How to start a SOC 2 practice at a small CPA firm
Every page ranking for this question sells SOC 2 to the company buying one. This is the firm side: what has to be true before you sign a first engagement letter.
There is no SOC 2 license. No accreditation body issues one. No registry lists approved firms. A SOC 2 is an examination performed under the AICPA attestation standards,1 which means the permit that governs the work is the CPA firm license your state board already issued you.5
Three things do gate entry, and none of them are the ones firms ask about first. Peer review scope. A quality management system with a date on it. One technical competence a tax practice does not already hold.
Search this question and the results explain SOC 2 to the company buying a report. That material is written for your prospect. It answers what a SOC 2 costs them and how long it takes, which tells you nothing about whether your firm should sell one. This page is the other side of the desk.
What the standards actually require
Four documents govern the work, and a firm can read all four before committing a dollar to anything. Two are standards, one is a criteria set, and one is the implementation guide practitioners work from.
- The attestation standards
- A SOC 2 is an examination under the Statements on Standards for Attestation Engagements.1 Same standards, same evidence requirements and same documentation bar as any other attest examination your firm performs. Nothing about SOC 2 is procedurally exotic. The subject matter is.
- The trust services criteria
- The criteria the controls are examined against.3 Security is common to every SOC 2. Availability, confidentiality, processing integrity and privacy are separate categories, and each one you add moves the hours.
- The AICPA SOC 2 guide
- The implementation reference for scoping, the management assertion, sampling and report form.2 Buy it before the first engagement, not during it. It is the difference between designing your own approach and following one that a peer reviewer will already recognize.
- Quality management
- SQMS No. 1, issued by the AICPA Auditing Standards Board in June 2022, applies to every firm performing any engagement in its accounting and auditing practice, and engagements under the attestation standards are inside that definition.
The SQMS dates are specific and they have already passed. Paragraph 14 requires systems of quality management to be designed and implemented by December 15, 2025, and the evaluation of the system to be performed within one year following that date. Paragraph 54 says that evaluation is undertaken as of a point in time and performed at least annually. Read it yourself: the standard is published in full, read on 1 August 2026. A firm whose practice was tax and compilations until now is entering that scope for the first time, and it is cheaper to find that out this month than during a review.
Peer review is the gate people forget to check
Attest work is reviewed work. The AICPA states it plainly: almost every firm that performs accounting or auditing work is required to undergo a peer review, which is a review of selected engagements to determine if they were compliant with professional standards, or an evaluation of the firm’s system of quality control.4
So the SOC 2 engagements you accept this year are candidates for selection in your next review. That is not an argument against taking them. It is an argument for telling your peer reviewer before the first one rather than after, and for writing the first engagement’s workpapers as though a stranger will read them without you in the room. Because one will.
Who runs the first engagement
Two people, at minimum. A partner who reviews and signs, and a senior who performs fieldwork. Headcount is not the constraint. What the senior can read is.
A SOC 2 population lives in a cloud console, an identity provider, a ticket queue and a code repository. Testing logical access means opening an access policy and deciding whether it grants what the control description claims it grants. That is closer to an information systems background than to a tax one. A firm without it has three honest options: hire it, subcontract it under your own supervision, or wait.
SQMS No. 1 also asks you to name a person. Ultimate responsibility for the system of quality management sits with an identified individual who evaluates it at least annually, and in a six person firm that is a partner rather than a committee. Keep the reviewer separate from the preparer. One person cannot both build a workpaper and be the second look at it.
What the first engagement looks like
Take a Type 1 first. A Type 1 examines design at a point in time, and a Type 2 examines operating effectiveness across a period, which multiplies the sampling and the elapsed calendar at the same time. The buyer-side explanation of that split sits at Type 1 versus Type 2, and it is worth reading because your prospect has probably read something like it.
- Scoping and the system description. The client writes the description. You assess whether it describes the system you are about to examine, and whether the boundary they drew includes infrastructure they do not control.
- Criteria selection. Security is common to all. Every additional category is a scope decision with an hours consequence, and it belongs in the engagement letter rather than in an email six weeks later.
- The request list. Writing it is fast. Making each line legible to an engineer who has never seen a prepared-by-client list is the actual work.
- Testing. Inspection, reperformance and exception handling against the criteria. This is the part your estimate is usually right about.
- Workpapers. Evidence tied to criteria so the conclusion can be followed without narration. That bar comes from the attestation standards, not from house style.
