SOC 2 report shelf life, and what year two costs

Nothing on the report expires, but buyers stop trusting it after about a year. That clock sets your renewal costs.

How long is a SOC 2 report valid? Technically, forever. It carries no expiry date and nobody can cancel it. What runs out is trust. A buyer will usually stop accepting a Type 2 about twelve months after the period it covers has ended, and that informal line is what drives a yearly renewal.

So the useful question is a cost one. What does it cost to keep a current report in front of buyers in year two, and year three?

The confusion tends to show up late, long after anyone has thought about the report. Your first report closes a deal. Eleven months later a new buyer asks for it and says it is too old. The document has not changed at all, but the reader’s patience has.

Two kinds of report, two kinds of age

SOC 2 does not certify you. A CPA firm examines the controls you put in scope and writes up what it found, with a date or a date range printed on the front.1 That printed window is the only thing a buyer uses to judge age. How it reads depends on the type.

Type 1
Looks at whether your controls were designed well on a single date. It says nothing about the weeks before or after, so it ages from that one day.
Type 2
Looks at whether the controls worked across a stated period, often three to twelve months. Age is counted from the last day of that period.

The facts inside stay true, because they describe a window that really happened and nothing later can undo that. A report covering last January through December still tells the truth about last year. It just says nothing about this spring, and a careful reviewer knows it. Type 1 versus Type 2 explains which one your buyer is likely to ask for.

The line buyers draw at twelve months

The rule is not in the standard. Buyers apply it anyway. If your Type 2 period ended more than a year ago, the review stops. Some vendor risk programs put it in policy. Others just send the report back.

The strict version asks for two things at once: a report whose period ended within the last year, and written cover for every month between that end date and the day they are reading it. That second request catches people out. Your period ended in March, it is now August, and from the buyer’s chair five months of your company are blank.

The buyer asks forThis worksThis gets sent back
Your SOC 2Your latest report, with its dates written in the emailA link to a trust page with no report behind it
A recent Type 2A report whose period ended inside the past yearA Type 1, whatever its date
Proof of coverage todayThat report plus a signed letter for the months sinceA silent gap they find on their own

What year two costs

This is the part a first year plan leaves out, because the first quote only ever talks about getting the first report. The twelve month line means a SOC 2 is not a one time purchase. It is an ongoing cost of staying current, whatever you call it. Year two has two costs, and it helps to plan both before year one ends.

Keeping the program running
Evidence has to keep being collected through the next period, or there is nothing for the next report to test. On our software that is $199 a month, cancel any time, which adds up to $2,388 over twelve months, or $2,189 a year, pay for eleven months, get twelve.
The next examination
Year two is normally a Type 2, because that is what buyers ask for once you have a Type 1. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, inside the app, and you see the quote before anything begins.

So year two starts with a choice: monthly at $199, or yearly at $2,189. Yearly costs less of the two if you know you are staying, since it is one month free. Audits unlock after four paid months on monthly, or right away on yearly, so the yearly plan also lets you request the Type 2 as soon as your window is done.

Compare that with a renewal that turns up as a bigger invoice with no warning. Knowing the mechanism in advance is what lets a small team plan for it. The full cost of SOC 2 lays out year one and year two side by side.

Bridge letters cover the months in between

A bridge letter, sometimes called a gap letter, fills the space between the end of your report period and today. You write it and your management signs it, in the company’s own name. The CPA firm does not. It never looked at those months, so it has nothing to report on.2

  1. State the dates. The last day of the examined period, and the date of the letter. Naming the gap plainly is half of what the letter is for.
  2. Say the controls kept running. The controls in the report have continued to operate, and no material change has affected them.
  3. Say what it is not. No independent examination covered the gap. This is management’s statement, not the auditor’s.

Three months of gap is routine, and a reviewer will read the letter without much fuss. Six is about the limit. Beyond that, reviewers stop seeing cover and start seeing an excuse, and a bridge letter never replaces a report.

If something material did change

Sometimes the standard sentence is not true, and it is better to see that before you sign it than after. You changed cloud providers. You were bought. The person who ran access reviews left. Signing “no material changes” anyway is a false written statement to a customer. Describe the change instead: what it was, when it happened, and which control now does the job. A disclosed change may cost you one more questionnaire. A hidden one can cost you the account when the next report shows it.

Who stands behind the report

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Run your periods back to back

Follow the twelve month rule through to its end and the calendar more or less sets itself. Your report goes stale about a year after its period closes. The next period has to close before that, so the next examination has to start months earlier. That is why SOC 2 becomes yearly. It is a rhythm set by buyers, not by the standard.2

It also explains why periods should touch. Picture a first Type 2 for January through March and a second for July through December. April to June is covered by nothing, and a reviewer reading both reports will find it. Back to back periods leave nothing to explain. How the observation period works covers why the first window cannot be rushed.

You can bridge a gap at the end. A gap in the middle stays forever.

The email to send while the next report is underway

You will write this email several times a year, so settle its shape once. Four moves, in this order, and each one saves a round of questions.

  1. Put the dates in the email itself. One line: this report covers these dates, and the attached letter covers the months since.
  2. Attach the bridge letter up front. Sent early it looks organized. Sent three emails later, after the reviewer has already flagged the gap, it looks improvised.
  3. Name the next period and its expected report date. A buyer who knows the next report lands in April can approve you now on that condition.
  4. Offer interim material, and label it honestly. Policies, a control list and a recent access review are useful. They are not a report, and saying so makes the rest believable.

All of this assumes a next report exists. If a deal is already stuck, what to do when a buyer wants a SOC 2 you do not have is the faster read, and the SOC 2 timeline gives you dates you can put in the email today.

Plan the renewal before you need it

If you have no report yet, start with where you stand. The free readiness assessment takes about 15 minutes and shows your score and your gaps, with nothing charged. Take the free assessment. If you already have a report and need year two covered, compare the monthly and yearly plans.

Questions

Is there an expiry date on a SOC 2 report?
No. It is a report, not a license, and no one can revoke it. A Type 1 speaks to one date and a Type 2 speaks to one period, and both stay accurate about that window forever. What fades is how willing a buyer is to rely on an old window.
When does a buyer treat a SOC 2 report as too old?
A common procurement rule is twelve months after the end of the period the Type 2 covers. Stricter reviewers also want the months since that end date covered in writing, which is the job of a bridge letter.
Who signs a bridge letter?
Your management does. The letter says the controls kept operating and nothing material changed since the period ended. The CPA firm does not sign it, because it did not examine the gap months.
How many months can a bridge letter cover?
Three months is ordinary. Around six is as far as reviewers will stretch. Past that the letter stops being treated as coverage, and no bridge letter ever stands in for a report.
How often should a company renew its SOC 2?
Once a year, because of the twelve month convention buyers apply. Plan each Type 2 period to begin the day after the last one ended, so no month of your history is left without a report.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.