A company must comply with SOC 2 Type II. What distinguishes a Type II report from a Type I report?
-
A
Type II covers more trust service criteria than Type I
-
B
Type II evaluates design and operating effectiveness over a period, Type I only evaluates design at a point in time
-
C
Type II is performed by internal auditors while Type I requires external auditors
-
D
Type II applies only to cloud providers while Type I applies to on-premises systems