- Review, then issuance. Partner time at partner rates, and it does not compress. A report that reaches issuance before the review completes is the one finding you cannot argue your way out of.
Where the hours actually go, and what to charge for them, is a separate calculation. SOC 2 engagement pricing works up from a published hours breakdown and shows where realization leaks on a small engagement.
The go/no-go worksheet
Printed in full below, no email address required. Every line is your own number except the arithmetic at the bottom, and the arithmetic is the entire decision. Fill it in before you buy software, before you take a course, and before you tell a client you are considering it.
| Line | What it is | Where your number comes from |
|---|---|---|
| 1. Peer review status | Your current review type and the date of the next one | Your peer reviewer, in a call you make this week |
| 2. Quality management system | Designed and implemented per SQMS No. 1, plus the date of your evaluation | Your own QM documentation, or the absence of it |
| 3. Technical competence | The named person who can read a cloud access policy and a log retention setting | Your staff list, or a subcontract you supervise |
| 4. Reference material and training | The AICPA guide, plus CPE for everyone on the engagement | The AICPA catalog and your CPE provider, at list price |
| 5. Insurance | Whether your professional liability policy covers attest work of this type | Your carrier, in writing, not over the phone |
| 6. Partner hours, year one | Setup, methodology, review and sign-off you will not bill to engagement one | Your partner rate times your own estimate |
| 7. Staff hours, year one | Fieldwork and workpaper build on the first engagement, above what you quoted | Your staff rate times your own estimate |
| 8. Software | Workpapers, request list, sampling and the sign-off chain | Per engagement, per user or per client, depending on the model |
| A. First-year fixed cost | What you spend before a single engagement earns | Lines 4 through 7, plus line 5 |
| B. Contribution per engagement | What one engagement leaves behind | Your fee, minus direct hours, minus the per engagement software cost |
| C. Break-even engagements | How many you need before the practice pays for itself | A divided by B, rounded up |
| D. Named prospects | Clients who have already been asked for a SOC 2 report by a customer | Real names on your client list, not a market estimate |
The decision rule is D against C. If you cannot name more prospects than the break-even count, the answer is not no. It is not yet, and the fix is line D rather than line A.
Line 6 is the one that gets understated, because building a methodology once feels like overhead rather than cost, and it is the largest number on the sheet in year one. Line D gets overstated in the other direction, because a category estimate feels like a pipeline. It is not. A name with a date attached is a pipeline.
Where the first client comes from
Your own book, and specifically the part of it selling software or data services to other businesses. The request arrives from a customer during procurement. The client then goes looking for a firm, and your name is already on their tax return.
So ask. One line in your next client email: has a customer asked you for a SOC 2 report. Answers to that question are worth more than any market sizing at this scale, because they come back as named companies with dates attached. That is line D on the worksheet, and it is the only line you cannot buy.
Take the first engagement from a client whose infrastructure you can actually see. Ask for three specific artifacts before you quote: the last access review, the current list of production administrators, and one closed incident ticket. What comes back, and how fast, tells you more about the engagement than the questionnaire will.
The software line, and what it does not include
Tooling is the smallest decision here and the one firms make first. What you need is narrow: workpapers tied to criteria, a request list a client can answer without a call, sampling, and a sign-off chain that still reads correctly a year later. What audit software costs a small firm compares the licensing models rather than the numbers, because the numbers in that category are mostly unpublished.
Polara Enterprise is one of the options, and its price is stated here once rather than gated. Free to join. No seats, no monthly fee, no annual commitment. An engagement costs $600, billed when you open it, and ten bought together are $5,000 and stay valid for twelve months. The fee is uniform. It does not move with your findings, your conclusions, or whether the report you issue ends up qualified.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.6 The scoping judgment, the conclusions and the issuance decision belong to the firm on the engagement. Software records who reached them and when, which is the part a reviewer asks about.
None of that is the decision though. The decision is line C against line D, and you can make it this week with two phone calls and a spreadsheet. If the answer comes back yes, the Enterprise page has the rest of it.
Questions
Do you need a special license to perform SOC 2 examinations?
Does taking on SOC 2 work change peer review?
What does SQMS No. 1 require, and by when?
How many people does a first SOC 2 engagement need?
What does the software cost a firm?
Sources
- Statements on Standards for Attestation Engagements
- SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- AICPA Peer Review Program
- State Boards of Accountancy directory
- SOC 2 Report
Bring one engagement.
$0 to join. $600 when you create an engagement. Run one, start to seal, and judge the binder that comes out.
Book a working session