Type I checks that controls are designed correctly at a point in time; Type II checks that they actually operated over months. For cloud PMS and AI tools it is the strongest evidence of security maturity a buyer can request.
From our data: 19 of 445 software products we track publicly report SOC 2 Type II.