensiba.com/soc2-quickstart-guide?hs_preview=BUYqtmnA-212242300720&hsLang=en) to ensure your foundational setup is complete before beginning your Type 2 journey.

---

### **Determining Your Audit Period**

Your **audit period** (also referred to as the observation period) is the timeframe during which your auditor will assess whether your controls are operating effectively.

#### Recommended Timeline

**Observation Period Length**  
For your first SOC 2 Type 2 audit, we generally recommend a **3-month observation period**. If you have previously completed a Type 2 audit, we typically recommend transitioning to a **12-month observation period** for subsequent audits.

**Scheduling Best Practices**  
Where possible, align your observation period with calendar months by starting on the **first day of the month** and ending on the **last day of the month**.

If you are transitioning from a **Type 1 to a Type 2 audit**, we recommend starting your Type 2 observation period as close to your Type 1 report date as practical, or earlier where appropriate.

**Backdating the Observation Period**  
In some circumstances, it may be possible to **backdate your observation period**, provided the required systems and platform integrations were connected and monitoring during the applicable period.

If you are considering backdating your observation period or are unsure which dates are appropriate, please **consult with your auditor before finalising your audit period**.

---

### **Maintain Evidence Throughout Your Audit Period**

For a SOC 2 Type 2 audit, evidence must demonstrate that your controls operated effectively **throughout the entire observation period**. This means it is important to maintain evidence as activities occur, rather than trying to recreate or collect documentation at the end of the audit period.

👀 Looking for the control framework? Please find SOC 2 Control Framework in the [**SOC 2** **Foundations Quick Start Guide.**](https://knowledge.sensiba.com/soc2-quickstart-guide?hsLang=en)

The following are key areas to consider:

#### Population-Based Controls

For controls that apply to events or activities occurring throughout the observation period, maintain evidence for **all applicable instances**. Examples include:

- **New Hires:** Background checks, policy acknowledgements, onboarding checklists, and documentation confirming appropriate system access was approved.
- **Terminations:** Offboarding checklists, evidence of system access revocation, and confirmation that company devices and assets were returned.
- **Code Changes:** Change tickets or pull requests demonstrating appropriate testing, review, approval, and deployment for production changes.
- **Security Incidents:** Incident tickets documenting the response, resolution, root cause analysis (RCA), and any resulting corrective actions.
- **Personnel Compliance:** Evidence that in-scope personnel maintain required security configurations and comply with applicable policies, such as disk encryption, antivirus/endpoint protection, and security policies.

#### Periodic Controls

For controls performed on a defined schedule, ensure the activity is completed within the required timeframe and that supporting evidence is retained. Examples include:

- **Business Continuity & Disaster Recovery Testing:** Test your business continuity and disaster recovery plans at the required frequency, including demonstrating the restoration of critical systems and data where applicable. Document the test results and any lessons learned.
- **Incident Response Testing:** Test your incident response procedures using a simulated scenario (e.g., a phishing attack), and document the response, outcomes, and lessons learned.
- **Risk Assessment:** Complete and document an organizational risk assessment at the frequency defined by your policies and procedures.
- **Penetration Testing:** Complete penetration testing at the required frequency, where applicable, and retain the resulting report and evidence of remediation.
- **Security Awareness Training:** Ensure all in-scope personnel complete required security awareness training within the defined timeframe.
- **Access Reviews:** Complete and document user access reviews at the frequency defined by your access management policies.
- **Vendor Reviews:** Complete periodic reviews of critical vendors and subservice organizations, including reviewing relevant SOC reports or other assurance documentation where applicable.

 

**💡Tip:** Don't wait until the end of your audit period to gather evidence. Maintaining evidence as activities occur will make your audit preparation significantly easier and help prevent gaps in your audit trail.

---

### What to Expect During Your Type 2 Audit

Once your observation period is underway, your auditor will begin reviewing your compliance environment and collecting the evidence required to complete the audit.

#### **Audit Readiness Review**

Your auditor will review your Compliance Automation Platform and assess the applicable controls. You will be provided with the **Type 2 workpaper**, which will identify any outstanding controls, evidence, or information requiring attention.

#### **Evidence Requests**

For population-based controls, your auditor will typically request supporting evidence approximately **2 weeks before the end of your observation period**. This allows sufficient time to determine the appropriate sample and request the required evidence.

#### **Sampling Methodology**

For population-based controls, your auditor will select samples based on the **size and nature of the population** during the observation period. You may therefore be asked to provide evidence for a selection of applicable events or activities rather than every individual occurrence.

#### **Non-Occurrences**

If no instances of a population-based control occurred during your observation period (for example, no new hires, terminations, or security incidents), the control may be recorded as a **"non-occurrence"** in your audit report.

