Who can perform a SOC 2 audit

The rule is one sentence long. Everything else sold in this market is preparation, which is a different job from signing.

Who can perform a SOC 2 audit? Only a licensed CPA firm. A SOC 2 report is an AICPA attestation engagement, and the opinion at the front of it can be issued by a licensed CPA firm and by nobody else. Software cannot issue one. A security consultancy cannot. A readiness firm cannot either, unless that readiness firm also holds a CPA license.

Plenty of companies help you get ready. Far fewer can sign. Both jobs are legitimate and they are not the same job, and the public license register of a state board of accountancy3 settles which one you are talking to.4

The question usually arrives late. A buyer asks for a report, a vendor promises one, and somewhere in between nobody says out loud who is going to sign it. That gap is where a company pays a readiness firm, reaches the security review, and discovers nobody in the arrangement can sign anything. The rule is one sentence. Every vendor claim you read after this one sorts into two piles: work anyone can do, and the signature only a CPA firm can put on it. If the money is the part you came for, what a SOC 2 auditor charges separates the audit fee from the software fee.

Why the signature has to come from a CPA firm

SOC 2 is not a certification. Nobody hands you a certificate and no registry of compliant companies exists. What exists is an examination performed under the AICPA attestation standards,2 ending in a written opinion on whether your controls were suitably designed and, for a Type 2, whether they operated across a period.1 A firm puts its name on that opinion.

Three things travel with a CPA license. Together they are the reason a security reviewer who has never met you will accept the document at all.

Professional standards
The examination follows the AICPA attestation standards2 rather than a methodology the vendor invented. Sampling, evidence sufficiency, documentation and the wording of the opinion itself are all prescribed. Two firms examining the same company should land in the same place.
Independence
The firm has to be independent of the company it examines, in fact and in appearance. That single constraint is what separates an opinion from a testimonial, and it is the rule most often bent in this market.
Peer review, and a license somebody can take away
Firms performing attestation work are enrolled in peer review, and the license comes from a state board that can suspend it. A consultancy answers to its customers. A CPA firm answers to a state board that can pull its license, and that is the only difference your buyer is paying for.

Remove those three and the report is a vendor asserting that it is secure. You already made that assertion in the sales call. Your buyer asked for a SOC 2 because they wanted it to come from somebody with something to lose.

Can a consultant do a SOC 2 audit?

A consultant can do almost all of the work. Scoping the criteria, writing the policies, standing up the control set, running the gap analysis, gathering evidence and rehearsing you for the questions the auditor will ask are all things a good consultant does better than you will on your own. None of that requires a license. Signing does.

So the answer has two halves and both matter. Yes, a consultant can prepare your SOC 2, and a good one shortens the examination. No, a consultant cannot issue the report unless the consultancy is itself a licensed CPA firm. Some are. Ask, in writing, which of the two you are hiring.

Readiness firm or attest firm: two jobs, one word

Most of the confusion here comes from one word doing two jobs. Nearly everyone selling SOC 2 help calls the engagement an audit, including the firms that never touch the opinion. Here is the split, task by task.

TaskReadiness firm or platformAttest firm, licensed CPA
Scoping the trust services criteriaYesYes, on its own scoping
Writing policies and building controlsYesNo, independence forbids it
Collecting and organizing evidenceYesNo, it requests and tests instead
Testing controls and pulling samplesNoYes
Issuing and signing the opinionNoYes
Listed on a state board license registerNot requiredRequired

Both columns are real work and most companies buy both. The failure mode is buying only the left column while believing you bought the right one, and that is a discovery worth making now rather than three days before a security review.

Independence, and why the rule is on your side

The firm that designed your controls generally cannot attest to them. The same goes for the firm that wrote your policies, ran your access reviews or operated your vulnerability management. Read as a rule it sounds like bureaucracy. Read from your buyer’s side of the table it is the whole point.

An examination is somebody checking whether the thing works. If the same people built it, checked it and graded it, the check tells the reader nothing they did not already have from you directly. The rule protects the value of the document you paid for, which is the only reason the document was worth buying.

This is why any vendor offering both halves has to draw a line somewhere, and asking exactly where is fair. A company that prepares you and also arranges the examination should be able to say which entity does which, and what stops them from being the same people.

Three questions for any vendor

Who signs my opinion, what is that firm called, and what is the relationship between that firm and you? A vendor that answers all three in one email is describing a real structure. If the answer needs a call, a follow up and some softening first, the structure is being assembled while you wait. Our own answers are at the bottom of this page.

