The honest answer to “how long does SOC 2 take” is that the audit is the short part. Fieldwork for a Type I can wrap in a couple of weeks. What stretches the calendar is everything that happens before your auditor opens a laptop, and almost none of it is visible when you first start planning.
Here is the timeline broken into phases, with the places teams consistently lose weeks.
Type I Timeline: Two to Four Months
Weeks 1–2: Scoping. Decide which Trust Services Criteria you are including. Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are elective. Adding categories you do not need is the single easiest way to inflate the entire project. Also define your system boundary — which product, which infrastructure, which subsidiaries.
Weeks 2–4: Readiness assessment. A gap analysis against the criteria in scope. A focused assessment completes in five to ten business days. What you get is a list of gaps ranked by how badly your auditor will react to each.
Weeks 4–10: Remediation. The variable phase, and the one that decides your actual date. Writing missing policies is fast. Implementing MFA everywhere, standing up centralised logging, or building an access review process that produces records is not.
Weeks 8–12: Evidence collection and pentest. Runs in parallel with late remediation. Your penetration test belongs here — late enough that fixes are in place, early enough that findings can be remediated and retested before fieldwork.
Weeks 10–14: Audit fieldwork and report. The CPA firm reviews evidence, interviews your team, and issues the report. Two to six weeks depending on firm and scope.
Type II Timeline: Six to Twelve Months
Type II follows the same preparation path, then adds the piece you cannot compress: the observation period. Your auditor is evaluating whether controls operated effectively across a window of time, which means time has to actually pass.
Observation periods commonly run three to twelve months. Three months is the usual choice for a first Type II, since it gets a report into buyers' hands fastest. Twelve months is the mature steady state most companies settle into for annual renewals.
The critical detail: your observation window starts when your controls are actually operating, not when you decide to pursue SOC 2. If you switch on quarterly access reviews in March, a three-month window cannot begin in January. Teams routinely lose a full quarter to this misunderstanding.
Four Things That Quietly Add Months
Remediation discovered late. If your first real gap analysis happens after you have signed with an auditor, you find out what is broken with the clock already running. This is the strongest argument for running readiness early.
Auditor availability. CPA firms book out, and Q4 and Q1 are the busy seasons. Engaging a firm two to three months before you want fieldwork is normal, not early.
Scope changes mid-project. A prospect asks for Availability, so you add it in month three. Every new category means new controls, new evidence, and often a reset observation window for the affected controls.
Pentest scheduling and retest. Booked too late, a critical finding lands with no time to fix and retest before fieldwork. Build in four to six weeks between test and audit.
Can You Compress It?
Somewhat, and only in specific places. Readiness and remediation can be run in parallel rather than sequentially if you have the people. Pentest lead time is compressible — ours start within days rather than weeks. Auditor scheduling can be locked in early.
What cannot be compressed is the Type II observation period. No amount of budget shortens it. Any provider suggesting otherwise is describing a Type I.
If you need a report in front of a buyer quickly, the realistic move is a Type I now with a Type II observation window opening immediately after — not a compressed Type II.
Sequencing Work in Parallel
The default assumption is that these phases run one after another. Several do not have to.
Policy writing can run alongside technical remediation, because they involve different people. Evidence collection can begin the moment a control is operating rather than waiting until remediation is fully complete. Auditor selection and contracting can happen during remediation instead of after it — and should, given lead times.
What must stay sequential: you cannot test controls that do not exist yet, you cannot start a Type II observation window before controls operate, and you cannot hand an auditor evidence for a period that has not elapsed. Everything else is a scheduling choice.
Teams that treat SOC 2 as a strictly linear project routinely add two to three months they did not need to.
What the Auditor's Calendar Does to Yours
CPA firms are seasonal. Calendar year-end drives a crush of work through Q4 and Q1, and firms book fieldwork months ahead. If your target date sits in that window, engage early — two to three months before you want fieldwork is normal, not cautious.
There is a second scheduling dependency people miss: report issuance is not the same as fieldwork completion. After the auditor finishes testing, there is review, quality control, and drafting. Two to four weeks between the end of fieldwork and a report in your hands is typical. If a customer needs the report by a date, that date is not your fieldwork date.
A Worked Example
A prospect needs a SOC 2 report in seven months. The buyer confirms Type II is required.
Working backwards: report issuance in month seven means fieldwork completing around month six. Fieldwork requires a completed three-month observation window, so the window must close by month six — meaning it opens at month three. Controls must therefore be fully operating by month three, which leaves roughly ten weeks for readiness and remediation from a standing start.
That is tight but achievable for an organisation with reasonable existing hygiene. For one starting from nothing, it is not, and the honest answer to the prospect is a Type I now with Type II to follow — which is a much better conversation to have in month one than in month five.
Renewal Timelines Are Different
Your second SOC 2 is a substantially smaller project. Controls exist, evidence collection is routine, and your auditor knows your environment. Most organisations move to a rolling twelve-month observation period with fieldwork immediately after it closes.
The thing to watch on renewal is gaps between report periods. If your first Type II covered January to March and your second covers the following January to December, there is a nine-month hole. Sophisticated buyers notice, and some require continuous coverage. Plan the second window to begin when the first ends.
Plan Against a Real Date
Start with your deadline and work backwards. If a prospect needs a report in six months, a Type I is comfortable and a first Type II is tight but possible with a three-month window. Our SOC 2 readiness assessment completes in five to ten business days and tells you exactly which of those is realistic for your environment.
For the budget side of the same plan, see our SOC 2 compliance cost guide. If you are still choosing between report types, start with Type I vs. Type II.