Skip to main content

From Type I to Type II: What Happens After Your First Report

A Type I report doesn't automatically turn into Type II — here's the monitoring period in between and what actually triggers the next audit.

Written by Upendra Varma

A SOC 2 (or ISO 27001) Type I report is a snapshot: it proves your controls were designed and in place on a single point in time. A Type II report proves those same controls actually operated correctly over a stretch of time — typically 3–12 months. Getting from one to the other isn't automatic, and it's easy to assume "we're done" after Type I when really you've just finished step one.

There's no re-audit waiting to happen automatically

Once your Type I report is issued, ComplyJet doesn't start a second audit behind the scenes, and your auditor doesn't either. What happens instead:

  1. The monitoring period begins. This is the stretch of time your Type II report will actually cover — ComplyJet keeps running your tests and collecting evidence throughout, exactly like it did leading up to Type I.

  2. You (or your auditor) decide when the monitoring period is long enough. Most auditors want a minimum of 3 months of evidence for a first Type II; some customers wait 6–12 months depending on what a prospect or customer is asking for.

  3. You create the Type II audit yourself, the same way you created Type I — see Creating & Managing Audits — selecting the monitoring period as your evidence date range, and engaging your auditor for that engagement.

Nothing about this requires a new sales conversation or contract in most cases if you're staying with the same auditor, but it does require you to actively start it — ComplyJet surfacing a passing dashboard doesn't mean a Type II audit has been kicked off for you.

What to watch during the monitoring period

Between Type I and Type II, keep an eye on:

  • Test failures — anything that regresses during the monitoring window can show up as an exception in your Type II report, so treat ongoing test failures as seriously as you did pre-Type-I.

  • Evidence continuity — if you disconnect an integration or change a process mid-window, make sure the gap is explainable; auditors will ask.

If your dashboard still shows "Type I" tasks

The Tasks page reflects whichever audit type you're actively working toward. If you've completed Type I and want to start prepping for Type II, that's set when you create the Type II audit — the readiness view doesn't automatically relabel itself just because time has passed.

Did this answer your question?