Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Who can perform a SOC 2 examination and issue the report?

Last verified

Only an independent licensed CPA firm can perform a SOC 2 examination and issue the report containing the opinion. Compliance-automation platforms, readiness advisers, security consultancies, and penetration-testing providers cannot, whatever their marketing implies. Verify the licence with the relevant state board of accountancy.

Who can perform a SOC 2 examination, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.

This is who may attest, not a recommendation of anyone

Audience: a founder or compliance owner about to sign an engagement, and a buyer deciding whether a received report is worth anything. This page names no firms and ranks nobody. It gives the authorisation rule and the verification steps. It does not determine that YOU need SOC 2 and does not issue a SOC 2 report.

Only a licensed CPA firm can perform a SOC 2 examination and issue the report. The examination is conducted under SSAE 18 — AT-C sections 105 and 205 — which set independence, competence, evidence, and reporting requirements on the practitioner. Those requirements are why the opinion carries weight with a vendor-risk reviewer, and why nobody outside that regime can produce one.

SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report. What is regulated is the practice of public accountancy — CPA licensure sits with state boards of accountancy, and firms performing attestation work are subject to peer review. "SOC 2 certified" is a misnomer that muddies this question, because there is no certification body to accredit and no SOC 2 certificate to issue; there is a licensed firm and its opinion. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, and the same firm performs either — the licensure question does not change with the type. Last verified 10 September 2026. Not legal advice.

Who can do what

Provider types by what they are actually authorised to deliver. This is a capability table, not a ranking, and it names no vendors.

Provider types and what each is authorised to deliver (not a ranking, no named firms; not legal advice)
Provider typeCan perform the examination?What it can doKind of text
Independent licensed CPA firmYes — and only this.Plan and perform the examination, test controls, form and issue the opinion, sign the report.Attestation-standard requirement — independence and competence are preconditions under AT-C section 105.
Individual CPA not practising through a licensed firmNo, in the ordinary case.Advise. Attestation reports are issued by a firm registered or licensed as required in the relevant jurisdiction.Licensing requirement — verify with the relevant state board of accountancy, whose rules govern.
Compliance-automation platformNo.Collect and organise evidence, monitor controls, track readiness, manage the request list.SRM recommendation — this product is in this category, and it is not the attestor.
Readiness or gap-assessment adviserNo.Assess gaps, help design controls, write policies, run a dry-run request list.Best practice — useful, and never a substitute for the examination.
Security consultancy or penetration-testing providerNo.Produce technical assessments that can serve as evidence within the examination.Best practice — evidence, not an attestation.
Certification body accredited for ISO standardsNo.Certify an ISO/IEC 27001 management system, which is a different instrument with a certificate and surveillance cycle.Voluntary standard — different regime, different deliverable.

Licensing and peer review

Two independent checks exist, and both are worth making before you sign. Neither is a quality ranking; they are minimum-legitimacy checks.

  • CPA licensure is granted and policed by state boards of accountancy. Verify the firm's licence status directly with the board in the relevant jurisdiction rather than relying on a logo on a website. Licensing requirement — the board's rules govern, not this page.
  • Firms performing attestation engagements are subject to the AICPA Peer Review Program, in which another firm reviews their work against professional standards. Ask for the firm's most recent peer-review report or its acceptance date. A firm that will not discuss peer review has told you something.
  • Independence is an attestation-standard requirement. A firm that designed, implemented, or operates your controls has an independence problem for the examination. Ask directly how they separate readiness work from the examination.
  • Competence in the subject matter is also required. Ask how many SOC 2 examinations the engagement team performs a year and in what kinds of technology environment. Best practice, since no standard publishes a threshold.
  • A report signed by anyone other than a licensed CPA firm is not a SOC 2 report, whatever it is titled. Best practice for a buyer: check the signature block and the firm's licence before relying on it.
  • Do not accept "our platform includes the audit" at face value. Ask which licensed CPA firm performs the examination, and contract clarity about who issues the opinion. SRM recommendation.

Tooling is not the attestor

This confusion is common enough to be worth stating flatly, and it applies to this product as much as to any other.

