Who can perform a SOC 2 audit
The rule is one sentence long. Everything else sold in this market is preparation, which is a different job from signing.
Who can perform a SOC 2 audit? Only a licensed CPA firm. A SOC 2 report is an AICPA attestation engagement, and the opinion at the front of it can be issued by a licensed CPA firm and by nobody else. Software cannot issue one. A security consultancy cannot. A readiness firm cannot either, unless that readiness firm also holds a CPA license.
Plenty of companies help you get ready. Far fewer can sign. Both jobs are legitimate and they are not the same job, and the public license register of a state board of accountancy3 settles which one you are talking to.4
The question usually arrives late. A buyer asks for a report, a vendor promises one, and somewhere in between nobody says out loud who is going to sign it. That gap is where a company pays a readiness firm, reaches the security review, and discovers nobody in the arrangement can sign anything. The rule is one sentence. Every vendor claim you read after this one sorts into two piles: work anyone can do, and the signature only a CPA firm can put on it. If the money is the part you came for, what a SOC 2 auditor charges separates the audit fee from the software fee.
Why the signature has to come from a CPA firm
SOC 2 is not a certification. Nobody hands you a certificate and no registry of compliant companies exists. What exists is an examination performed under the AICPA attestation standards,2 ending in a written opinion on whether your controls were suitably designed and, for a Type 2, whether they operated across a period.1 A firm puts its name on that opinion.
Three things travel with a CPA license. Together they are the reason a security reviewer who has never met you will accept the document at all.
- Professional standards
- The examination follows the AICPA attestation standards2 rather than a methodology the vendor invented. Sampling, evidence sufficiency, documentation and the wording of the opinion itself are all prescribed. Two firms examining the same company should land in the same place.
- Independence
- The firm has to be independent of the company it examines, in fact and in appearance. That single constraint is what separates an opinion from a testimonial, and it is the rule most often bent in this market.
- Peer review, and a license somebody can take away
- Firms performing attestation work are enrolled in peer review, and the license comes from a state board that can suspend it. A consultancy answers to its customers. A CPA firm answers to a state board that can pull its license, and that is the only difference your buyer is paying for.
Remove those three and the report is a vendor asserting that it is secure. You already made that assertion in the sales call. Your buyer asked for a SOC 2 because they wanted it to come from somebody with something to lose.
Can a consultant do a SOC 2 audit?
A consultant can do almost all of the work. Scoping the criteria, writing the policies, standing up the control set, running the gap analysis, gathering evidence and rehearsing you for the questions the auditor will ask are all things a good consultant does better than you will on your own. None of that requires a license. Signing does.
So the answer has two halves and both matter. Yes, a consultant can prepare your SOC 2, and a good one shortens the examination. No, a consultant cannot issue the report unless the consultancy is itself a licensed CPA firm. Some are. Ask, in writing, which of the two you are hiring.
Readiness firm or attest firm: two jobs, one word
Most of the confusion here comes from one word doing two jobs. Nearly everyone selling SOC 2 help calls the engagement an audit, including the firms that never touch the opinion. Here is the split, task by task.
| Task | Readiness firm or platform | Attest firm, licensed CPA |
|---|---|---|
| Scoping the trust services criteria | Yes | Yes, on its own scoping |
| Writing policies and building controls | Yes | No, independence forbids it |
| Collecting and organizing evidence | Yes | No, it requests and tests instead |
| Testing controls and pulling samples | No | Yes |
| Issuing and signing the opinion | No | Yes |
| Listed on a state board license register | Not required | Required |
Both columns are real work and most companies buy both. The failure mode is buying only the left column while believing you bought the right one, and that is a discovery worth making now rather than three days before a security review.
Independence, and why the rule is on your side
The firm that designed your controls generally cannot attest to them. The same goes for the firm that wrote your policies, ran your access reviews or operated your vulnerability management. Read as a rule it sounds like bureaucracy. Read from your buyer’s side of the table it is the whole point.
An examination is somebody checking whether the thing works. If the same people built it, checked it and graded it, the check tells the reader nothing they did not already have from you directly. The rule protects the value of the document you paid for, which is the only reason the document was worth buying.
This is why any vendor offering both halves has to draw a line somewhere, and asking exactly where is fair. A company that prepares you and also arranges the examination should be able to say which entity does which, and what stops them from being the same people.
Who signs my opinion, what is that firm called, and what is the relationship between that firm and you? A vendor that answers all three in one email is describing a real structure. If the answer needs a call, a follow up and some softening first, the structure is being assembled while you wait. Our own answers are at the bottom of this page.
How to verify a firm before you sign anything
None of this requires trusting anyone, including us. Every check below runs against public records or against the document itself, and the whole sequence takes about ten minutes.
- Get the firm name in writing. Before the engagement letter, not after. A vendor that will not name the firm until you have paid has already answered a different question.
- Search the state board license register. Every U.S. CPA firm is licensed by the board of accountancy in the state where it is registered, and those registers are public and free. Search the firm, not the individual.
- Match the licensee to the name on the letter. This is the step people skip. The opinion is signed by a firm, and that exact firm name should appear on the register. A close variant deserves a question.
- Read the letterhead and the signature block. An opinion letter sits on firm letterhead, addressed to your company, dated, and signed with the firm name. An unsigned letter is a draft.
- Ask about peer review. Firms doing attestation work are enrolled in a peer review program. Asking is ordinary, and a real firm will not be offended that you did.
What software can and cannot do
A platform can make an examination shorter and cheaper, and it can do that honestly. Gap analysis, a policy pack written against your actual stack, evidence pulled from AWS, GitHub, Google Cloud and Google Workspace, and a binder mapped control by control to the criteria being tested. That work removes weeks of back and forth, which is where the cost of a small examination usually goes: the auditor receives a finished package rather than a promise of one.
What no platform can do is grade the result. If a tool offers you a SOC 2 report with no CPA firm named anywhere in the process, the thing being sold is something other than a SOC 2 report, and your buyer will work that out during the security review.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
How this works at Polara Labs
We prepare. An independent partner auditor examines and signs. A Type 1 is $4,000 one time, and that number covers the examination and the engagement fee for the independent partner auditor, so the work arrives as one invoice instead of two.
Our answers to the three questions above, in order.
- Who signs
- The signer is an independent partner auditor, a licensed U.S. CPA firm. Not us, and not this software.
- What that firm is called
- Ask and the name comes back in writing, in the same reply, before any engagement letter. That is the moment step one above is worth something. We do not print it here because a marketing page is not a record. Your engagement letter and your report are, and both carry the name you should be checking. Run step two on it.
- The relationship to us
- We engage the firm and its fee comes out of the one price above. The examination after that is theirs. We do not draft conclusions, suggest findings or otherwise influence it. We do not sit in on their testing. We are paid the same whatever the opinion says.
Those three fit in one email because the arrangement behind them is ordinary. If we ever cannot answer them that way, hold us to the same rule as every other vendor on this page. It has no exception for us. Our independence and ethics position sets out the rest, including the work we will not take. If the price is what sent you looking for this rule in the first place, whether a cheap audit is legitimate answers that objection using the same public records.
One limit, stated plainly. Polara Labs publishes no customer counts, no case studies and no named clients, so nothing on this page rests on a logo wall. The checks above work without one. They also work on every other vendor in this category, which is the point of writing them down.
Questions
Who can perform a SOC 2 audit?
Does a SOC 2 auditor have to be a CPA?
Can a consultant do a SOC 2 audit?
How do I check that a SOC 2 auditor is licensed?
Can the firm that helped me prepare also sign my report?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.