SOC 2

SOC 2 observation period: 3, 6 or 12 months?

28 September 2026 · 9 min read · CertAssist

How long the SOC 2 Type 2 observation period should run, what each window costs, and how to work backwards from the date a customer wants the report.

The SOC 2 observation period is the window of time a SOC 2 Type 2 audit examines, and it normally runs from 3 to 12 months. Three months is the practical floor for a first report, 6 months is the most common first-year choice, and 12 months becomes standard once a company is on an annual cycle. The AICPA sets no minimum. The SOC 2 observation period you choose decides what your auditor can test, what a prospect will accept, and how many audit fees you pay in a year.

How long is the SOC 2 observation period?

The SOC 2 observation period normally runs 3 to 12 months and is agreed between the organisation being audited and the CPA firm performing the examination. A SOC 2 Type 2 report states the exact period on its cover, for example 1 January 2026 to 30 June 2026, and the auditor's opinion covers only that period. A SOC 2 Type 1 report has no observation period at all, because a Type 1 assesses control design at a single point in time. The observation period is a SOC 2 Type 2 concept only.

Is there a minimum SOC 2 observation period?

The AICPA does not set a minimum SOC 2 observation period. Its attestation guidance requires the service auditor to obtain sufficient appropriate evidence that the controls operated effectively throughout the stated period, and leaves the length to professional judgement. In practice three months is the shortest window CPA firms normally accept, because several routine controls only produce evidence on a monthly or quarterly cadence. A quarterly access review, a vendor review, a backup restore test and an incident response exercise each need one completed cycle inside the window, or the auditor has nothing to sample.

A window shorter than three months is therefore usually refused by the auditor rather than by the standard. The AICPA's own description of the SOC suite of services is on the AICPA SOC services page.

Should your SOC 2 observation period be 3, 6 or 12 months?

Choose the SOC 2 observation period from the buyer, not the calendar. If one named customer is blocking a contract and will accept a short report, a 3 month window gets you moving. If your pipeline is mid-market and nobody has stated a requirement, 6 months is the safe default. If you are selling into enterprise procurement, assume 12 months is expected.

Observation periodWhat the auditor can testHow buyers usually treat itThe trade-off
3 monthsOne cycle of monthly and quarterly controlsAccepted as a first report, usually on the understanding that a longer one followsFastest route to a report, but you will probably pay for a second audit inside the year
6 monthsTwo quarterly cycles and a fuller evidence trailAccepted by most mid-market buyers without commentThe usual first-year compromise between speed and credibility
12 monthsEvery annual control, including the risk assessment, policy review and management reviewThe expectation in enterprise procurement and at renewalMost evidence to maintain, and the longest wait for a first report

None of these windows is more compliant than the others. A SOC 2 Type 2 report over 3 months and one over 12 months carry the same kind of opinion. The difference is how much operating history that opinion covers.

Comparison chart of 3 month, 6 month and 12 month SOC 2 Type 2 observation periods showing that a 3 month window captures one quarterly control cycle and reaches a report in about 5 months, a 6 month window captures two quarterly cycles and reaches a report in about 8 months, and a 12 month window captures every annual control and reaches a report in about 14 months

How does the SOC 2 observation period affect cost?

The SOC 2 observation period affects cost less through the audit fee than through how many audits you buy. A CPA firm prices a SOC 2 Type 2 mainly on scope, the Trust Services Criteria in the examination and system complexity, not on months, so a 12 month window does not cost four times a 3 month one. The expensive pattern is a 3 month window followed immediately by a 12 month window, which means two full Type 2 audit fees inside about 15 months.

Cost lineTypical range, USDHow the observation period changes it
Independent SOC 2 Type 2 auditUS$10,000 to US$30,000+Driven by scope and criteria, not by months. A second short window means a second full fee.
Penetration test, where requiredUS$4,000 to US$12,000Normally once per report cycle, so a 3 month cycle repeats it sooner.
Compliance platformUS$225 per month with CertAssistScales directly with the number of months you run.
Consultant, optionalUS$10,000 to US$40,000+A longer window means a longer engagement if you retain one throughout.
Your team's timeCharged in hours, not invoicedThe largest hidden line, and it runs for the whole window.

Ranges above are commonly reported figures for small US companies and vary with scope and firm. The CertAssist figure was verified against the live pricing page in September 2026: US$225 per month on the current launch offer, normally US$375 per month, or US$2,475 per year. For the full picture, see the SOC 2 cost breakdown.

What happens during the SOC 2 observation period?

During the SOC 2 observation period your controls simply have to run, and the evidence has to accumulate as they run. The auditor is not present for those months. At the end of the period the CPA firm samples from the window and tests whether each control operated as described, so what matters is that the record exists and is dated inside the period. Typical evidence includes:

The part teams underestimate is that a SOC 2 observation period cannot be backfilled. If a quarterly access review was missed in month two, producing it in month seven does not fix the gap, because the evidence is dated outside the cycle it was meant to cover. The auditor records an exception instead, and exceptions are what prospects read closely. Knowing what auditors look for in evidence before the window opens is cheaper than finding out after it closes.

