Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you choose a SOC 2 auditor?
Last verifiedStart with the non-negotiables: a licensed CPA firm, verified with the state board, with current peer review and no independence conflict. Then compare relevant recent experience, report readability, engagement-team continuity, fieldwork lead time, and fee against identical written scope. Nobody should be ranking firms for you.
How to choose a SOC 2 auditor, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
Criteria and questions, not a ranking
Audience: an engineering lead, CTO, or compliance owner running a selection process. This page names no firms and ranks nobody, deliberately. A published ranking of audit firms would be an endorsement we cannot defend and cannot keep current, and the right firm for a twelve-person company is not the right firm for a regulated enterprise. What follows is criteria you apply yourself.
The non-negotiable floor: only a licensed CPA firm can perform a SOC 2 examination and issue the report. Verify licensure with the relevant state board of accountancy, and treat compliance-automation platforms, readiness advisers, and security consultancies as complements, never as the attestor. Compliance-automation tooling, including this product, is not the attestor.
SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report and none tells you how to pick a firm. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate, so you are not shopping for a certification body; you are engaging a practitioner whose opinion your buyers will read. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, and a firm's fee and lead time depend on which you want. Last verified 10 September 2026. Not legal advice.
Selection criteria
Each criterion states what to check and how, plus the kind of text it is. Weight them yourself — the weighting is a judgement about your situation, and we are not making it for you.
| Criterion | What to check | How to verify | Kind of text |
|---|---|---|---|
| CPA licence | The firm is licensed or registered as required to perform attestation engagements in the relevant jurisdiction. | Check directly with the state board of accountancy, not the firm's website. | Licensing requirement — the board's rules govern. Non-negotiable. |
| Peer review | The firm participates in the AICPA Peer Review Program and its most recent review is current. | Ask for the report or acceptance date. A refusal to discuss it is itself a finding. | Licensing requirement plus best practice — not a quality ranking. |
| Independence | No conflict from readiness work, control design, or tooling sold by the same organisation. | Ask in writing how independence is preserved and who performed any readiness work. | Attestation-standard requirement — AT-C section 105. Non-negotiable. |
| Relevant recent experience | SOC 2 examinations for organisations of similar size, technology stack, and criteria categories, performed recently. | Ask how many the engagement team performed in the last year and in what environments. Ask for redacted references. | Best practice — no standard sets a threshold, so state your own bar. |
| Report quality | Reports that read clearly: an intelligible description, comprehensible test descriptions, and exceptions written so a buyer understands scope. | Ask for a redacted sample report and read it as your buyer would. | Best practice — your buyers read the report, not the engagement letter. |
| Engagement-team continuity | The people you meet during selection are the people who perform the work, and the team persists across periods. | Ask who is on the team, their roles, and what turnover looks like. | Market observation — continuity commonly reduces repeated ramp-up cost. |
| Timeline and capacity | Fieldwork lead time and report turnaround that fit the date you owe a customer. | Ask for both in writing, and ask what happens if their calendar slips. | Market observation — capacity is commonly the binding constraint. |
| Fee and scope discipline | A fee quoted against your written scope, with the triggers for a change order named. | Get proposals from several firms against identical written scope. | Market observation — comparing quotes on different scopes compares nothing. |
| Working style | How they deliver requests, how they handle a discovered deviation, and how responsive they are. | Ask how they raise a possible exception and when. Reference calls answer this better than proposals. | Best practice — this determines whether fieldwork is calm or adversarial. |
Questions to ask every firm
Ask all of them, the same way, and write down the answers. Differences in how firms answer the awkward ones are more informative than the proposals.
- Which entity is licensed to issue the report, and in which jurisdiction? Licensing requirement.
- When was your last peer review, and what was the outcome?
- Who is on the engagement team, and how many SOC 2 examinations has that team performed in the past year?
- How do you preserve independence if we also buy readiness or tooling from you or an affiliate? Attestation-standard requirement.
- How do you deliver the request list, and in what format do you want evidence?
- How and when do you raise a possible exception during fieldwork?
- What is your fieldwork lead time from signature, and your report turnaround from fieldwork close?
- What would trigger a change order on the fee, and how large might it be?
