How to choose a SOC 2 auditor for your first audit
Your SOC 2 auditor must be a licensed CPA firm. Ask whether it is enrolled in AICPA peer review, how it relates to your compliance tool vendor, and who on its team will do the work. A report your customers do not trust is not worth having.
Who is allowed to issue a SOC 2 report?
Only a licensed CPA firm. SOC is a suite of service offerings that CPAs may provide under AICPA standards. A compliance software company can prepare you and can introduce or bundle an auditor, but the opinion must come from the CPA firm.
What is AICPA peer review, and why ask about it?
Peer review is the AICPA's programme in which CPA firms that perform audit and attestation work have their quality reviewed by other practitioners. Asking whether a firm is enrolled, and when its last review took place, is a simple check a buyer can make.
Why does the auditor's relationship with your tool vendor matter?
Several tools bundle, arrange or run the audit. That can save time. It also raises a fair question about auditor independence: the firm that examines your controls should not depend on the company that helped you build them. In 2026 the AICPA and the Journal of Accountancy published several items on this subject (listed below). Ask your vendor and the audit firm to describe their business arrangement in writing.
How do the five tools approach the audit?
Thoropass provides automation and audit from one company, with the audit work led by its audit partner. Scytale offers Built-In Audit with partner auditors, or manages the audit with an auditor you choose. Secureframe includes access to its Audit Partner Network in Fundamentals. Vanta says 26k audits have been completed with AICPA-peer reviewed auditors. Comp AI lists audit needs as a price factor; no auditor network is described on the pages we reviewed.
What should you ask a SOC 2 auditor before signing?
- Is the firm a licensed CPA firm, and in which jurisdictions?
- Is it enrolled in AICPA peer review, and when was its last review?
- What is its relationship with our compliance tool vendor, including any referral fees or revenue sharing?
- Who will do the fieldwork, and how many SOC 2 examinations have they done?
- What is the fee, what does it include, and what triggers extra charges?
- How are exceptions handled, and when will we see a draft?
Further reading
- Promises of 'fast and easy' threaten SOC credibility, Journal of Accountancy, 2026-02-01Source: aicpa-cima.com · Read 2026-09-29
- Business arrangements with SOC tool providers, AICPA Ethics Staff Insights, 2026-04-13Source: aicpa-cima.com · Read 2026-09-29
- The risks of quick-turn SOC engagements and what CPAs should know, Journal of Accountancy podcast, 2026-04-30Source: aicpa-cima.com · Read 2026-09-29
- AICPA guides peer reviewers to address SOC 2 risks, Journal of Accountancy, 2026-05-14Source: aicpa-cima.com · Read 2026-09-29
What should you read next?
Next lesson · 10 of 10After your first SOC 2 report: sharing, renewing and the next framework
Questions founders ask
Can our compliance tool vendor also be our auditor?
Only a licensed CPA firm can issue the report. Some companies offer both software and audit through an audit partner; ask how the two sides are separated and how auditor independence is maintained.
How do we check a SOC 2 auditor?
Confirm the CPA licence, ask about AICPA peer review enrolment, and ask for the relationship with your tool vendor in writing.