How do you work backwards from a customer deadline?

Work backwards from the date the customer needs the SOC 2 report, because the observation period is one of four blocks of time and the other three add up to roughly two months. The last date you can start a 6 month window is about eight months before the deadline.

StageTypical durationWhat decides it
Readiness and remediation4 to 12 weeksHow many controls already run, and how much policy writing is left
Observation period3, 6 or 12 monthsYour choice, constrained by what the buyer accepts
Fieldwork and evidence review3 to 6 weeksAuditor availability and how tidy your evidence is
Report drafting and issue2 to 4 weeksThe CPA firm's internal review and your management response

From a standing start that puts a 3 month SOC 2 observation period at roughly 5 to 8 months to a report in hand, a 6 month period at 8 to 11 months, and a 12 month period at 14 to 17 months. Book the auditor early: the fieldwork slot, not the observation period, is what slips.

Timeline diagram of a SOC 2 Type 2 engagement from a standing start, showing 4 to 12 weeks of readiness and remediation, then a 3, 6 or 12 month observation period, then 3 to 6 weeks of auditor fieldwork and 2 to 4 weeks of report drafting, giving a report in hand at about 5 to 8 months for a 3 month window, 8 to 11 months for a 6 month window and 14 to 17 months for a 12 month window

Does a SOC 2 report expire once the observation period ends?

A SOC 2 report does not formally expire, because it is an auditor's opinion about a period that has already happened rather than a certificate with a validity date. A SOC 2 report goes stale instead. Most customers treat a report as current for about 12 months after the observation period end date.

The months between the period end and today are covered by a SOC 2 bridge letter, a short statement from management confirming nothing material changed since the period ended. A bridge letter is not an audit and does not extend the observation period, so most buyers accept one covering a few months and push back on one covering nine. Scheduling each period to start where the last one ended keeps coverage continuous and bridge letters short.

When is a short SOC 2 observation period the wrong choice?

A short SOC 2 observation period is the wrong choice when your controls are not actually running yet. A 3 month window on controls that started last week produces a report full of exceptions, which is worse in a security review than no report at all, because the prospect now has a document to quote back at you. Spend six more weeks on readiness and open the window once the controls hold.

It is also wrong when the buyer has already told you what they need. If enterprise procurement requires a 12 month SOC 2 Type 2, a 3 month report will not clear the review. Ask the customer's security team what period they accept before you set the dates.

How does CertAssist help during a SOC 2 observation period?

CertAssist lays out the SOC 2 Trust Services Criteria control by control, gives you editable policy and evidence templates, and holds the dated evidence for the whole observation period in one place with an activity history on every change. When the window closes, your auditor gets read-only access and reviews the evidence where it sits. CertAssist costs US$225 per month on the current launch offer, or US$2,475 per year.

CertAssist has no integrations by design. It does not connect to your cloud, your identity provider or your code, so there is no access to grant and nothing for an attacker to reach through, and it also means CertAssist does not collect evidence automatically. Your team gathers it and files it. If you want continuous automated monitoring across a 12 month window, that is a real benefit of the integration-heavy platforms and you should expect to pay for it. CertAssist suits organisations of roughly 5 to 200 people certifying for the first time.

Frequently asked questions about the SOC 2 observation period

How long does SOC 2 Type 2 last?
A SOC 2 Type 2 report covers the observation period printed on its cover, normally 3 to 12 months, and it does not expire on a set date. Most buyers treat the report as current for about 12 months after the period end date, and ask for a bridge letter to cover the months since.

Does SOC 2 expire?
SOC 2 has no formal expiry date, because a SOC 2 report is an auditor's opinion on a past period rather than a certificate with a validity window. In practice a SOC 2 report is treated as stale once the observation period ended more than 12 months ago, and most customers will ask for a newer report at renewal.

How often are SOC 2 audits done?
Most organisations run a SOC 2 Type 2 audit once a year, with a 12 month observation period starting where the previous one ended so there is no gap in coverage. Companies getting a first report sometimes run two audits close together, a short window to unblock a deal and then a 12 month window.

Are SOC 2 reports annual?
SOC 2 reports are usually annual but nothing in the AICPA guidance requires it. The annual pattern exists because customers ask for a report no more than 12 months old, so an annual SOC 2 Type 2 keeps coverage continuous. Some companies issue two reports a year with 6 month windows instead.

How long does a SOC 2 Type 2 audit take?
Fieldwork for a SOC 2 Type 2 audit normally takes 3 to 6 weeks after the observation period ends, plus 2 to 4 weeks for the report to be drafted and issued. That sits on top of the observation period, so a 3 month window typically produces a report about 5 months after you start.

Run your observation period without an enterprise price tag

CertAssist lays out every SOC 2 control, gives you editable policy and evidence templates, and lets your auditor review the evidence in one place, for a flat US$225 a month.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.