Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is the difference between an auditor, a consultant, and a certification body?

Last verified

What is the difference between an auditor, a consultant, and a certification body? Each role issues different outputs under different rules. This page compares roles. Not legal advice. Not procurement advice.

Security assurance guidance, last verified 10 September 2026 against AICPA attestation standards, AICPA Code ET §1.200, ISO/IEC 27001:2022, and ISO/IEC 17021-1:2015. This page does not determine which role YOU need on YOUR facts.

Role-comparison table

SOC 2 is CPA attestation — not ISO certification. ISO/IEC 27001 is accredited certification — not a SOC 2 report. A consultant letter is neither. Last verified 10 September 2026. Not legal advice.

Auditor vs consultant vs certification body (not legal advice — verify YOUR engagement)
RoleIssuesLicensed / accredited?Independence barExample schemes
Licensed CPA auditor (SOC 2)SOC 2 Type I / II attestation reportYes — CPA licence + AICPA peer reviewAICPA Code ET §1.200 — no self-reviewSOC 2 under AICPA SSAE 18 / AT-C
Accredited certification bodyISO/IEC 27001 or ISO/IEC 42001 certificateYes — ISO/IEC 17021-1 via national ABISO/IEC 17021-1 §5 impartiality — consultancy limitsISO management-system certification
Consultant / readiness providerPolicies, gap analysis, evidence prep — not a report or certificateNo universal licence — credentials varyMust not be same party as YOUR auditor/CB if independence rules applyReadiness for any framework
Internal audit functionInternal audit reports — not external attestationOrganizational role — not external CPA/CBMust be independent of operations auditedCOSO / IIA standards — best practice

SOC 2 CPA attestation vs ISO accredited certification

  • SOC 2: licensed CPA firm, Trust Services Criteria, attestation report for a defined period — AICPA professional standard.
  • ISO/IEC 27001: accredited CB, ISO/IEC 27001:2022 management system, certificate with AB mark — ISO/IEC 17021-1 professional standard.
  • Customers sometimes accept either; YOUR contract names which instrument — this page does not read YOUR contract.
  • ShipReadyMetrics is readiness tooling — not any of the three issuing roles above.

What to do now

  • Read YOUR contract for the named deliverable (SOC 2 report vs ISO certificate vs 'security audit').
  • If the deliverable is SOC 2, shortlist CPA firms only. If ISO/IEC 27001, shortlist accredited CBs only.
  • Use consultants for preparation if independence rules allow separation — see same-firm-prepare-and-audit guide.
  • Walk the how-to-choose-a-security-auditor decision tree on this site.

Checklist

  • Named deliverable matches provider type?
  • Register verification completed for CPA licence or CB accreditation?
  • Consultant scope explicitly excludes signing the attestation/certificate?
  • Independence questionnaire documented?

Where this shows up in ShipReady Metrics

ShipReadyMetrics sits in the readiness layer: evidence collection, obligation map, crosswalk. It does not audit, certify, or sign attestation reports. Marking a framework in-scope is not a determination that it applies.

Frequently asked questions