Skip to main contentChat with us

Learn · SOC Reports

How Long Is a SOC 2
Report Valid?

A SOC 2 report does not expire. There is no AICPA rule that retires it after a set number of months, and there is no certificate with an expiry date on it. What ends is your customers' willingness to accept it — and that is a commercial threshold, not an accounting one.

The distinction that matters: the observation period is what the CPA firm tested. Commercial usability is how long buyers keep accepting the result. They are different lengths, and confusing them is how teams get caught mid-sales-cycle without current assurance.

0AICPA-defined expiry dates
~12 motypical commercial shelf life
250+SOC 2 engagements supported by TCSA

Plain-English explainer · AT-C 205 examination · Last reviewed August 2026

A SOC 2 Type 2 report is a historical report covering one stated period — for example, 1 May 2026 to 31 July 2026. It says what the auditor tested and what they found during that window, and nothing about any date after it. That is why the question “when does it expire?” has no technical answer. The AICPA sets no expiry, and a SOC 2 is an attestation performed under AT-C 205, not a certification with a validity term. Anyone who tells you a SOC 2 “certificate” is “valid for one year” is describing a document that does not exist. What does exist is a well-established market convention about staleness — and that convention is what your sales cycle actually runs into.

Three dates, not one

What people mean when they say “valid”

Almost every argument about SOC 2 validity is really a collision between three different dates printed in or around the same report.

Observation period

The window the CPA firm actually tested — say 1 May to 31 July 2026. This is the only period the opinion covers. A Type 1 has no observation period at all; it is a point-in-time view of control design.

Report date

The date the service auditor signed the opinion, usually a few weeks after the period closed. Useful for knowing how promptly the work was completed; it does not extend the coverage.

Commercial usability

How long your customers keep accepting the report before asking for something newer. Set by their vendor-risk policy, not by the AICPA, and the only one of the three that behaves like an expiry date.

The freshness ladder

How buyers actually age a report

Measured from the end of the observation period — not from the report date, and not from when you sent it. This is market practice observed across enterprise vendor-risk reviews, not an AICPA requirement; individual customers set their own thresholds and some are stricter.

0–3 months

Accepted without comment

The report is current by any reasonable standard. Procurement and security reviewers take it at face value and move to the substance — the opinion, the exceptions, and the CUECs assigned to them.

3–6 months

Accepted, with a question

Still normal. Stricter reviewers begin asking whether the next examination is underway and when the period closes. Having a scheduled next period is usually the whole answer.

6–12 months

Bridge letter territory

Enterprise vendor-risk teams commonly ask for a bridge letter confirming nothing material has changed since the period ended. Some will ask for interim evidence on specific controls.

12+ months

Treated as lapsed

Most enterprise programmes operate on an annual refresh cycle. Past twelve months from the period end, expect the report to be treated as out of date regardless of what it says, and expect the request to become “send us the current one”.

The short-period trap

A 3-month report ages faster

Many organisations run a short first Type 2 — often three months — to get a report into sales conversations quickly. That is a reasonable trade, and the report is entirely legitimate. But the freshness ladder above is not the whole story for a short window, because a reader is weighing two things at once: how long ago the testing stopped, and how much testing there was.

“You have given us three months of tested operating effectiveness, and that tested period ended eight months ago.”

— the objection a short first Type 2 eventually meets

A twelve-month report read eight months later still shows a full year of operating evidence. A three-month report read at the same remove shows a quarter of testing followed by two-thirds of a year with no coverage at all. Both are “eight months old”; they are not equally persuasive. This is why we advise clients not to describe a three-month Type 2 to customers as simply “valid for twelve months” — it invites a challenge the report cannot answer. Describe what it is: a completed examination of a stated period, with the next period already scheduled.

Sequencing

Closing the gap permanently

The durable answer to “how long is it valid” is to stop having a gap. Consecutive observation periods should abut: the next one begins the day after the last one ends, so every calendar month is eventually covered by some report.

Report 1

1 May – 31 July 2026

Short first Type 2 — gets assurance into the sales cycle quickly.

Report 2

1 Aug 2026 – 31 July 2027

Twelve-month period starting the day after Report 1 closed. No uncovered month.

Report 3

1 Aug 2027 – 31 July 2028

Annual cadence from here. Each report lands before the previous one goes stale.

A six-month second period is also a common choice where the control set is still settling — it reaches a full annual rhythm one cycle later but keeps the evidence burden lighter. What matters is that the periods touch. See choosing your observation period for how to pick the length.

Frequently Asked Questions

Does a SOC 2 report expire?

Not in any formal sense. The AICPA sets no expiry date for a SOC 2 report, and there is no certificate that lapses. The report covers a stated historical period and remains a true record of that period indefinitely. What changes is commercial acceptance: most enterprise vendor-risk programmes want assurance no more than about twelve months old, measured from the end of the observation period.

Is a SOC 2 report valid for 12 months?

Twelve months is a market convention, not a rule, and it describes how long buyers typically keep accepting a report rather than any property of the report itself. It is a reasonable planning assumption for an annual cadence. It is a poor thing to assert to a customer as though it were a standard — particularly if your observation period was short, because the reader is also weighing how much testing sits behind the report.

My observation period was only 3 months. How long is my report good for?

The same freshness ladder applies — comfortable to roughly six months past the period end, bridge-letter territory to twelve — but expect more scrutiny sooner. A reader eight months out is looking at three months of tested evidence and eight months without. The right move is not to argue for a longer shelf life; it is to have the next observation period already running, starting the day after the first one closed, so you can answer "what about since then?" with a date rather than an assurance.

What is the difference between the observation period and the report validity?

The observation period is the window the CPA firm tested and the only period the opinion covers — for example 1 May to 31 July 2026. Validity is not a defined term at all; it is shorthand for how long your customers keep accepting the report. The observation period is fixed and printed in the report. Commercial acceptance is set by each customer’s vendor-risk policy and typically runs about a year from the period end.

Can a bridge letter extend how long my SOC 2 report is valid?

It helps across a normal gap and does not extend validity indefinitely. A bridge letter is a statement from your own management that nothing material has changed since the period ended — it carries no audit assurance, because the CPA firm performs no procedures on the gap period. It works well for a quarter or so. If it would need to cover more than about three months, or the underlying report is over a year old, customers will generally want the next report instead.

How soon should we start the next SOC 2 audit?

Plan for the next observation period to begin the day after the current one ends, so consecutive reports abut and no month is left uncovered. Practically that means the readiness and evidence work runs continuously rather than restarting each year. Where a client has just completed a short first Type 2, we normally recommend moving straight into a longer second period rather than repeating a short window.

Does a SOC 2 Type 1 report have the same shelf life?

It has less. A Type 1 reports on the design of controls at a single point in time, with no operating-effectiveness testing behind it, so it goes stale faster in buyers’ eyes and many enterprise customers will not accept one as the final answer at all. Treat a Type 1 as a milestone on the way to a Type 2 rather than as a report with a shelf life to manage.

Related reading: SOC 2 bridge letters, choosing your observation period, Type 1 vs Type 2, how to read a SOC 2 report, opinions and exceptions, and the SOC 2 hub.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: August 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations