How long a SOC 2 report stays useful
It never expires, because it is not a certificate. What ages is the window it describes, and buyers enforce that line themselves.
How long is a SOC 2 report valid? It does not expire. A SOC 2 report is not a certificate with an expiry date on the front, and there is no body that revokes it. It describes one date, for a Type 1, or one stated period, for a Type 2, and it will keep describing that window accurately forever.
What ages is the usefulness. Most enterprise procurement will not accept a Type 2 whose period ended more than twelve months ago, and many want the months since then covered too. That convention is the thing with a clock on it. Not the document.
Nobody explains this at the point of purchase. You get a signed report, you send it to the buyer who asked for it, the deal closes, and eleven months later a different buyer asks the same question and gets a different answer. The report did not change. The reader’s tolerance did.
A report is not a certificate
Two words cause most of the confusion here: certified and valid. Neither one belongs to SOC 2. A CPA firm does not certify you and does not issue a license that lapses. It examines the controls you scoped and reports what it found, in a document with a date range printed on the front.1 If you are still deciding which document you need, Type 1 versus Type 2 covers the choice your buyer is actually making for you.
- Type 1
- An opinion that your controls were suitably designed as of one specific date. It speaks to that date and to nothing else. It never covered a period, so it can never be stretched into one.
- Type 2
- An opinion that those controls operated effectively throughout a stated period, usually three to twelve months. The period is printed on the report, and it is the only thing a buyer measures age against.
The facts in the report stay true indefinitely, because they were true in the window it covers. Relevance is what decays. A report covering last January through last December says nothing about what you did in March of this year, and a serious reviewer knows that perfectly well.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
The twelve month line buyers enforce
Procurement teams run on a rule that almost none of them write down. If the period covered by your Type 2 ended more than twelve months ago, the report is stale and the review stops. Some vendor risk programs say so in policy. Most just bounce it.
The stricter version asks for two things at once: a report whose period ended inside the last twelve months, plus written coverage of every month between that end date and today. The second half is where founders get caught. Your period ended in March, it is now August, and five months of your operating history are blank from the buyer’s side of the table.
| What the buyer asks for | What satisfies it | What gets bounced |
|---|---|---|
| Your SOC 2, no further detail | The most recent report you hold, with its period stated in the email body | A trust page link with no document behind it |
| Your most recent Type 2 | A report whose period ended inside the last twelve months | A Type 1 of any age, offered as a substitute |
| Current coverage | That report plus a signed letter covering every month since it ended | A gap of five months nobody mentions until they ask |
Bridge letters, and the case the templates skip
A bridge letter, also called a gap letter, covers the space between the end of your report period and today. You write it. Management signs it. The CPA firm does not sign it. Nothing over the gap period was examined, so there is nothing for an auditor to report on.2
- The dates
- The end of the examination period on one side and the date of the letter on the other. That span is the gap, and stating it plainly is half the value of the letter.
- The continuity assertion
- That the controls described in the report have continued to operate, and that no material changes have occurred that would affect them.
- The limitation
- That no independent examination was performed over the gap period, and that the letter is management’s statement rather than the auditor’s.
How long a buyer will take one is the real question. Three months is routine. Six months is the practical ceiling, and past that reviewers stop reading it as coverage and start reading it as an excuse.
A bridge letter asserts that no material changes occurred. Sometimes one did. You moved cloud providers, you were acquired, you lost the person who ran access reviews, or you rebuilt the product on a different stack. Signing the standard sentence anyway is a false statement by management, in writing, to a customer. Name the change instead: what changed, on what date, and which control operates now in place of the one described in the report. A disclosed change costs you one more security questionnaire. An undisclosed one costs you the account when the next report shows it.
Why the cadence becomes annual, and why periods touch
Follow the twelve month convention to its conclusion and the schedule writes itself. Your report ages out roughly a year after its period closes. The next period therefore has to close before that happens, which means the next examination has to be underway months earlier. That is the whole reason SOC 2 settles into an annual cycle, and it is a buyer driven rhythm rather than a rule from the standard.2
It also explains why experienced teams design consecutive periods rather than convenient ones. If your first Type 2 covers January through March and your second covers July through December, there is an uncovered quarter sitting inside your own history, and a diligent reviewer reading both reports side by side will find it. Back to back periods leave nothing to explain. How long that first window has to run, and why no platform can shorten it, is the subject of the SOC 2 observation period.
A Type 1 through Polara Labs is $4,000 one time. Keeping evidence collected afterwards is $600 per month on a 12-month term, and each examination is $5,000. That puts a steady state year, one renewal and one examination, at $12,200. The full arithmetic, including the year you are paying for two things at once, sits on what SOC 2 certification costs.
What to send while your next report is in progress
This is the email you will write several times a year, so it is worth having a shape for it. Four moves, in this order.
- Send the report with its dates in the email body. Do not make a reviewer hunt through a PDF for the period. One line does it: this report covers these dates, and here is the letter covering the months since.
- Attach the bridge letter before anyone asks. Volunteering it reads as competence. Producing it three emails later reads as improvisation, and by then the reviewer has already flagged the gap.
- Name the next period and the examination date. A buyer who knows your next report covers through March and lands in April can write a conditional approval today instead of waiting for you.
- Offer the interim artifacts, and label them honestly. Your policy set, your control list and a recent access review are not a report. Saying so yourself is what makes the rest of the email credible.
None of that helps if there is no next report. If a deal is already paused on this, what to do when a customer asks for a SOC 2 you do not have is the shorter path, and how long a SOC 2 actually takes gives you the dates to put in the email today.
Questions
Does a SOC 2 report expire?
How old can a SOC 2 report be before a customer rejects it?
Who writes the bridge letter, you or the auditor?
How long will a buyer accept a bridge letter?
How often do you need a SOC 2 audit?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.