On this page
A SOC 2 observation period is the span of time covered by a Type 2 examination. During that window, the CPA firm tests whether the controls in scope operated effectively, not merely whether they were suitably designed on one date. Three, six, and twelve months are common planning windows, but the engaged CPA firm must approve the period.
What the observation period proves

A Type 1 examination addresses controls as of a specified date. A Type 2 examination covers their operation throughout a stated period. That difference is the reason evidence from daily work matters: access changes, production deployments, incident handling, security reviews, and other activities may all become part of the auditorโs test population.
The AICPAโs authoritative SOC 2 reporting guide describes the framework in terms of control design and effectiveness. It does not publish a universal three-month minimum on that page. Audit firms commonly plan first Type 2 engagements around 3, 6, or 12 months, but their acceptance of a period depends on the controls, evidence available, intended report users, and professional judgment.
If you are still deciding between report types, start with our Type 1 versus Type 2 comparison. Our guide to what a SOC 2 Type 2 report contains explains the final deliverable.
How to choose a 3, 6, or 12-month period
Choose the window with the CPA firm before it begins. Window length alone says little about assurance. The period needs to give the auditor enough relevant evidence to test the controls in scope and produce a report your customers will accept.
| Common window | When it can fit | What to confirm before choosing it |
|---|---|---|
| 3 months | A first Type 2 report tied to a near-term procurement need | Whether important quarterly or less-frequent controls will operate during the window, and whether target customers accept the coverage |
| 6 months | A first audit that needs more operating history without waiting a full year | Whether the period includes each relevant control cadence and enough events for the planned testing approach |
| 12 months | A recurring program or buyers that expect a longer coverage period | Whether the team can sustain evidence quality for a full year and how the next annual cycle will overlap |
These are common planning windows, not AICPA-prescribed tiers. A CPA firm might accept another duration when it fits the engagement. It might also recommend changing the start date so that quarterly or annual activities fall inside the period. Confirm the exact dates, scope, and expected evidence with the firm that will sign the report.
Evidence to retain during the period
Auditors generally test a selection from the full population rather than asking you to submit every event. Your job is to preserve complete populations and reliable records so the auditor can choose samples and trace what happened. The sample size and method are the auditorโs decision.
| Control cadence | Evidence to retain | Practical check |
|---|---|---|
| Event-driven | New hires, terminations, access changes, incidents, production changes | Can you export a complete population for the whole period? |
| Daily or weekly | Monitoring alerts, backup results, vulnerability activity, operational reviews | Are timestamps, owners, outcomes, and follow-up actions retained? |
| Monthly or quarterly | Access reviews, vulnerability reviews, management reviews, vendor activities | Does the record show completion, reviewer approval, and remediation? |
| Annual | Risk assessment, training, policy review, tabletop exercise, where included in your controls | Did the activity occur inside the period, or has the auditor agreed how it will be tested? |
The examples are common, not a universal SOC 2 checklist. Your control descriptions and selected Trust Services Criteria determine what is relevant. Follow the cadence written in your own policies and controls. If a policy says a review is monthly, completing it every six weeks creates a mismatch even when the underlying security work is sound.
For a working collection process, use the SOC 2 evidence collection guide.
What can go wrong mid-period
Missing evidence and missed controls are different problems. A team may complete a review but fail to retain approval records. In another case, it may not perform the review at all. Tell the auditor which situation occurred rather than recreating records after the fact.
Watch for these issues:
- The control changed. A new identity provider, ticketing system, or approval workflow can change the evidence source. Record the transition and preserve evidence from both systems.
- The population is incomplete. Screenshots may show individual items but cannot establish that the auditor received the full set from which to sample.
- A scheduled activity was missed. Escalate it, document the cause and remediation, and ask the auditor how it affects testing.
- The scope changed. A new product, cloud environment, subprocess, or subservice organization may affect the system description and control set.
- Owners changed. Reassign recurring tasks before an employee leaves so control operation does not quietly stop.
Do not assume that one exception automatically produces a qualified opinion, or that fixing an issue erases what happened. The CPA firm evaluates exceptions in context, including their nature, cause, frequency, and effect on the engagement.
Does a longer observation period cost more?
Sometimes, but duration alone is rarely the main price driver. The number and complexity of systems, Trust Services Criteria, locations, control activities, subservice organizations, and evidence populations usually shape fees more than adding calendar months to a stable scope.
Our current directory pricing context puts a specialist CPA firmโs Type 2 audit at $16,000โ$50,000, while a Big Four Type 2 engagement is typically $60,000โ$200,000. These are directional market ranges, not quotes. Organization group describes the firm; engagement scope drive the difference far more than whether the observation period is six or twelve months.
Ask each firm to state what its fee includes: readiness work, the examination itself, testing of additional criteria, travel, report revisions, and support for customer questions. Also ask whether extending or changing the period after fieldwork begins would trigger a change order.
Before the observation period begins
The cleanest time to solve an evidence problem is before the clock starts. Get written alignment with the CPA firm on:
- the exact start and end dates;
- the system and Trust Services Criteria in scope;
- the final control descriptions and their stated frequencies;
- the evidence source and owner for each control;
- how complete populations will be produced;
- any control that may not operate during the proposed window; and
- how changes, exceptions, and scope updates should be communicated.
Run one internal evidence review before day one. Pick several event-driven and scheduled controls, retrieve the records, and check whether an independent reviewer could understand who did what, when, with what result. Then keep that process running throughout the observation period. Consistent capture of ordinary operations produces the evidence for a Type II report throughout the period.