  • A compliance-automation platform can collect evidence, monitor controls continuously, and show you readiness. None of that is an opinion.
  • Some platforms partner with or refer you to CPA firms. The firm, not the platform, performs the examination and signs the report. Verify the firm separately.
  • A dashboard showing every control green is your own assessment. It is not an attestation, and no buyer should be shown it as one.
  • Automation does not remove the practitioner's obligation to obtain sufficient appropriate evidence, and it does not oblige the practitioner to accept tool output as evidence. Attestation-standard requirement.
  • This product does not issue a SOC 2 report and does not replace a licensed CPA examination.

Kinds of text on this page

Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.

How to read the claims on this page (not a ranking; not legal advice; last verified 10 September 2026)
Kind of textWhat it meansWhat it is not
Attestation-standard requirementSSAE 18 — AT-C sections 105 and 205 — governs independence, competence, evidence, and reporting for the practitioner.Not a statute, and it binds the practitioner rather than you.
Licensing requirementCPA licensure and firm registration rules set by state boards of accountancy, plus the AICPA Peer Review Program.Not a SOC 2 rule as such, and not a quality ranking of any firm.
Trust Services Criteria referenceA pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100.Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase.
Best practiceVerification steps experienced buyers and compliance owners take.Not required by any attestation standard. Skipping it is not an exception.
Market observationWhat providers and buyers are commonly observed to do, including how platforms describe partnerships.Not a rule, not an endorsement, and not a promise about any provider.
SRM recommendationSomething this product suggests doing.Not a legal requirement, not an attestation requirement, and not an audit opinion.

What to do now

Verification takes an afternoon and prevents the worst outcome in this cluster: paying for something that is not an examination.

  • Ask the prospective provider, in writing, which licensed CPA firm will perform the examination and sign the report.
  • Verify that firm's licence with the relevant state board of accountancy yourself.
  • Ask for the firm's most recent peer-review outcome, and ask when the next one is due.
  • Ask how independence is preserved if the same organisation also sold you readiness work or tooling.
  • Ask who on the engagement team has performed SOC 2 examinations in a technology environment like yours, and how recently.
  • If you are the buyer receiving a report, check the signature block, confirm the firm is licensed, and read the opinion before the marketing summary.
  • Do not treat a tooling contract as an audit engagement. Only a licensed CPA firm can perform the examination and issue the report.

Checklist

Verification questions, labelled by kind of text. Criteria and questions only — no endorsement, no ranking, no named firms.

  • Is the attestor a licensed CPA firm, verified with the board rather than a website? Licensing requirement.
  • Is the firm's peer-review status current and disclosed? Licensing requirement plus best practice.
  • Has independence been addressed in writing where readiness work or tooling came from the same source? Attestation-standard requirement.
  • Does the engagement team have relevant recent SOC 2 experience? Best practice.
  • Does the engagement letter state who issues the opinion? Attestation-standard requirement in effect.
  • Are we clear that our automation platform, including this one, is not the attestor? SRM recommendation.
  • For a received report: signature block checked, licence verified, opinion read? Best practice for buyers.

Where this shows up in ShipReady Metrics

This page is vendor-neutral and there is no product mapping to claim. What is worth saying plainly: this product sits in the compliance-automation category and is not the attestor. It does not perform examinations, does not employ practitioners to attest on your behalf, does not sign reports, and does not partner-issue an opinion.

If you already have a session: evidence collection, evidence review with the met-verdict overlay, the policies library, the 24-framework crosswalk (criteria series references only, no Trust Services Criteria text reproduced), connector-sourced evidence, ShipReady Passport with the auditor share token, and the cyber risk register are all preparation surfaces. They help you arrive at an examination with evidence in order. Readiness in this product is not an attestation opinion.

This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.

Primary sources (last verified 10 September 2026)

Authorisation and independence come from the AICPA attestation standards; licensure comes from state boards of accountancy. Neither authority ranks firms, and neither does this page.

AICPA attestation standards SSAE 18, AT-C section 105 (including independence and competence) and AT-C section 205. AICPA Peer Review Program requirements for firms performing attestation engagements. State boards of accountancy for CPA and firm licensure, with NASBA's directory as the route to the right board. AICPA Trust Services Criteria, TSP section 100 — proprietary AICPA material cited by reference and paraphrased, never reproduced. These are not a complete list, and none of them is legal advice.

The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.

Frequently asked questions