How to verify a firm before you sign anything

None of this requires trusting anyone, including us. Every check below runs against public records or against the document itself, and the whole sequence takes about ten minutes.

  1. Get the firm name in writing. Before the engagement letter, not after. A vendor that will not name the firm until you have paid has already answered a different question.
  2. Search the state board license register. Every U.S. CPA firm is licensed by the board of accountancy in the state where it is registered, and those registers are public and free. Search the firm, not the individual.
  3. Match the licensee to the name on the letter. This is the step people skip. The opinion is signed by a firm, and that exact firm name should appear on the register. A close variant deserves a question.
  4. Read the letterhead and the signature block. An opinion letter sits on firm letterhead, addressed to your company, dated, and signed with the firm name. An unsigned letter is a draft.
  5. Ask about peer review. Firms doing attestation work are enrolled in a peer review program. Asking is ordinary, and a real firm will not be offended that you did.

What software can and cannot do

A platform can make an examination shorter and cheaper, and it can do that honestly. Gap analysis, a policy pack written against your actual stack, evidence pulled from AWS, GitHub, Google Cloud and Google Workspace, and a binder mapped control by control to the criteria being tested. That work removes weeks of back and forth, which is where the cost of a small examination usually goes: the auditor receives a finished package rather than a promise of one.

What no platform can do is grade the result. If a tool offers you a SOC 2 report with no CPA firm named anywhere in the process, the thing being sold is something other than a SOC 2 report, and your buyer will work that out during the security review.

The line no platform crosses

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

How this works at Polara Labs

We prepare. An independent partner auditor examines and signs. A Type 1 is $4,000 one time, and that number covers the examination and the engagement fee for the independent partner auditor, so the work arrives as one invoice instead of two.

Our answers to the three questions above, in order.

Who signs
The signer is an independent partner auditor, a licensed U.S. CPA firm. Not us, and not this software.
What that firm is called
Ask and the name comes back in writing, in the same reply, before any engagement letter. That is the moment step one above is worth something. We do not print it here because a marketing page is not a record. Your engagement letter and your report are, and both carry the name you should be checking. Run step two on it.
The relationship to us
We engage the firm and its fee comes out of the one price above. The examination after that is theirs. We do not draft conclusions, suggest findings or otherwise influence it. We do not sit in on their testing. We are paid the same whatever the opinion says.

Those three fit in one email because the arrangement behind them is ordinary. If we ever cannot answer them that way, hold us to the same rule as every other vendor on this page. It has no exception for us. Our independence and ethics position sets out the rest, including the work we will not take. If the price is what sent you looking for this rule in the first place, whether a cheap audit is legitimate answers that objection using the same public records.

One limit, stated plainly. Polara Labs publishes no customer counts, no case studies and no named clients, so nothing on this page rests on a logo wall. The checks above work without one. They also work on every other vendor in this category, which is the point of writing them down.

Questions

Who can perform a SOC 2 audit?
Only a licensed CPA firm can perform a SOC 2 examination and issue the opinion. Software cannot do it, a security consultancy cannot do it, and a readiness firm cannot do it unless that firm also holds a CPA license. Preparation can come from anyone. The signature cannot.
Does a SOC 2 auditor have to be a CPA?
Yes. SOC 2 is an AICPA attestation engagement, so the examination has to be performed by a firm licensed to practice public accounting. The people signing on behalf of the firm work under that license and under the AICPA attestation standards.
Can a consultant do a SOC 2 audit?
A consultant can prepare you for one. They can scope the criteria, write policies, build controls and assemble evidence. They cannot issue the opinion unless the consultancy is itself a licensed CPA firm, and some are. Ask which of the two you are hiring before you sign an engagement letter.
How do I check that a SOC 2 auditor is licensed?
Ask for the firm name in writing, then search the public license register of the state board of accountancy where the firm is registered. Confirm the name on the register matches the firm name on the opinion letter, and that the letter is on firm letterhead, dated and signed.
Can the firm that helped me prepare also sign my report?
Generally no. Independence rules stop a firm from attesting to controls it designed or operated. That separation is what makes the opinion mean anything to your buyer, so a vendor that offers to do both should be able to say exactly what keeps the two apart.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. State Boards of Accountancy directory NASBA. Where to confirm a CPA firm holds an active license in its state. Checked 1 August 2026.
  4. CPAverify licensee lookup NASBA. A single lookup across participating state boards. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty