All framework guides
Help Center · Framework guide
SOC 2 Type I
SOC 2 Type I · Security · Global · vType I
SaaSAuditTrust ServicesType I
Overview
SOC 2 Type I reports on whether controls relevant to the Trust Services Criteria were suitably designed and implemented as of a specific date — a common first step before a Type II period review.
61 controls available in ComplAI for this framework.
Who it's for
- Startups and growth-stage SaaS vendors pursuing their first SOC 2 report
- Teams that need a point-in-time attestation for enterprise sales cycles
- Organizations building toward a subsequent Type II examination period
Why it matters
Type I establishes baseline trust with customers and auditors before you accumulate a full period of operating effectiveness evidence for Type II.
Trust Services Criteria (Security + optional criteria)Control design and implementation at a review datePoint-in-time policies, procedures, and configuration evidenceFoundation for Type II operating effectiveness testing
How ComplAI helps
- Activate SOC 2 Type I in the Framework Library to load its control catalog
- Assign owners, track compliance status, and attach evidence per control
- Use risk register and issues workflows when controls fail or deviate
- Export readiness views for leadership and auditors
Sample controls
- governance
CC1.1
Integrity and ethical values
- governance
CC1.2
Board independence and oversight
- governance
CC1.3
Organizational structure and authority
- human resources
CC1.4
Commitment to competence
- governance
CC1.5
Accountability for internal control
- governance
CC2.1
Internal communication of objectives
Getting started
- Open Framework Library and activate SOC 2 Type I
- Review the control list and prioritize high-impact domains
- Attach policies, procedures, and technical evidence
- Mark controls audit-ready and monitor residual gaps
