SOC 2 report shelf life, and what year two costs
Nothing on the report expires, but buyers stop trusting it after about a year. That clock sets your renewal costs.
How long is a SOC 2 report valid? Technically, forever. It carries no expiry date and nobody can cancel it. What runs out is trust. A buyer will usually stop accepting a Type 2 about twelve months after the period it covers has ended, and that informal line is what drives a yearly renewal.
So the useful question is a cost one. What does it cost to keep a current report in front of buyers in year two, and year three?
The confusion tends to show up late, long after anyone has thought about the report. Your first report closes a deal. Eleven months later a new buyer asks for it and says it is too old. The document has not changed at all, but the reader’s patience has.
Two kinds of report, two kinds of age
SOC 2 does not certify you. A CPA firm examines the controls you put in scope and writes up what it found, with a date or a date range printed on the front.1 That printed window is the only thing a buyer uses to judge age. How it reads depends on the type.
- Type 1
- Looks at whether your controls were designed well on a single date. It says nothing about the weeks before or after, so it ages from that one day.
- Type 2
- Looks at whether the controls worked across a stated period, often three to twelve months. Age is counted from the last day of that period.
The facts inside stay true, because they describe a window that really happened and nothing later can undo that. A report covering last January through December still tells the truth about last year. It just says nothing about this spring, and a careful reviewer knows it. Type 1 versus Type 2 explains which one your buyer is likely to ask for.
The line buyers draw at twelve months
The rule is not in the standard. Buyers apply it anyway. If your Type 2 period ended more than a year ago, the review stops. Some vendor risk programs put it in policy. Others just send the report back.
The strict version asks for two things at once: a report whose period ended within the last year, and written cover for every month between that end date and the day they are reading it. That second request catches people out. Your period ended in March, it is now August, and from the buyer’s chair five months of your company are blank.
| The buyer asks for | This works | This gets sent back |
|---|---|---|
| Your SOC 2 | Your latest report, with its dates written in the email | A link to a trust page with no report behind it |
| A recent Type 2 | A report whose period ended inside the past year | A Type 1, whatever its date |
| Proof of coverage today | That report plus a signed letter for the months since | A silent gap they find on their own |
What year two costs
This is the part a first year plan leaves out, because the first quote only ever talks about getting the first report. The twelve month line means a SOC 2 is not a one time purchase. It is an ongoing cost of staying current, whatever you call it. Year two has two costs, and it helps to plan both before year one ends.
- Keeping the program running
- Evidence has to keep being collected through the next period, or there is nothing for the next report to test. On our software that is $199 a month, cancel any time, which adds up to $2,388 over twelve months, or $2,189 a year, pay for eleven months, get twelve.
- The next examination
- Year two is normally a Type 2, because that is what buyers ask for once you have a Type 1. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, inside the app, and you see the quote before anything begins.
So year two starts with a choice: monthly at $199, or yearly at $2,189. Yearly costs less of the two if you know you are staying, since it is one month free. Audits unlock after four paid months on monthly, or right away on yearly, so the yearly plan also lets you request the Type 2 as soon as your window is done.
Compare that with a renewal that turns up as a bigger invoice with no warning. Knowing the mechanism in advance is what lets a small team plan for it. The full cost of SOC 2 lays out year one and year two side by side.
Bridge letters cover the months in between
A bridge letter, sometimes called a gap letter, fills the space between the end of your report period and today. You write it and your management signs it, in the company’s own name. The CPA firm does not. It never looked at those months, so it has nothing to report on.2
- State the dates. The last day of the examined period, and the date of the letter. Naming the gap plainly is half of what the letter is for.
- Say the controls kept running. The controls in the report have continued to operate, and no material change has affected them.
- Say what it is not. No independent examination covered the gap. This is management’s statement, not the auditor’s.
Three months of gap is routine, and a reviewer will read the letter without much fuss. Six is about the limit. Beyond that, reviewers stop seeing cover and start seeing an excuse, and a bridge letter never replaces a report.
Sometimes the standard sentence is not true, and it is better to see that before you sign it than after. You changed cloud providers. You were bought. The person who ran access reviews left. Signing “no material changes” anyway is a false written statement to a customer. Describe the change instead: what it was, when it happened, and which control now does the job. A disclosed change may cost you one more questionnaire. A hidden one can cost you the account when the next report shows it.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Run your periods back to back
Follow the twelve month rule through to its end and the calendar more or less sets itself. Your report goes stale about a year after its period closes. The next period has to close before that, so the next examination has to start months earlier. That is why SOC 2 becomes yearly. It is a rhythm set by buyers, not by the standard.2
It also explains why periods should touch. Picture a first Type 2 for January through March and a second for July through December. April to June is covered by nothing, and a reviewer reading both reports will find it. Back to back periods leave nothing to explain. How the observation period works covers why the first window cannot be rushed.
The email to send while the next report is underway
You will write this email several times a year, so settle its shape once. Four moves, in this order, and each one saves a round of questions.
- Put the dates in the email itself. One line: this report covers these dates, and the attached letter covers the months since.
- Attach the bridge letter up front. Sent early it looks organized. Sent three emails later, after the reviewer has already flagged the gap, it looks improvised.
- Name the next period and its expected report date. A buyer who knows the next report lands in April can approve you now on that condition.
- Offer interim material, and label it honestly. Policies, a control list and a recent access review are useful. They are not a report, and saying so makes the rest believable.
All of this assumes a next report exists. If a deal is already stuck, what to do when a buyer wants a SOC 2 you do not have is the faster read, and the SOC 2 timeline gives you dates you can put in the email today.
Plan the renewal before you need it
If you have no report yet, start with where you stand. The free readiness assessment takes about 15 minutes and shows your score and your gaps, with nothing charged. Take the free assessment. If you already have a report and need year two covered, compare the monthly and yearly plans.
Questions
Is there an expiry date on a SOC 2 report?
When does a buyer treat a SOC 2 report as too old?
Who signs a bridge letter?
How many months can a bridge letter cover?
How often should a company renew its SOC 2?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.