Who is allowed to sign a SOC 2 report, and which work you can do yourself
Only a licensed CPA firm can sign the opinion. Everything before that signature is preparation, and preparation is where you can save.
Who can perform a SOC 2 audit? A licensed CPA firm, and only a licensed CPA firm. SOC 2 is an AICPA attestation engagement, and the opinion at the front of the report has to come from a firm licensed to practice public accounting. Software cannot sign it. A security consultancy cannot. A readiness firm cannot either, unless it also holds a CPA license.
Many kinds of company can help you get ready. Only one kind can sign. The public license register of a state board of accountancy3 tells you which one you are dealing with.4
This matters for your costs as much as for compliance. When you know which work needs a license, you know which work you are free to do yourself, and which spend you cannot avoid.
Two bills: preparation and the signature
Every SOC 2 has two parts, and they are priced very differently. Preparation is scoping, policies, controls and evidence. Anyone can do it, including you, and it is where most of the hours go. The signature is the examination and the opinion. Only a CPA firm can provide it, and no amount of software replaces it.
That split is where a small team saves money. You can run the preparation yourself on our software for $199 a month instead of paying consultant rates for it. The signature you still have to buy, through our preferred pricing program. The software does most of the work, so the auditor only has to verify evidence that arrives prepared. We negotiate the fee on your behalf, and you see the price in your account before you book. If you want the audit fee by itself, what a SOC 2 auditor charges separates it from the software.
Task by task: who can do what
One word causes most of the confusion here. SOC 2 help gets sold as an audit even when the seller never touches the opinion. This table splits the job into its real pieces so you can see which column you are paying for.
| Task | Readiness firm, consultant or software | Licensed CPA firm |
|---|---|---|
| Scoping the trust services criteria | Yes | Yes, and it does its own scoping too |
| Writing policies and building controls | Yes | No, independence rules forbid it |
| Gathering and organizing evidence | Yes | No, it requests and tests evidence instead |
| Testing controls and pulling samples | No | Yes |
| Issuing and signing the opinion | No | Yes |
| Listed with a state board of accountancy | Not required | Required |
Both columns are real work, and a company going for SOC 2 needs both. The trap is paying for the left column while thinking you bought the right one. Better to find that out now than a few days before a security review.
What a CPA license brings to the report
SOC 2 is not a certification. There is no certificate and no public list of compliant companies. There is an examination under the AICPA attestation standards,2 ending in a written opinion on whether your controls were designed well and, for a Type 2, whether they worked across a period.1 A firm signs that opinion, and three things come with its license.
- Set standards
- The work follows the AICPA attestation standards,2 not a method the vendor made up. Sampling, evidence, documentation and the wording of the opinion are all prescribed, so two firms looking at the same company should reach the same place.
- Independence
- The firm must be independent of the company it examines, both in fact and in appearance. That rule is what turns a testimonial into an opinion.
- Peer review and a license that can be lost
- Firms doing attestation work take part in peer review, and their license comes from a state board that can suspend it. A consultancy answers to its clients. A CPA firm also answers to a regulator, and that is what your buyer is relying on.
Take those three away and the report is just you saying you are secure. You already said that on the sales call. Your buyer asked for SOC 2 because they wanted the statement to come from someone with something to lose.
Can a consultant do the audit?
A consultant can do almost everything except the part that counts as the audit. Scoping, policies, controls, a gap analysis, evidence collection and practice runs for the auditor’s questions are all fair game, and none of it needs a license. Signing does.
So the answer has two halves. Yes, a consultant can prepare your SOC 2, and a good one makes the examination shorter. No, a consultant cannot issue the report, unless the consultancy is itself a licensed CPA firm. Some are. Ask which you are hiring, and get the answer in writing.
Independence works in your favor
A firm that designed your controls generally cannot give an opinion on them. The same goes for a firm that wrote your policies, ran your access reviews or managed your vulnerability scans. It can look like red tape. From your buyer’s side it is the whole point.
An examination is someone checking that a thing works. If the same people built it, checked it and graded it, the reader learns nothing new. The rule protects the value of the report you are paying for. Any vendor that offers both preparation and the examination should be able to say which entity does which, and what keeps them apart.
Who signs my opinion? What is that firm called? How is it related to you? A vendor that can answer all three in one email has a real structure. If the answer needs a call and a follow up first, the structure is being built while you wait. Our answers are further down.
Check any firm in five steps
You do not need to trust anyone for this, us included. Each step below uses public records or the document itself, and the whole check takes about ten minutes. It costs nothing, which makes it the lowest cost protection in the whole SOC 2 process.
- Get the firm name in writing. Before you sign the engagement letter. A vendor that will only name the firm after payment has told you something.
- Search the state board register. Every U.S. CPA firm is licensed by the board of accountancy where it is registered, and the registers are public and free. Search for the firm, not a person.
- Match the register to the letter. The exact firm name on the register should appear on the opinion. A near match deserves a question.
- Read the letterhead and signature. The opinion letter sits on firm letterhead, is addressed to your company, dated, and signed in the firm’s name. An unsigned letter is a draft.
- Ask about peer review. Firms doing attestation work are enrolled in peer review. A real firm will not mind the question.
What software can and cannot do
A platform can make the examination shorter and less costly without cutting corners. It can run the gap analysis, write a policy set against your real stack, pull evidence from AWS, GitHub, Google Cloud and Google Workspace, and map it all control by control to the criteria. That removes weeks of back and forth, which is where a small examination loses time and money. The auditor gets a finished package instead of a promise of one.
What software cannot do is grade the result. If a tool offers you a SOC 2 report with no CPA firm named anywhere, it is selling you something other than a SOC 2 report. Your buyer will notice during the security review.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Our answers to the three questions
We prepare you. An independent partner auditor examines your controls and signs the report. Here are our answers, in the same order as above, so you can hold us to the same test as anyone else.
- Who signs
- an independent partner auditor, a licensed U.S. CPA firm. Not us, and not the software.
- What the firm is called
- Ask and we name it in writing, in the same reply, before any engagement letter. We leave it off this page because a marketing page is not a record. Your engagement letter and your report are, and both carry the name. Run step two on it.
- How it relates to us
- We arrange the engagement. The examination is theirs. We do not draft conclusions, suggest findings or sit in on their testing.
If we ever cannot answer those three in one email, apply the same rule to us that you apply to everyone else. Our independence and ethics position covers the rest, including work we will not take. If price is what made you doubt a low cost report, whether a low-priced audit is legitimate answers that with the same public records.
Ready to start on the preparation half? The free readiness assessment takes about 15 minutes and shows your gaps at no cost. Take it now, or compare the plans first.
Questions
Who is allowed to perform a SOC 2 audit?
Must a SOC 2 auditor be a CPA?
Can a security consultant run my SOC 2 audit?
How can I confirm a SOC 2 auditor is licensed?
Can one firm both prepare me and sign my report?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.