A SOC 2 Type I asks a single question: "Are your controls designed appropriately at a point in time?" The auditor reads the system description, walks the selected Trust Service Criteria against the Common Criteria, and writes an opinion on design only. A Type I can usually be produced inside about six weeks of controls being stable, costs roughly one third to one half of a Type II, and is the right artifact for early-customer trust pages and for sales cycles that ask "are you SOC 2?" but do not yet demand the operating-effectiveness evidence.
A SOC 2 Type II asks the harder question: "Did your controls actually operate effectively over a window?" The auditor describes the system, then tests a sample of controls over the audit period — typically six months minimum, twelve months for the cleanest opinion — and reports on operating effectiveness in addition to design. A Type II is slower, more expensive, and the artifact enterprise procurement teams demand for any vendor that holds regulated data, integrates with the production stack, or processes more than a defined threshold of customer records.
Both reports use the same five Trust Service Criteria selection; the difference is the period the auditor covers and the depth of evidence required. A common path is a Type I in year one to clear the trust-page objection and qualify for enterprise pipeline, then a Type II covering the next twelve months once the controls have actually been run long enough to produce a defensible opinion.