SOC 2 Type 1 readiness for startups
SOC 2 Type 1 looks at your security controls at a specific date. Controls are the checks and procedures you use to protect your service, such as reviewing who has access. First, confirm that your customer accepts Type 1. Then prepare the systems and records an independent accounting firm will review.
New to compliance? Start with the shared foundations, then return here for the SOC 2 Type 1 path.
By Sythe Labs Team · Sources reviewed September 14, 2026
Use this guide to plan the work. Confirm which requirements apply and what the review needs to cover with your auditor or adviser. AICPA: SOC 2 report types (July 2022, PDF).
- Start here if
- Your customer has confirmed that a report covering a specific date will meet their request.
- What to have ready
- Bring the customer's request, a list of the systems running your service, and any security policies you already use.
If your customer needs evidence of checks performed over time, read the SOC 2 Type 2 pathway.
Read the steps in order, or jump to the one you need. The highlight shows your selected step, not completed work.
1. Confirm the request
Ask your customer which service the report must cover and whether Type 1 is acceptable. Agree with the independent accounting firm on what it will examine and the date the report will cover.
Record to keep: The customer's acceptance and a written description of what the audit covers.
2. Put the checks in place
Compare what your team does today with the audit requirements. Give each missing piece an owner, make the changes, and check that they work. Your written policies should match what people actually do.
Record to keep: Who owns each check, what changed, and how you verified the fix.
3. Review the package
Check that your written description matches the live service. Organize the records so the auditor can see what happened, when, and who approved it. Explain any departures from the normal process.
Record to keep: An accurate service description and a list of supporting records.
4. Complete independent review
Answer the CPA firm's evidence questions and preserve the issued report. Track changes afterward; the report's date does not move when your service changes.
Record to keep: Issued Type 1 report and a subsequent change record.
A bank asks for a report before the pilot
A financial software startup has a working product, but the bank's security reviewer has asked for SOC 2. Before booking a date, the founder asks whether Type 1 is acceptable and which service the bank expects the report to cover. The engineering lead then checks that the audit's written scope includes the live systems that run that service.
During preparation, the team finds that former contractors still have production access. It removes that access, verifies the result, and records who will review access afterward. The evidence package explains the change and its date so the CPA firm can examine the controls in place.
Check your preparation
Can you show who owns each check, how it works, and the records supporting it at the agreed date?
This helps you find unfinished work. It is not an audit result.
Questions for your team
- Has the customer explicitly accepted Type 1 for this request?
- Does the scope include the production service the customer will use?
- What unfinished work could delay the audit?
What is your next SOC 2 Type 1 task?
Choose one task from the guide, assign someone to resolve it, and agree on what they will bring back. Download your notes before leaving this page; they are not saved between visits.
________________________________
________________________________
________________________________
________________________________
Supporting articles, sources, and templates
When you have worked through this route, return to your startup compliance plan to assign the remaining work and ongoing reviews.