A non-occurrence is a **standard audit notation** and does not indicate a control deficiency or negatively impact your compliance. It simply means there were no applicable instances available to test during the observation period.

#### **Exceptions**

If an instance of a control did occur but did not fully meet the defined control requirements, this may be identified as an **exception**. Your auditor will assess the nature and significance of the exception and determine whether any further action or documentation is required.

An exception does not automatically mean that your audit will be unsuccessful. Your auditor will discuss any identified exceptions with you and provide guidance on the appropriate next steps.

---

### Tips for Success

A proactive approach throughout your observation period will help keep your audit on track and minimise delays.

- **Monitor Your Compliance Platform Regularly**  
  Review your compliance dashboard and monitoring results at least weekly to identify and address failed tests, outstanding tasks, or evidence gaps early.
- **Complete Periodic Controls Early**  
  Where possible, schedule and complete annual or periodic controls early in your observation period. This provides additional time to address any issues or remediation identified through the testing process.
- **Maintain Evidence as You Go**  
  Upload and maintain supporting evidence throughout the observation period rather than waiting until the end. This will make the final audit evidence collection process much smoother.
- **Address Issues Promptly**  
  Investigate failed monitoring tests, control exceptions, and outstanding tasks as they arise. Early action gives you more time to remediate issues before the audit is finalised.
- **Ask Questions Early**  
  If you are unsure about a control requirement, evidence request, or whether an activity is in scope, reach out to your auditor or Customer Success Manager. We are here to help you understand what is required and keep your audit moving forward.

 

- [Platform](https://knowledge.sensiba.com/platform?hsLang=en#main-content)

    - [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)
    - [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)
    - [Scrut](https://knowledge.sensiba.com/platform?hsLang=en#scrut)
    - [Sprinto](https://knowledge.sensiba.com/platform?hsLang=en#sprinto)
- [Best Practices Series](https://knowledge.sensiba.com/best-practices-series?hsLang=en#main-content)

    - [Risk management & internal controls](https://knowledge.sensiba.com/best-practices-series?hsLang=en#risk-management-internal-controls)
    - [Information & communication](https://knowledge.sensiba.com/best-practices-series?hsLang=en#information-communication)
    - [Data protection](https://knowledge.sensiba.com/best-practices-series?hsLang=en#data-protection)
    - [System security](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-security)
    - [Change management](https://knowledge.sensiba.com/best-practices-series?hsLang=en#change-management)
    - [System operations](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-operations)
    - [Control environment](https://knowledge.sensiba.com/best-practices-series?hsLang=en#control-environment)
- [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#main-content)

    - [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)
    - [Vulnerability Management](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#vulnerability-management)
    - [Security Awareness](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#security-awareness)
    - [Anti-malware](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#anti-malware)
    - [Information Asset Lifecycle](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#information-asset-lifecycle)
    - [Access Control](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#access-control)
    - [Governance Requirements](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#governance-requirements)
- [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)
- [Control Environment](https://knowledge.sensiba.com/control-environment?hsLang=en)
- [Information and Communication](https://knowledge.sensiba.com/information-and-communication?hsLang=en)
- [Risk Management](https://knowledge.sensiba.com/risk-management?hsLang=en)
- [Vendor Management](https://knowledge.sensiba.com/vendor-management?hsLang=en)
- [System Security](https://knowledge.sensiba.com/system-security?hsLang=en)
- [System Operations](https://knowledge.sensiba.com/system-operations?hsLang=en)
- [Change Management](https://knowledge.sensiba.com/change-management?hsLang=en)
- [Confidentiality](https://knowledge.sensiba.com/confidentiality?hsLang=en)
- [Privacy](https://knowledge.sensiba.com/privacy?hsLang=en)
- [CDR Reps](https://knowledge.sensiba.com/cdr-reps?hsLang=en)
- [Access reviews](https://knowledge.sensiba.com/access-reviews?hsLang=en)
- [Governance](https://knowledge.sensiba.com/governance?hsLang=en)
- [Employee management](https://knowledge.sensiba.com/employee-management?hsLang=en)
- [FAQs](https://knowledge.sensiba.com/faqs?hsLang=en)
- [Sensiba Audit Tools](https://knowledge.sensiba.com/sensiba-audit-tools?hsLang=en)

- Sensiba

[![Sensiba Logo](https://knowledge.sensiba.com/hs-fs/hubfs/Sensiba_Logo_Hubspot-01.png?width=247&height=48&name=Sensiba_Logo_Hubspot-01.png "Sensiba Logo")](https://sensiba.com/)

Copyright © 2026, Sensiba LLP