Learn · SOC Reports
How Long Is a SOC 2
Report Valid?
A SOC 2 report does not expire. There is no AICPA rule that retires it after a set number of months, and there is no certificate with an expiry date on it. What ends is your customers' willingness to accept it — and that is a commercial threshold, not an accounting one.
The distinction that matters: the observation period is what the CPA firm tested. Commercial usability is how long buyers keep accepting the result. They are different lengths, and confusing them is how teams get caught mid-sales-cycle without current assurance.
Plain-English explainer · AT-C 205 examination · Last reviewed August 2026
A SOC 2 Type 2 report is a historical report covering one stated period — for example, 1 May 2026 to 31 July 2026. It says what the auditor tested and what they found during that window, and nothing about any date after it. That is why the question “when does it expire?” has no technical answer. The AICPA sets no expiry, and a SOC 2 is an attestation performed under AT-C 205, not a certification with a validity term. Anyone who tells you a SOC 2 “certificate” is “valid for one year” is describing a document that does not exist. What does exist is a well-established market convention about staleness — and that convention is what your sales cycle actually runs into.
Three dates, not one
What people mean when they say “valid”
Almost every argument about SOC 2 validity is really a collision between three different dates printed in or around the same report.
Observation period
The window the CPA firm actually tested — say 1 May to 31 July 2026. This is the only period the opinion covers. A Type 1 has no observation period at all; it is a point-in-time view of control design.
Report date
The date the service auditor signed the opinion, usually a few weeks after the period closed. Useful for knowing how promptly the work was completed; it does not extend the coverage.
Commercial usability
How long your customers keep accepting the report before asking for something newer. Set by their vendor-risk policy, not by the AICPA, and the only one of the three that behaves like an expiry date.
The freshness ladder
How buyers actually age a report
Measured from the end of the observation period — not from the report date, and not from when you sent it. This is market practice observed across enterprise vendor-risk reviews, not an AICPA requirement; individual customers set their own thresholds and some are stricter.
0–3 months
Accepted without comment
The report is current by any reasonable standard. Procurement and security reviewers take it at face value and move to the substance — the opinion, the exceptions, and the CUECs assigned to them.
3–6 months
Accepted, with a question
Still normal. Stricter reviewers begin asking whether the next examination is underway and when the period closes. Having a scheduled next period is usually the whole answer.
6–12 months
Bridge letter territory
Enterprise vendor-risk teams commonly ask for a bridge letter confirming nothing material has changed since the period ended. Some will ask for interim evidence on specific controls.
12+ months
Treated as lapsed
Most enterprise programmes operate on an annual refresh cycle. Past twelve months from the period end, expect the report to be treated as out of date regardless of what it says, and expect the request to become “send us the current one”.
The short-period trap
A 3-month report ages faster
Many organisations run a short first Type 2 — often three months — to get a report into sales conversations quickly. That is a reasonable trade, and the report is entirely legitimate. But the freshness ladder above is not the whole story for a short window, because a reader is weighing two things at once: how long ago the testing stopped, and how much testing there was.
“You have given us three months of tested operating effectiveness, and that tested period ended eight months ago.”
— the objection a short first Type 2 eventually meets
A twelve-month report read eight months later still shows a full year of operating evidence. A three-month report read at the same remove shows a quarter of testing followed by two-thirds of a year with no coverage at all. Both are “eight months old”; they are not equally persuasive. This is why we advise clients not to describe a three-month Type 2 to customers as simply “valid for twelve months” — it invites a challenge the report cannot answer. Describe what it is: a completed examination of a stated period, with the next period already scheduled.
Sequencing
Closing the gap permanently
The durable answer to “how long is it valid” is to stop having a gap. Consecutive observation periods should abut: the next one begins the day after the last one ends, so every calendar month is eventually covered by some report.
Report 1
1 May – 31 July 2026
Short first Type 2 — gets assurance into the sales cycle quickly.
Report 2
1 Aug 2026 – 31 July 2027
Twelve-month period starting the day after Report 1 closed. No uncovered month.
Report 3
1 Aug 2027 – 31 July 2028
Annual cadence from here. Each report lands before the previous one goes stale.
A six-month second period is also a common choice where the control set is still settling — it reaches a full annual rhythm one cycle later but keeps the evidence burden lighter. What matters is that the periods touch. See choosing your observation period for how to pick the length.
Frequently Asked Questions
Does a SOC 2 report expire?
Not in any formal sense. The AICPA sets no expiry date for a SOC 2 report, and there is no certificate that lapses. The report covers a stated historical period and remains a true record of that period indefinitely. What changes is commercial acceptance: most enterprise vendor-risk programmes want assurance no more than about twelve months old, measured from the end of the observation period.
Is a SOC 2 report valid for 12 months?
Twelve months is a market convention, not a rule, and it describes how long buyers typically keep accepting a report rather than any property of the report itself. It is a reasonable planning assumption for an annual cadence. It is a poor thing to assert to a customer as though it were a standard — particularly if your observation period was short, because the reader is also weighing how much testing sits behind the report.
My observation period was only 3 months. How long is my report good for?
The same freshness ladder applies — comfortable to roughly six months past the period end, bridge-letter territory to twelve — but expect more scrutiny sooner. A reader eight months out is looking at three months of tested evidence and eight months without. The right move is not to argue for a longer shelf life; it is to have the next observation period already running, starting the day after the first one closed, so you can answer "what about since then?" with a date rather than an assurance.
What is the difference between the observation period and the report validity?
The observation period is the window the CPA firm tested and the only period the opinion covers — for example 1 May to 31 July 2026. Validity is not a defined term at all; it is shorthand for how long your customers keep accepting the report. The observation period is fixed and printed in the report. Commercial acceptance is set by each customer’s vendor-risk policy and typically runs about a year from the period end.
Can a bridge letter extend how long my SOC 2 report is valid?
It helps across a normal gap and does not extend validity indefinitely. A bridge letter is a statement from your own management that nothing material has changed since the period ended — it carries no audit assurance, because the CPA firm performs no procedures on the gap period. It works well for a quarter or so. If it would need to cover more than about three months, or the underlying report is over a year old, customers will generally want the next report instead.
How soon should we start the next SOC 2 audit?
Plan for the next observation period to begin the day after the current one ends, so consecutive reports abut and no month is left uncovered. Practically that means the readiness and evidence work runs continuously rather than restarting each year. Where a client has just completed a short first Type 2, we normally recommend moving straight into a longer second period rather than repeating a short window.
Does a SOC 2 Type 1 report have the same shelf life?
It has less. A Type 1 reports on the design of controls at a single point in time, with no operating-effectiveness testing behind it, so it goes stale faster in buyers’ eyes and many enterprise customers will not accept one as the final answer at all. Treat a Type 1 as a milestone on the way to a Type 2 rather than as a report with a shelf life to manage.
Related reading: SOC 2 bridge letters, choosing your observation period, Type 1 vs Type 2, how to read a SOC 2 report, opinions and exceptions, and the SOC 2 hub.
Written By Expert Auditors
Keep Exploring
Related Reading
SOC 2 Bridge Letters
Management signs it, not the CPA. What it can credibly say, and what it cannot.
Read moreSOC 2 Observation Period: 3, 6 or 12 Months?
No AICPA minimum. Why short windows leave low-frequency controls untested.
Read moreType 1 vs Type 2
Which report to get first, and when to go straight to Type 2.
Read moreHow to Read a SOC 2 Report
All five sections annotated, an 8-step reviewer checklist, and the red flags.
Read moreSOC 2 Knowledge Hub
Type 1 vs Type 2, criteria, timelines and audit prep — all guides.
Read moreSOC 2 Overview
The AICPA attestation US and global enterprise buyers ask for.
Read moreGet in touch
Book a free consultation or send us your requirements. We respond within 24 hours.
Quick Call
Pick a time slot
Send Requirements
Get a custom quote in 24 hours