- Can we see a redacted sample report from an engagement resembling ours?
- Who signs the report, and what happens if that person leaves mid-engagement?
Signals worth pausing on
None of these disqualifies a firm on its own, and none is an accusation about any particular provider. They are prompts to ask a further question. Market observation.
- A quote given before anyone asked about your scope, criteria categories, or boundary.
- Reluctance to discuss peer review or to name the licensed entity that issues the report.
- A promise about the outcome of the examination. Nobody can promise an unmodified opinion — that would defeat the independence the report rests on.
- A guaranteed report date given before evidence quality is known.
- The same organisation selling readiness work, tooling, and the examination without a clear independence answer.
- Marketing that describes the deliverable as certification. If the firm uses the misnomer, ask how carefully they write reports.
- Fees far outside the range other firms quote for identical scope, in either direction. Both ends deserve a question.
Kinds of text on this page
Different sentences here carry different weight. The table labels which is which, and nothing here is an endorsement of any provider.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — including independence and competence. | Not a statute, and it binds the practitioner rather than you. |
| Licensing requirement | CPA and firm licensure set by state boards of accountancy, plus the AICPA Peer Review Program. | Not a quality ranking, and not an endorsement of any firm that satisfies it. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | Selection steps experienced buyers take, such as reading a redacted sample report. | Not required by any attestation standard. |
| Market observation | What firms and buyers are commonly observed to do, including where capacity binds. | Not a rule, not a ranking, and not a promise about any provider. |
| SRM recommendation | Something this product suggests doing. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
Run it as a procurement exercise with a written scope. That single discipline makes every other comparison meaningful.
- Write the scope: report type, criteria categories, system boundary, entities, subservice organisations, and the date you owe a customer.
- Shortlist several licensed CPA firms and verify each licence with the relevant state board yourself.
- Send the identical written scope to all of them and ask the same question list.
- Read a redacted sample report from each, as your buyer would read it.
- Take reference calls and ask specifically how the firm handled a discovered deviation.
- Compare fee, lead time, turnaround, and change-order triggers side by side against identical scope.
- Get independence in writing where readiness work or tooling came from the same organisation.
- Do not choose on price alone, and do not choose a firm that promised you an outcome.
Checklist
A selection checklist, labelled by kind of text. Criteria and questions only — no ranking, no endorsement, no named firms.
- Licence verified with the relevant state board of accountancy? Licensing requirement.
- Peer-review status current and disclosed? Licensing requirement plus best practice.
- Independence addressed in writing? Attestation-standard requirement.
- Relevant recent experience evidenced by team detail and references? Best practice.
- Redacted sample report read from the buyer's point of view? Best practice.
- Fieldwork lead time and report turnaround in writing? Market observation — the usual constraint.
- Proposals compared against identical written scope, with change-order triggers named? Market observation.
- Nobody promised an outcome, and nobody called the deliverable a certification? Attestation-standard requirement for independence; the misnomer is a credibility signal.
Where this shows up in ShipReady Metrics
This page is vendor-neutral and there is no product mapping to claim. The relevant honesty is about our own category: this product sits in compliance automation, is not the attestor, does not perform examinations, does not sign reports, and does not partner-issue an opinion. Do not treat a subscription here as an audit engagement.
If you already have a session: evidence collection, evidence review with the met-verdict overlay, the policies library, the 24-framework crosswalk (criteria series references only, no Trust Services Criteria text reproduced), connector-sourced evidence, ShipReady Passport with the auditor share token, and the cyber risk register are preparation surfaces. Arriving at a selection conversation with evidence already in order is what shortens a firm's scoping questions, and it is also what makes their fee estimate more reliable.
Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
Independence and competence come from the attestation standards; licensure and peer review from the boards and the AICPA. None of these authorities ranks firms, and neither does this page.
AICPA attestation standards SSAE 18, AT-C section 105 (independence, competence, engagement acceptance) and AT-C section 205. AICPA Peer Review Program requirements for firms performing attestation engagements. State boards of accountancy for CPA and firm licensure, reachable through NASBA's directory. AICPA Trust Services Criteria, TSP section 100 — proprietary AICPA material cited by reference and paraphrased, never reproduced. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.