How to start a SOC 2 practice at a small CPA firm

Every page ranking for this question sells SOC 2 to the company buying one. This is the firm side: what has to be true before you sign a first engagement letter.

There is no SOC 2 license. No accreditation body issues one. No registry lists approved firms. A SOC 2 is an examination performed under the AICPA attestation standards,1 which means the permit that governs the work is the CPA firm license your state board already issued you.5

Three things do gate entry, and none of them are the ones firms ask about first. Peer review scope. A quality management system with a date on it. One technical competence a tax practice does not already hold.

Search this question and the results explain SOC 2 to the company buying a report. That material is written for your prospect. It answers what a SOC 2 costs them and how long it takes, which tells you nothing about whether your firm should sell one. This page is the other side of the desk.

What the standards actually require

Four documents govern the work, and a firm can read all four before committing a dollar to anything. Two are standards, one is a criteria set, and one is the implementation guide practitioners work from.

The attestation standards
A SOC 2 is an examination under the Statements on Standards for Attestation Engagements.1 Same standards, same evidence requirements and same documentation bar as any other attest examination your firm performs. Nothing about SOC 2 is procedurally exotic. The subject matter is.
The trust services criteria
The criteria the controls are examined against.3 Security is common to every SOC 2. Availability, confidentiality, processing integrity and privacy are separate categories, and each one you add moves the hours.
The AICPA SOC 2 guide
The implementation reference for scoping, the management assertion, sampling and report form.2 Buy it before the first engagement, not during it. It is the difference between designing your own approach and following one that a peer reviewer will already recognize.
Quality management
SQMS No. 1, issued by the AICPA Auditing Standards Board in June 2022, applies to every firm performing any engagement in its accounting and auditing practice, and engagements under the attestation standards are inside that definition.

The SQMS dates are specific and they have already passed. Paragraph 14 requires systems of quality management to be designed and implemented by December 15, 2025, and the evaluation of the system to be performed within one year following that date. Paragraph 54 says that evaluation is undertaken as of a point in time and performed at least annually. Read it yourself: the standard is published in full, read on 1 August 2026. A firm whose practice was tax and compilations until now is entering that scope for the first time, and it is cheaper to find that out this month than during a review.

Peer review is the gate people forget to check

Attest work is reviewed work. The AICPA states it plainly: almost every firm that performs accounting or auditing work is required to undergo a peer review, which is a review of selected engagements to determine if they were compliant with professional standards, or an evaluation of the firm’s system of quality control.4

So the SOC 2 engagements you accept this year are candidates for selection in your next review. That is not an argument against taking them. It is an argument for telling your peer reviewer before the first one rather than after, and for writing the first engagement’s workpapers as though a stranger will read them without you in the room. Because one will.

Who runs the first engagement

Two people, at minimum. A partner who reviews and signs, and a senior who performs fieldwork. Headcount is not the constraint. What the senior can read is.

A SOC 2 population lives in a cloud console, an identity provider, a ticket queue and a code repository. Testing logical access means opening an access policy and deciding whether it grants what the control description claims it grants. That is closer to an information systems background than to a tax one. A firm without it has three honest options: hire it, subcontract it under your own supervision, or wait.

SQMS No. 1 also asks you to name a person. Ultimate responsibility for the system of quality management sits with an identified individual who evaluates it at least annually, and in a six person firm that is a partner rather than a committee. Keep the reviewer separate from the preparer. One person cannot both build a workpaper and be the second look at it.

What the first engagement looks like

Take a Type 1 first. A Type 1 examines design at a point in time, and a Type 2 examines operating effectiveness across a period, which multiplies the sampling and the elapsed calendar at the same time. The buyer-side explanation of that split sits at Type 1 versus Type 2, and it is worth reading because your prospect has probably read something like it.

  1. Scoping and the system description. The client writes the description. You assess whether it describes the system you are about to examine, and whether the boundary they drew includes infrastructure they do not control.
  2. Criteria selection. Security is common to all. Every additional category is a scope decision with an hours consequence, and it belongs in the engagement letter rather than in an email six weeks later.
  3. The request list. Writing it is fast. Making each line legible to an engineer who has never seen a prepared-by-client list is the actual work.
  4. Testing. Inspection, reperformance and exception handling against the criteria. This is the part your estimate is usually right about.
  5. Workpapers. Evidence tied to criteria so the conclusion can be followed without narration. That bar comes from the attestation standards, not from house style.
  6. Review, then issuance. Partner time at partner rates, and it does not compress. A report that reaches issuance before the review completes is the one finding you cannot argue your way out of.

Where the hours actually go, and what to charge for them, is a separate calculation. SOC 2 engagement pricing works up from a published hours breakdown and shows where realization leaks on a small engagement.

The go/no-go worksheet

Printed in full below, no email address required. Every line is your own number except the arithmetic at the bottom, and the arithmetic is the entire decision. Fill it in before you buy software, before you take a course, and before you tell a client you are considering it.

LineWhat it isWhere your number comes from
1. Peer review statusYour current review type and the date of the next oneYour peer reviewer, in a call you make this week
2. Quality management systemDesigned and implemented per SQMS No. 1, plus the date of your evaluationYour own QM documentation, or the absence of it
3. Technical competenceThe named person who can read a cloud access policy and a log retention settingYour staff list, or a subcontract you supervise
4. Reference material and trainingThe AICPA guide, plus CPE for everyone on the engagementThe AICPA catalog and your CPE provider, at list price
5. InsuranceWhether your professional liability policy covers attest work of this typeYour carrier, in writing, not over the phone
6. Partner hours, year oneSetup, methodology, review and sign-off you will not bill to engagement oneYour partner rate times your own estimate
7. Staff hours, year oneFieldwork and workpaper build on the first engagement, above what you quotedYour staff rate times your own estimate
8. SoftwareWorkpapers, request list, sampling and the sign-off chainPer engagement, per user or per client, depending on the model
A. First-year fixed costWhat you spend before a single engagement earnsLines 4 through 7, plus line 5
B. Contribution per engagementWhat one engagement leaves behindYour fee, minus direct hours, minus the per engagement software cost
C. Break-even engagementsHow many you need before the practice pays for itselfA divided by B, rounded up
D. Named prospectsClients who have already been asked for a SOC 2 report by a customerReal names on your client list, not a market estimate

The decision rule is D against C. If you cannot name more prospects than the break-even count, the answer is not no. It is not yet, and the fix is line D rather than line A.

Two lines firms fill in wrong

Line 6 is the one that gets understated, because building a methodology once feels like overhead rather than cost, and it is the largest number on the sheet in year one. Line D gets overstated in the other direction, because a category estimate feels like a pipeline. It is not. A name with a date attached is a pipeline.

Where the first client comes from

Your own book, and specifically the part of it selling software or data services to other businesses. The request arrives from a customer during procurement. The client then goes looking for a firm, and your name is already on their tax return.

So ask. One line in your next client email: has a customer asked you for a SOC 2 report. Answers to that question are worth more than any market sizing at this scale, because they come back as named companies with dates attached. That is line D on the worksheet, and it is the only line you cannot buy.

Take the first engagement from a client whose infrastructure you can actually see. Ask for three specific artifacts before you quote: the last access review, the current list of production administrators, and one closed incident ticket. What comes back, and how fast, tells you more about the engagement than the questionnaire will.

The software line, and what it does not include

Tooling is the smallest decision here and the one firms make first. What you need is narrow: workpapers tied to criteria, a request list a client can answer without a call, sampling, and a sign-off chain that still reads correctly a year later. What audit software costs a small firm compares the licensing models rather than the numbers, because the numbers in that category are mostly unpublished.

Polara Enterprise is one of the options, and its price is stated here once rather than gated. Free to join. No seats, no monthly fee, no annual commitment. An engagement costs $600, billed when you open it, and ten bought together are $5,000 and stay valid for twelve months. The fee is uniform. It does not move with your findings, your conclusions, or whether the report you issue ends up qualified.

The line no software crosses

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.6 The scoping judgment, the conclusions and the issuance decision belong to the firm on the engagement. Software records who reached them and when, which is the part a reviewer asks about.

None of that is the decision though. The decision is line C against line D, and you can make it this week with two phone calls and a spreadsheet. If the answer comes back yes, the Enterprise page has the rest of it.

Questions

Do you need a special license to perform SOC 2 examinations?
No. There is no SOC 2 license and no SOC 2 accreditation body. A SOC 2 is an examination performed under the AICPA attestation standards, so the permit that governs it is the CPA firm license your state board already issues. SOC 2 is an attestation rather than a certification, and no certificate is issued at the end of it.
Does taking on SOC 2 work change peer review?
SOC 2 examinations are attest engagements, so they sit inside the accounting and auditing practice your peer review already covers. Tell your peer reviewer before the first engagement rather than after it, because the engagements you accept in a year decide what gets selected in the next review.
What does SQMS No. 1 require, and by when?
Statement on Quality Management Standards No. 1 required systems of quality management to be designed and implemented by December 15, 2025, and the evaluation of the system to be performed within one year following that date. It applies to every firm performing any engagement in its accounting and auditing practice, and engagements under the attestation standards are part of that practice.
How many people does a first SOC 2 engagement need?
Two, at minimum. A partner who reviews and signs, and a senior who performs the fieldwork. The binding constraint is technical rather than numerical. Somebody on the engagement has to read a cloud access policy and decide whether it does what the control description says it does.
What does the software cost a firm?
Polara Enterprise is free to join, with no seats, no monthly fee and no annual commitment. An engagement costs $600, billed when you open it, and ten bought together are $5,000 and stay valid for twelve months. The fee is uniform and does not move with your findings, your conclusions, or whether the report you issue is qualified.

Sources

  1. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  2. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.
  3. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  4. AICPA Peer Review Program AICPA. Enrollment and scope for firms performing attest engagements. Checked 1 August 2026.
  5. State Boards of Accountancy directory NASBA. Where to confirm a CPA firm holds an active license in its state. Checked 1 August 2026.
  6. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Bring one engagement.

$0 to join. $600 when you create an engagement. Run one, start to seal, and judge the binder that comes out.

Book a working session
polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty