SOC 2 Type 1 vs Type 2 for seed startups
When seed SaaS should pursue Type 1 vs Type 2, what each proves, and how buyers usually sequence them.
PW-SOC2-007 SOC 2 readiness spoke
TL;DR. Most first reports cover Security (Common Criteria) only. Add Availability if uptime SLAs and resilience are buyer-visible; add Confidentiality when handling sensitive customer data is central to the deal. Extra categories mean more controls, evidence, and cost.
Claim ladder Material statements on this page are labeled Verified, Inferred, or Unknown per editorial standards.
Key terms: Trust Services Criteria, Common Criteria.
Security is the baseline category and includes the Common Criteria. Most seed Type 1 reports start here. It covers control environment, communication, risk, monitoring, and logical/physical access themes relevant to your system.
Adding categories expands testing and evidence. Start narrow unless a named deal requires otherwise—and document that requirement.
Security uses the Common Criteria as its foundation in the TSC model.
Only if in scope for your commitments; it is a separate category with more work.
Yes in a later period/report—plan evidence now if you expect to.