If you are starting from nothing and your buyer wants a Type 2, plan on somewhere between six months and a year from the day you start to the day you hand over a report. If they will accept a Type 1, you can often get there in two to four months. Those ranges are wide because the variable that dominates is not the audit — it is how much of your control environment already exists and runs on its own.
In a first SOC 2 audit, the examination itself is the shortest phase. Founders consistently misjudge this. They assume the auditor is the long pole, then discover that the auditor’s fieldwork takes a few weeks and the eight months before it were spent building the things the auditor tests.
Phase 1: Scoping and choosing your criteria
Typically one to three weeks.
Before anyone can plan, you need three answers from whoever asked you for the report: Type 1 or Type 2, which trust services criteria beyond Security, and the date they need it by. Security is the only required category. Availability, Confidentiality, Processing Integrity and Privacy are added when your commitments or your buyer’s expectations call for them, and each one adds criteria, controls and evidence.
You also decide what is in scope: which product, which environments, which supporting systems, which subservice organizations get carved out. This is where over-scoping quietly sets fire to your timeline. A first SOC 2 covering one production platform is a different project from one covering three acquired products on separate stacks.
Do this properly. Scope changes after fieldwork starts are expensive in both time and fees.
Phase 2: Readiness assessment
Typically two to six weeks.
A readiness assessment maps the applicable criteria against what you actually do, and produces a gap list with owners. Some firms deliver this in a couple of weeks; others take longer because they interview more people or walk through systems in more depth.
You can skip this if you have run a SOC 2 before, or if you have a security lead who has and can do the mapping internally. Most first-timers should not skip it, because the alternative is discovering gaps during fieldwork, when the fix is a finding rather than a to-do.
Note the independence point: if a firm performs your readiness work, that is consulting, not the examination. Firms handle this differently, and some will not do both for the same client. Ask early rather than assuming.
Phase 3: Remediation
Typically one to four months. This is the phase that moves.
This is where your timeline is really decided, and it is almost entirely in your hands. Remediation usually splits into three buckets.
Documentation. Information security policy, access control, change management, incident response, vendor management, business continuity, risk assessment. Writing these is fast. Getting them reviewed, approved and actually distributed takes longer than people plan for.
Tooling and configuration. MFA everywhere, centralized logging, endpoint management, vulnerability scanning, background checks, security awareness training. Each item is small. Twenty of them running through a stretched engineering team is a quarter.
Process. Quarterly access reviews, risk assessment, vendor reviews, incident response tabletop, backup restoration testing. These are the ones that need to have happened, not merely be planned, and they are the reason remediation and the observation window interact.
A team with cloud infrastructure, SSO already in place and a functioning ticketing workflow can be through remediation in six weeks. A team with shared admin accounts, direct-to-production deploys and no formal onboarding will take considerably longer, and should.
Phase 4: The observation window (Type 2 only)
Commonly three to twelve months; three to six is typical for a first report.
A Type 2 opines on whether controls operated effectively across a period, so there must be a period. The clock starts when your controls are genuinely live, not when you decided to do a SOC 2.
Shorter windows get you a report sooner. Longer windows produce a report buyers find more convincing, and they line you up for annual twelve-month periods sooner. Three months is common for a first report when a deal is waiting; six is common when it is not.
The important constraint: quarterly controls need a quarter to happen in. If your window is three months, exactly one access review falls inside it, and if that one review is late or unsigned, you have an exception with no second instance to soften it.
During the window your job is not to relax. It is to run the controls and let the evidence accumulate with dates and approvers attached.
Phase 5: Fieldwork
Typically two to six weeks.
The auditor requests evidence, samples populations, tests controls, and asks follow-up questions. You will get a request list, and the speed of this phase depends almost entirely on how fast your team responds to it.
Where it slows down: populations that cannot be produced completely (a full list of employees who left during the period, a full list of production changes), evidence that exists but lacks dates or approvals, and screenshots taken today for a control that was supposed to operate in month two.
Where it moves: teams that exported evidence continuously during the window rather than reconstructing it afterwards.
Expect at least one round of clarification. That is normal, not a warning sign.
Phase 6: Reporting
Typically two to four weeks after fieldwork closes.
The auditor drafts the report, including the opinion, your system description and, for a Type 2, the tests of controls and results. You review the description for accuracy, management signs the assertion, and the firm completes its internal quality review before issue. Firms differ in how long that internal review takes.
If exceptions were identified, this is when you write management responses. A report with a handful of well-explained exceptions and sensible responses is normal and readable. Trying to argue exceptions out of the report at this stage rarely works and costs weeks.
What actually compresses, and what does not
You can compress remediation by dedicating people to it, by narrowing scope, and by choosing only the criteria you need. You can compress fieldwork by having evidence ready before it starts.
You cannot compress the observation window. Time is the input. This is the single most common surprise for founders who assume paying more will buy a faster report — it will not, because a Type 2 covering three months requires three months to have passed.
You also cannot compress the requirement that controls be real. An auditor testing a quarterly access review will ask for evidence of the review, and if it was performed in a rush the week before fieldwork, that shows in the dates.
What to do next
Work backwards from the date your buyer needs the report. Subtract three to four weeks for reporting, a month for fieldwork, then your observation window. Whatever is left is your remediation budget — and if that number is negative, you have three options: ask the buyer whether a Type 1 plus a committed Type 2 date is acceptable, shorten the window, or narrow the scope.
Have that conversation with the buyer before you commit to a date internally. Assurion is a licensed CPA firm and performs SOC 2 examinations; if you want a sanity check on whether your target date is achievable, that is a short conversation worth having early.