Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is the difference between an auditor, a consultant, and a certification body?
Last verifiedWhat is the difference between an auditor, a consultant, and a certification body? Each role issues different outputs under different rules. This page compares roles. Not legal advice. Not procurement advice.
Security assurance guidance, last verified 10 September 2026 against AICPA attestation standards, AICPA Code ET §1.200, ISO/IEC 27001:2022, and ISO/IEC 17021-1:2015. This page does not determine which role YOU need on YOUR facts.
Role-comparison table
SOC 2 is CPA attestation — not ISO certification. ISO/IEC 27001 is accredited certification — not a SOC 2 report. A consultant letter is neither. Last verified 10 September 2026. Not legal advice.
| Role | Issues | Licensed / accredited? | Independence bar | Example schemes |
|---|---|---|---|---|
| Licensed CPA auditor (SOC 2) | SOC 2 Type I / II attestation report | Yes — CPA licence + AICPA peer review | AICPA Code ET §1.200 — no self-review | SOC 2 under AICPA SSAE 18 / AT-C |
| Accredited certification body | ISO/IEC 27001 or ISO/IEC 42001 certificate | Yes — ISO/IEC 17021-1 via national AB | ISO/IEC 17021-1 §5 impartiality — consultancy limits | ISO management-system certification |
| Consultant / readiness provider | Policies, gap analysis, evidence prep — not a report or certificate | No universal licence — credentials vary | Must not be same party as YOUR auditor/CB if independence rules apply | Readiness for any framework |
| Internal audit function | Internal audit reports — not external attestation | Organizational role — not external CPA/CB | Must be independent of operations audited | COSO / IIA standards — best practice |
SOC 2 CPA attestation vs ISO accredited certification
- SOC 2: licensed CPA firm, Trust Services Criteria, attestation report for a defined period — AICPA professional standard.
- ISO/IEC 27001: accredited CB, ISO/IEC 27001:2022 management system, certificate with AB mark — ISO/IEC 17021-1 professional standard.
- Customers sometimes accept either; YOUR contract names which instrument — this page does not read YOUR contract.
- ShipReadyMetrics is readiness tooling — not any of the three issuing roles above.
What to do now
- Read YOUR contract for the named deliverable (SOC 2 report vs ISO certificate vs 'security audit').
- If the deliverable is SOC 2, shortlist CPA firms only. If ISO/IEC 27001, shortlist accredited CBs only.
- Use consultants for preparation if independence rules allow separation — see same-firm-prepare-and-audit guide.
- Walk the how-to-choose-a-security-auditor decision tree on this site.
Checklist
- Named deliverable matches provider type?
- Register verification completed for CPA licence or CB accreditation?
- Consultant scope explicitly excludes signing the attestation/certificate?
- Independence questionnaire documented?
Where this shows up in ShipReady Metrics
ShipReadyMetrics sits in the readiness layer: evidence collection, obligation map, crosswalk. It does not audit, certify, or sign attestation reports. Marking a framework in-scope is not a determination that it applies.