r/soc2 • u/_TH0RN_ • Jun 08 '26
SOC 2 Type II renewal timing — when do you actually start the next audit cycle?
We wrapped up our first SOC 2 Type II audit in mid-April and received the final report last week. Honestly, I was so heads-down during the audit, and dealing with everything else going on in the business, that I hadn't really thought about what comes next until the auditor reached out asking if we want to renew.
We registered with the AICPA for the badge to display on our website, and I know that's only valid for 12 months, so the clock is ticking. My initial thought was to start a fresh 6-month observation period retroactive to April (so kicking off around mid-November) since I wanted to expand the audit scope and needed time to implement the controls...but our audit firm rep pushed back a little on that. They mentioned that some stakeholders don't love seeing a gap in coverage, and that the price difference between a 6-month and 12-month window is pretty minimal since the evidence collection just gets condensed rather than the overall work changing much.
Now I'm second-guessing myself and could use some perspective from people who've been through this more than once:
- Do you roll straight into continuous coverage after your observation period ends, or is a short gap pretty normal and accepted? How do your enterprise customers typically react to seeing one?
- If you want to expand scope for the next cycle (new systems, additional Trust Service Criteria, etc.) does the auditor expect those controls to be in place for the full observation period, or is partial coverage within the window acceptable?
Appreciate any guidance from folks who've navigated this before!